Skip to content

Nobody tells you why you were rejected. We will. Free, in 30 seconds.

Score my CV against live jobs

Product Security Engineer

Arcticrd · Calmsden, Cirencester

On-sitePosted 4 Aug 2026

What this role requires

3 requirements, read out of the advert rather than guessed from the job title:

Also mentioned, not required: cryptography, detection and response, platform security, AWS, GCP, Azure. Worth having, but their absence is not what gets a CV filtered out.

See how often each of these is required across open security roles in Europe.

Check my CV against these 3 requirements

Free, no card. Tells you which of them your CV evidences and which it only implies.

Job description

LOCATION - ONSITE: CALMSDEN, CIRENCESTER, UK & IN THE FIELD WHEN NEEDED

THE LAST FRONTIER

The Arctic is a place of extremes: unforgiving, untamed, and undergoing rapid change. A literal defrosting reveals a multi-trillion-dollar opportunity spanning energy, defence, logistics, research, and infrastructure.

ARD was founded on a paradox. The Arctic is both the next great economic frontier and one of the most hostile environments on Earth. Rich in resources and strategically vital, yet bone-chillingly cold, dark for months, and fundamentally inhospitable to humans. This paradox—an explosion of activity in a place that resists human presence—is why we exist.

Our solution is autonomy.

We build systems that operate reliably and intelligently in the Arctic, so that humans don't always have to.

Read the full description (34 more sections)

Founded by record-holding pioneers with decades of polar experience, we take calculated risks on hard problems that matter. If you want to build and deploy ground-up technology with real-world impact, at an inflection point in history that won’t reappear, we’d like to talk.

THE ROLE We’re hiring our first Product Security Engineer. Security Engineering at ARD blends sharp technical skill, an attacker's mindset, and tangible real-world stakes. You'll operate across our entire hardware and software product suite — cloud infrastructure, applications, identity systems, and the autonomous products we field — spotting and cutting down the risks that actually matter. The systems we run and the data we hold call for a security approach that's thorough, flexible, and woven into everything we do. Your work will directly underpin the trust partners, customers, and the public place in us, while keeping our teams free to build and ship with confidence. Given how high the stakes are at ARD, this is core to delivering our mission the right way.

CORE RESPONSIBILITIES

Spot, evaluate, and rank security risks across our physical products, systems and infrastructure — separating hypothetical worries from genuine threats to the business

Build and roll out practical security controls across cloud platforms, applications, products, and data, and help engineering teams do likewise

Build and use threat models to catch architectural weak points, trust boundary gaps, and failure modes before they turn into incidents

Own secure-by-design evidence, EN 18031/CRA Annex I assessments, fuzzing/pen-test programmes, the vulnerability register and advisories

Work alongside engineering, product, and operations teams as a trusted security partner — offering patterns, guidance, and guardrails rather than acting as a gatekeeper

Play a part in detecting, investigating, and containing security incidents, and push for lasting fixes based on what we learn

Cut down on manual, reactive security work through automation, better tooling, and secure-by-default habits built into how we develop and run systems

Apply technical rigour to assurance work like audits, certifications, and customer security reviews — making sure our controls hold up in practice, not just on paper

WHAT WE VALUE

Deep, hands-on skill in one or two security domains — application security, cloud security, identity and access management, cryptography, detection and response, or platform security — backed by real evidence of impact

An instinct for trust boundaries, failure modes, blast radius, and attacker behaviour, rather than viewing vulnerabilities in isolation

A knack for turning complex security risk into terms that land with engineers, product managers, and senior leadership alike, and for shaping outcomes through persuasion rather than title

A risk-based approach — weighing decisions proportionately under uncertainty, and always asking whether the work cuts real risk rather than just checking a compliance box

Comfort juggling multiple teams and technical domains at once without losing quality or judgement

A history of finding gaps and pushing security fixes through to completion, even in messy or loosely defined problem spaces

BONUS POINTS

Time spent in or around regulated, high-assurance, or defence-adjacent settings where security demands are intricate and failure carries real weight

Practical offensive security background — red teaming, penetration testing, or adversarial simulation — that shapes how you think about defensive design and threat modelling

Awareness of security issues unique to AI or machine learning systems, such as model integrity, data pipeline security, or adversarial ML

A hand in building security programmes at scale — security champions networks, secure development lifecycle tooling, or company-wide risk frameworks

A background in cloud-native security engineering, especially across AWS, GCP, or Azure, spanning infrastructure-as-code, container security, and cloud identity patterns

Some exposure to supply chain security issues, such as dependency management, build pipeline integrity, or third-party component assurance

Experience working with classified data, government security frameworks, or cross-domain security requirements

WHAT WE OFFER

Competitive compensation

Equity — meaningful options as an early employee at an early-stage company

Private healthcare, dental & optician

Real field exposure — travel to Arctic sites and Outposts when needed (genuinely, not as a gimmick)

Mission-driven culture — focus on impact, not hours logged

Small team, real ownership — what you build matters and ships

Find more English Speaking Jobs in United Kingdom on Arbeitnow

You will apply. Then you will hear nothing.

And no one will tell you what was wrong. See it before you send: your ATS score, every weak line, and the fix for each.

  1. 1

    Drop in your CV

    One PDF, thirty seconds. No card.

  2. 2

    See what is wrong with it

    Every weak passage, quoted from your own CV, with the line to replace it.

  3. 3

    Apply where you fit

    Every European role ranked against what your CV actually says.

  • Free, no card
  • Your CV file is deleted after parsing
  • Or skip the upload — build your profile by hand
  • Refreshed every 6 hours