At the company, we’re reinventing how enterprise businesses operate, starting with the most painful parts: procurement – where a single purchase can drag on for months, trigger 50+ emails , and pull in Finance, Legal, Security, and IT just to get something approved.
Our AI-native platform connects every person, step, and system so buying is fast, safe, and efficient – one place to request, automated approvals and renewals, real-time supplier risk, and complete spend visibility.
The opportunity is massive. Every enterprise on the planet has this problem and nobody has solved it . We’re now the 4th fastest growing startup in Europe & the Sunday Times' 1 Best Medium Sized Tech Company To Work for.
You’ll work alongside leaders like Ben , Abs , Sabrina , and Rebe .
Find out more about the team and life at the company here .
Why We Need a Platform Security Engineer Now
The company takes security seriously. In an era where exploits and supply chain attacks are being discovered and conducted faster than ever before, it’s vital that we stay on the cutting edge of keeping our systems and our customers’ data safe.
Hardening our systems is only part of the solution. As we scale out to more industries with their diverse security requirements, we want another individual who can help us attain and maintain higher levels of compliance certification.
Responsibilities
Implement and take ownership of our Security roadmap. Working with the Platform Lead, a successful candidate will steadily take ownership over the Platform Security Roadmap, leading implementations and experiments to level up the company’s security posture.
Own Security Tooling. From safe-chain plugins to SAST/DAST tooling, we want someone who’s keen to get stuck in, onboard, and evolve our tooling to ensure our posture stays at the bleeding edge.
Deliver Compliance Programs. The company plans to tackle multiple additional compliance certifications to enable the business to serve some of the most regulated industries on the planet. You’ll have a massive hand in making sure we’re up to those standards.
Collaborate with our DevX streams. The company ships fast, and we want to ship even faster. Making sure we can enable that safely and securely will become your wheelhouse.
Implement hardening patterns. See an area where code security could be improved? Let’s do it, and do it in a way that can be scaled out across the entire codebase and easily implemented by the rest of the engineering staff.
What Can You Expect?
A strong team. You'll join a platform team of senior and staff engineers who set a high bar and will push you to do your best work.
Continuous delivery. We deploy multiple times a day. Your work determines how fast and safely the whole engineering org ships.
Scalability challenges. As we 10x revenue, you'll be a part of evolving our infrastructure to defend against new security threats and keep us one step ahead.
Customer impact. Delivering on our compliance goals and successfully handling audits.
Massive ownership. You own problems end-to-end, from brainstorming through to production.
Collaboration & autonomy. Plenty of heads-down technical work, but also close partnership with product engineers and engineering leadership.
Requirements
We're hiring at both Level 3 (Senior) and Level 4 (Staff) . For calibration, candidates typically bring 5+ years of platform engineering experience in high-growth, cloud-native SaaS environments, but we care more about impact than years. We’re looking for that “T”-shaped skillset where the candidate’s depth is in Cloud Security.
Furthermore, the ideal candidate will have a product engineering background but caught the bug for security and cares deeply about enabling people to work fast, safely. Finally, we’re looking for someone who sees security as an enabler and force-multiplier and answers questions with a “Yes, here’s how we do it securely” attitude as opposed to the flat “No” security teams are too often renowned for.
Platform engineer & builder. You design reliable infrastructure and write clean production code (TypeScript or similar). You've built and maintained CI/CD pipelines, IaC, and security gates at scale.
Cloud-native. Deep knowledge of AWS (Lambda, DynamoDB, EventBridge, IAM, networking), or equivalent cloud-native experience. You understand serverless and its trade-offs.
Security as an enabler. You think about engineers and business as your customers. You automate toil, improve feedback loops, and care deeply about making other people productive.
Commercially minded. You understand that infrastructure & security exist to serve the product and the business. You make trade-offs with that in mind.
Bias for action. You iterate quickly, ship pragmatically, and automate everything.
Culture carrier. You coach teammates, share knowledge freely, and keep calm when things break.
Nice-to-haves
Experience with Pulumi or similar IaC frameworks.
ISC2 (any level) certification.
Experience running SaaS compliance programs (ISO:27001, SOC 2 Type II).
Open-source contributions to security, infrastructure, or developer tooling projects.
You can learn more about Engineering at the company and our hiring process via our R&D Candidate Hub here.
At the company, we embrace diversity. We encourage you to apply even if your experience doesn't quite match the full job spec! And regardless of your race, religion, colour, gender, or anything else! If you think you could be a good fit for the company, please reach out.
A few things to note:
We offer competitive geo-localised benefits, and you can check out our UK Benefits Package here and our US Benefits Package here .
We work Tuesdays, Wednesdays & Thursdays in-person at our offices. At this early stage of our company life-cycle it's important to us that we get this together-time, and you can read more about why we believe this is a winning move here
We're commercial, ambitious and we don't pretend otherwise! We're actively seeking folks looking to make the most of a career-defining opportunity, with the hunger to be part of building something really impressive . You can see our values here and our the company Future Founder's fund here !
We sometimes use AI note-takers to help us transcribe interview notes, so we can be more present in your interview. If you'd like to opt out of us using automatic transcribers, please note this in the free text field in your application, otherwise we'll take your application as confirmation that you're happy for us to use notetakers (whether added to video calls or in the background).
We are proud to be recognised for both our culture and product, and we are just getting started. Join us as we grow!
Legal note: if you are viewing this posting outside of the the company careers' page, this may be an auto-generated advertisement and may lack the full range of advertised information - please click through to the posting at the company's site to view additional advertised information on this posting.
Additionally, where roles have hard-specified requirements (e.g. [x] days in office, unable to provide visas, etc), if in your application you provide deterministic check-box confirmation that you do not meet the hard-specified requirements, deterministic (not AI or subjective) automatic rejection criteria are in place.