Smarsh

Product Security Engineer

London, England, United Kingdom

Not SpecifiedCompensation
Mid-level (3 to 4 years), Senior (5 to 8 years)Experience Level
Full TimeJob Type
UnknownVisa
Biotechnology, SoftwareIndustries

Product Security Engineer

Employment Type: Full-Time

Position Overview

Smarsh empowers its customers to manage risk and unleash intelligence in their digital communications. Our growing community of over 6500 organizations in regulated industries counts on Smarsh every day to help them spot compliance, legal or reputational risks in 80+ communication channels before those risks become regulatory fines or headlines. Relentless innovation has fueled our journey to consistent leadership recognition from analysts like Gartner and Forrester, and our sustained, aggressive growth has landed Smarsh in the annual Inc. 5000 list of fastest-growing American companies since 2008.

We're seeking a Product Security Engineer to support secure development across our engineering teams. In this hands-on role, you'll help identify and mitigate product risks by participating in security reviews, improving tooling, and supporting vulnerability remediation. You'll work closely with senior security engineers and cross-functional teams to build security into our software development lifecycle.

This is a great opportunity for a security-minded engineer who wants to grow their technical breadth while making meaningful impact in a cloud-first, DevOps-centric environment. You must be comfortable working as part of a global team in a dynamic, fast-paced environment. Collaboration across time zones and geographies is a key part of our culture and success.

Responsibilities

  • Secure SDLC Support: Assist in integrating security practices into the software development lifecycle, including design reviews and backlog grooming.
  • Threat Modelling: Participate in structured threat modelling exercises with guidance from senior team members.
  • Vulnerability Triage: Work with engineering teams to review findings from SAST, SCA, DAST, and container scans and track remediation progress.
  • Code & Config Review: Conduct basic secure code and configuration reviews, escalating high-risk findings as needed.
  • Security Tooling & Automation: Help maintain and enhance security scanning integrations in CI/CD pipelines.
  • Pen Testing Coordination: Assist in preparing for and triaging internal and third-party penetration tests.
  • Security Documentation & Guidance: Help develop security best practices, developer guidance, and response runbooks.

Requirements

  • 4 years in security engineering, DevSecOps, application security, or related software engineering roles.
  • Strong foundational knowledge of secure coding and OWASP Top 10 risks.
  • Experience with at least one modern programming language (e.g., Python, Java, JavaScript, Go, or C#).
  • Familiarity with cloud platforms (AWS, Azure, or GCP) and container technologies (Docker, Kubernetes).
  • Exposure to security tooling such as SAST, SCA, or DAST scanners (e.g., Semgrep, Endor, Burp).
  • Basic understanding of identity and access controls (OAuth, SAML, API tokens).
  • Strong collaboration and communication skills, with a willingness to learn and grow.

Preferred Qualifications

  • Experience working in Agile/Scrum teams or DevOps environments.
  • Familiarity with CI/CD tools like GitHub Actions or Jenkins.
  • Exposure to security frameworks (NIST, ISO 27001, SOC 2).
  • Experience working in SaaS, multi-tenant cloud environments.
  • Knowledge of machine learning security (AI/ML model risks, LLM security best practices).
  • Familiarity with attack surface management and threat intelligence.
  • Relevant certifications (e.g., Security+, SSCP, GSEC) are a plus but not required.

Company Information

Smarsh empowers its customers to manage risk and unleash intelligence in their digital communications. Our growing community of over 6500 organizations in regulated industries counts on Smarsh every day to help them spot compliance, legal or reputational risks in 80+ communication channels before those risks become regulatory fines or headlines. Relentless innovation has fueled our journey to consistent leadership recognition from analysts like Gartner and Forrester, and our sustained, aggressive growth has landed Smarsh in the annual Inc. 5000 list of fastest-growing American companies since 2008.

What We Offer

  • Competitive salary along with company bonus
  • Strong maternity and paternity scheme
  • A workplace pension scheme
  • Take what you need holiday package
  • Private medical insurance
  • Dental plan
  • Group life assurance
  • Group income protection
  • Employee assistance programme
  • A monthly wellness allowance
  • Adoption assistance
  • Stock options

Don't meet every requirement? Apply anyway! We value diverse candidates and encourage applications, even if you don't perfectly match the job description. Studies have shown that some individuals are less likely to apply for jobs unless they meet every qualification.

Skills

Product Security
Secure SDLC
Threat Modelling
Vulnerability Triage
SAST
SCA
DAST
Container Scans
Secure Code Review
Configuration Review
Security Tooling
Automation
DevOps
Cloud-First

Smarsh

Archiving and compliance solutions provider

About Smarsh

Smarsh provides archiving and compliance solutions specifically designed for financial services, government agencies, and other regulated industries. Their main product is a cloud-based archive that allows organizations to securely store, search, and manage their communications data, including emails, text messages, and social media interactions. This system helps businesses meet complex security, data privacy, and regulatory requirements. Smarsh differentiates itself from competitors by offering a scalable Software-as-a-Service (SaaS) model that caters to both large enterprises and smaller organizations, ensuring that clients can adapt to evolving regulations. Their goal is to help organizations efficiently manage their communication data, identify risks, and maintain compliance, particularly through tools like Connected Capture for Microsoft Teams, which supports remote workforces.

Portland, OregonHeadquarters
2001Year Founded
$42.4MTotal Funding
BUYOUTCompany Stage
Enterprise Software, Cybersecurity, Financial ServicesIndustries
1,001-5,000Employees

Benefits

Health Insurance
Dental Insurance
Life Insurance
Disability Insurance
Unlimited Paid Time Off
Paid Vacation
Paid Sick Leave
Paid Holidays
Hybrid Work Options
Stock Options
401(k) Company Match
Employee Assistance Programme
Wellness Program
Adoption Assistance
Group Income Protection
Group Life Assurance
Maternity Leave
Paternity Leave
Workplace Pension Scheme
Monthly Wellness Allowance
Company Bonus

Risks

Integration with OpenAI's API may pose compliance and security challenges.
EU's AI Act requires significant adjustments to Smarsh's AI systems.
Expansion into Latin America may expose Smarsh to regional instability.

Differentiation

Smarsh offers cloud-native, context-aware archiving solutions for regulated industries.
The company integrates with popular tools like Microsoft Teams for seamless compliance.
Smarsh serves 9 of the top 10 banks, showcasing its industry trust.

Upsides

Smarsh's global expansion includes a new office in Costa Rica for enhanced support.
Integration with OpenAI's ChatGPT API enhances Smarsh's AI compliance capabilities.
Partnership with Verizon simplifies mobile compliance procurement for Verizon's clients.

Land your dream remote job 3x faster with AI