Bloomberg
Posted 3mo ago

Product Security Engineer - Software Security Enablement

Bloomberg
London, England, United Kingdom
OnsiteFull Time
Responsibilities
  • building automation
  • integrating testing
  • conducting reviews
Requirements
  • 3+ years software development experience
  • Strong engineering and programming skills (C, C++
  • Python
  • JavaScript/TypeScript)
  • Experience with DevOps tools and build systems
  • Knowledge of SAST/DAST/SCA and vulnerability concepts
  • Experience with LLMs and security automation
Technical tools mentioned
SASTDASTSCALLMCodeQLSemgrepGitHubJenkinsCMakenpmMavenGradleCC++PythonJavaScriptTypeScriptJavaGoRustKubernetesDockerAWSGCPAzureMCP servers

Job description

Description & Requirements

Our Team:


Bloomberg is building the world’s most trusted information network for financial professionals. We protect Bloomberg. We partner with internal departments to ensure the confidentiality, integrity, and availability of Bloomberg systems and the data we process. We aim to ensure that our clients see us as a trusted partner.

Our Chief Information Security Office (CISO) owns the technical aspects of this mission by ensuring Bloomberg products, systems, networks and commercial applications are built and maintained with security in mind.

What's the role?


We are seeking a Product Security Engineer to help ensure that Bloomberg software is built securely. You will be responsible for building and maintaining automated security capabilities across the software development lifecycle. You will also engage with engineering partners to provide remediation guidance and enhance security testing to deliver high-fidelity, actionable results.

As a member of the Product Security Enablement team, you will help provide automated security testing solutions for Bloomberg, including SAST, DAST, SCA, Secret searching and LLM-based assessments. Our team’s goal is to create preventative security capabilities that integrate into development pipelines and help detect issues early in the software development lifecycle.

An engineering skillset is required for this role. You will be responsible for prototyping new tools, integrating security testing tools and capabilities into the software development lifecycle, and developing custom security capabilities to deliver scalable testing solutions to our engineering teams. This role will routinely challenge your technical background and critical thinking. You will be expected to collaborate with different stakeholders in a fast-paced environment across many technology stacks and services.

We'll trust you to:

  • Partner with engineering stakeholders to understand Bloomberg’s development landscape and security needs.

  • Develop automated security solutions that integrate into development pipelines.

  • Maintain and enhance existing security automation processes and security capabilities.

  • Understand and research technical details of core technology stacks and develop or enhance custom code analysis queries.

  • Communicate vulnerability landscape and work on mitigations with stakeholders across the business.

  • Actively monitor the latest news and trends in automated security capabilities, secure development, and AI-assisted security workflows.

  • Develop and enhance operational runbooks

  • Perform ad-hoc vulnerability discovery, including code review and static analysis for key engineering teams, applications and services.

  • Build or adopt new security capabilities to address issues at scale, such as Software Composition Analysis, Secret searching, and other automated security testing techniques.

  • Use LLMs and AI-assisted workflows as part of security assessments, vulnerability research, secure code review, developer enablement, and security automation.

  • Explore, evaluate, and build automation using modern LLM tooling and integration patterns, including custom skills, MCP servers, agentic workflows, retrieval-augmented workflows, and integrations with development and security tooling.

You'll need to have:

  • A strong core engineering background with a proven track record.

  • 3+ years of experience in software development.

  • Strong programming experience, with working knowledge of at least one of: C/C++, Python, JavaScript/TypeScript.

  • Knowledge and experience with DevOps and software used in development pipelines (e.g. Github, Jenkins).

  • Working knowledge of build systems, package managers, and development tooling (such as cmake, npm, maven, gradle etc).

  • A core understanding of common security vulnerabilities, such as OWASP Top 10 issues and language-specific vulnerabilities.

  • Experience using, evaluating, or building with LLMs or AI-assisted tooling in technical workflows.

  • Ability to combine technical knowledge with an understanding of core aspects of an information security program.

  • Motivation to keep up with latest trends and techniques in the information security community.

  • Excellent written and verbal communication skills.

We'd love to see (not required, but nice to have!):

  • Experience or familiarity with running, maintaining, and customizing static analysis security testing tools such as CodeQL and Semgrep.

  • Broad familiarity with programming language ecosystems and frameworks, particularly C++, JavaScript/TypeScript, Python, Java as well as well as modern systems and infrastructure languages such as Go and Rust

  • Experience using LLMs or AI-assisted tools for security assessments, vulnerability research, secure code review, developer enablement, or security automation.

  • Familiarity with LLM automation concepts and tooling, such as custom skills, MCP servers, agentic workflows, retrieval-augmented workflows, or integrations with development and security tooling.

  • Knowledge of open source software component management, Software Composition Analysis, and related security tools.

  • Knowledge of core concepts in public cloud providers such as AWS, GCP, and Azure.

  • Familiarity with container orchestration technologies such as Kubernetes and Docker, and cloud deployment orchestration.

