Senior Software Security Developer – Core Platform Services
SKILLS
FULL DESCRIPTION
[Employer hidden — view at passion-project.co.uk] is a deep-tech company with roots in numerical physics and Formula One, dedicated to accelerating hardware innovation at the speed of software.
We are building an AI-driven simulation software stack for engineering and manufacturing across advanced industries. By enabling high-fidelity, multi-physics simulation through AI inference across the entire engineering lifecycle, [Employer hidden] unlocks new levels of optimization and automation in design, manufacturing, and operations — empowering engineers to push the boundaries of possibility. Our customers include leading innovators in Aerospace & Defense, Materials, Energy, Semiconductors, and Automotive.
The Role
We are recruiting for a Senior Software Security Developer within our Core Platform Services Team. You will be responsible primarily for writing secure code components that many teams will use across the business. There is a strong emphasis on authentication for this role.
What you will do
- Design and implement platform security features and guardrails.
- Act as an SME for security for the Core Services development team. This includes mentoring, performing threat modeling, sand ecurity code reviews.
- Help shape incident response procedures and vulnerability management workflows
- Support the response team by validating and remediating product security vulnerabilities.
- Contribute to secure coding standards and provide training/mentorship to developers
What you bring to the table
- 8+ years in a developer role focused with strong focus on designing and building security features
- Extensive RBAC/ABAC knowledge and implementation experience
- Experience with user, agent, and machine authentication workflows.
- Hands-on experience with secure coding, OWASP Top 10, and threat modeling
- Strong developer skills and extensive experience shipping code to production.
- Experienced in CI/CD, IaC, Python and Go.
- Track record of balancing pragmatism and security rigor in a fast-paced team
- Thorough knowledge of authentication and authorization protocols (e.g., OAuth, OpenID Connect, SAML, LDAP, etc.).
- Strong communication skills, comfortable working across development teams and managing multiple initiatives.
Nice to Have Skills
- Strong understanding of AI security fundamentals
- Participation in bug bounty programs
- Familiarity with the BSIMM framework
- Experience in cloud security including identity and access management and cloud-native services.