  • Technical information security certifications, such as CISSP, CSSLP, or SANS certifications.

  • Prior experience integrating security testing into DevOps pipelines.



Description & Requirements


If indicated, please note that years of experience are a guide; we will consider applications from all candidates who can demonstrate the skills necessary for the role.

Description & Requirements

Discover what makes Bloomberg unique - watch our podcast series for an inside look at our culture, values, and the people behind our success.

About Bloomberg

Delivers financial data, news, and software to global markets.

Similar jobs

Product Security Engineer roles near London, England
1w
Save
Mark Applied
Hide
Senior Product Security Engineer
London, England, United Kingdom
OnsiteFull Time
Anduril Industries
Anduril Industries: Defense technology building autonomous military hardware and software.
Experience securing firmware, embedded and networked systems; proficiency in C/C++, Golang, Rust or Python; threat modeling, architecture review, adversarial testing; eligible for UK SC clearance and UK citizenship required.
C/C++, Golang, Rust, Python, Linux
2w
Save
Mark Applied
Hide
Senior Product Security Engineer
Chemnitz or Berlin or Dresden or Leipzig or London or Sydney or Tokyo or Prague or New York City or Minneapolis or Saint Paul
HybridFull Time
Staffbase
Staffbase: Provides an AI-powered internal communications platform for employees.
Practical security knowledge (penetration testing, SAST/DAST, vulnerability management), strong programming skills (TypeScript/JavaScript/Kotlin/Java/Go/Python), Kubernetes and Unix experience, Terraform/Kustomize familiarity, and strong English communication.
TypeScript, JavaScript, Kotlin, Java, Go, Python, Kubernetes, Terraform, Kustomize
2w
Save
Mark Applied
Hide
Staff Product Security Engineer
Cambridge, England, United Kingdom
HybridFull Time
Entrust
Entrust: Provides identity-centric security and secure payment solutions.
Deep expertise in product and cryptographic security, security architecture, hardware and embedded security, threat modeling, vulnerability management, and strong programming skills in modern languages; relevant security certifications desirable.
Python, C/C++, Go, Rust, Java, CI/CD, fuzzing, software composition analysis (SCA), static analysis, dynamic analysis, FPGA
2w
Save
Mark Applied
Hide
Senior Product Security Engineer
Cambridge, England, United Kingdom
£74k-£100k/yr HybridFull Time
Arm
ArmNASDAQ: ARM: Designs and licenses processor architectures and semiconductor intellectual property.
Experienced in building and operating backend services, strong Python and scripting skills, API and service integration, cloud (AWS) and container (Docker) experience, CI/CD familiarity, and strong communication.
Python, bash, AWS, Docker, React
3w
Save
Mark Applied
Hide
Staff Product Security Engineer
Cambridge, England, United Kingdom
OnsiteFull Time
Renesas Electronics
Renesas ElectronicsTokyo Stock Exchange: 6723: Designs and manufactures semiconductors for automotive and industrial systems.
5+ YOE5+ years in application/product security, Bachelor's degree or equivalent experience, hands-on web/API security, threat modeling, manual pentesting, security regression testing, CI/CD security integration, and cloud/multi-tenant expertise.
OWASP Top 10, DAST, SAST, CI/CD, AWS
1mo
Save
Mark Applied
Hide
Senior Product Security Engineer
Luton or Lincoln or Southampton or Bristol
£45k-£55k/yr HybridMultiple Commitments Available
Leonardo
LeonardoBorsa Italiana: LDO: Designs and manufactures aerospace, defense, and security technology products.
Experience delivering product security across engineering lifecycles, ISO27001/27004/27005 and NIST RMF knowledge, security risk management for regulated products, interpreting pen test reports, and engagement with UK government assurance processes.
1mo
Save
Mark Applied
Hide
Principal Engineer, Product Security
Berlin or London or München or Valencia
HybridFull Time
commercetools
commercetools: SaaS platform for building enterprise headless commerce experiences.
5+ YOE5+ years hands-on product security, 2+ years leadership in product security, secure architecture and threat modeling, Linux, Kubernetes, Terraform, Vault, API security, DevSecOps, scripting in JavaScript or Go, strong communication.
Linux, Kubernetes, Terraform, Vault, API, JavaScript, Go, Static Analysis
1mo
Save
Mark Applied
Hide
Product Security Engineer
San Francisco or New York City or London or Berlin or United States
$208k-$312k/yr HybridFull Time
Vercel
Vercel: Frontend cloud platform for building and hosting web applications.
5+ YOE5+ years product security experience; threat modeling, secure code review, vulnerability management, OSS/supply-chain security, SAST/DAST and dependency scanning, CI/CD security integration, familiarity with JavaScript/TypeScript, Node.js, and Next.js; technical leadership skills.
Next.js, Node.js, JavaScript, TypeScript, GitHub Advanced Security (GHAS), GitHub workflows, CI/CD, SAST, DAST, Dependabot, Snyk, Open Policy Agent, Terraform