See how much of this job your resume covers, and what’s missing.
Want a recruiter to go through it line by line?
Get professional reviewUpload your resume and we draft a letter for this exact role, tailored to what it asks for.
You will own security engineering outcomes by building scalable tooling, processes, and security practices across engineering teams. You will also act as a subject matter expert to coach teams, conduct threat modeling, and manage security incident response.
Would you like to create the future of a product used by thousands of businesses and millions of consumers? Phorest Salon Software powers over 11,000 hair and beauty salons in Ireland, UK, Germany, Australia, Finland, USA, Canada, UAE and Netherlands and the platform processes 7 million appointments a month for hair and beauty consumers. Phorest is the number 1 salon software brand for premium independent salons in those markets and our next goal is to become a platform upon which other companies can build applications for premium salons.
Our system touches every point of the salon experience. We have the in-salon software desktop application, Phorest Go (the native staff application), online bookings website for salons, and custom native apps per salon. In a typical month, Phorest processes 3 million appointments and we send over 3 million SMS and 4 million emails. We process 200k online bookings per month and over 150 custom built white label native apps.
We’re adding to our security capability and we are looking for someone who can move the needle, not a ticket-taker, but an experienced engineer who takes initiative, builds things, and genuinely partners with our product and engineering teams and the wider business. You’ll use your deep security expertise not only to solve complex problems, but to raise the security capability of the teams around you.
Reactive work eats into time that should be spent on proactive, strategic programmes. You will change that dynamic: by building security tooling and processes that scale, identifying risks and capability gaps, and turning them into impactful improvements. By embedding yourself in our engineering culture you’ll make security an integral part of how teams build and enable engineers to make good security decisions.
You will function primarily as an enabler, working across our stream-aligned engineering teams to build security knowledge, tooling, and practice where the work actually happens. An integral part of your impact will come through coaching others, sharing knowledge and creating scalable practices that raise the security bar for our Engineering Team.
You will own security engineering outcomes - acting as SME, identifying cross-functional opportunities, and driving improvements through to impact.
Security Platform & Developer Tooling
Partner with engineering teams to introduce tooling that makes secure coding the path of least resistance. Identify opportunities to improve the security experience and take ownership of delivering improvements that materially reduce risk or friction.
Collaborate with platform engineers to weave security into CI/CD pipelines, our cloud environment and code review workflows, without creating friction or bottlenecks. Establish reusable patterns and practices that enable teams to adopt secure-by-default approaches.
Work with engineering leads to identify and prioritise process & tooling improvements against our real risk landscape, building shared agreement on what matters most.
Developer Enablement & Partnership
Proactively identify security knowledge and capability gaps, and build confidence across Phorest engineering through collaborative threat-modelling sessions, documentation, and hands-on pairing, so teams can make good security decisions independently.
Embed with stream-aligned product teams at key stages like design, architecture review, pre-launch to provide security input as a trusted peer, not an external auditor. Coach teams through complex security decisions, helping them build their own capability.
Act as a subject matter expert and trusted partner between Security and Product & Engineering, helping teams understand security and compliance requirements.
Share security learnings, emerging threats and lessons from incidents across Engineering, creating reusable guidance that raises the baseline of secure engineering and proactively creates awareness for how teams consider security.
Security Monitoring & Risk Understanding
Work alongside the broader security and IT team to proactively monitor security signals and alerts, identify patterns and build shared situational awareness across the team.
Identify and assess emerging security risks and opportunities, conduct exploratory risk analysis that shapes the security programme roadmap, bringing in the engineering perspective you've built through close team relationships.
Build out security requirements and review processes for our AWS-hosted, multi-tenant SaaS environment.
Contribute to the on-call rota, providing security coverage for incidents as they arise.
Support security incident response end to end, from initial triage and containment through to post-incident review and remediation tracking.
You take initiative.
We’re looking for someone that creates momentum over responding to demand, we need someone who sees a risk or an opportunity, develops a point of view, and moves, keeping stakeholders informed along the way. You are comfortable defining the problem, deciding your approach and owning the outcome.
You can bridge technical and non-technical worlds.
Phorest's engineering teams are sharp and want genuine security partnership, but not everyone in the company is technical, so you will need to be credible with both explaining risk clearly to technical and non technical audiences, and translating security requirements into practical engineering guidance.
You have a proactive growth mindset.
You seek feedback, challenge the status quo, embrace ambiguity and turn what you learn into action — sharing knowledge and raising the capability of those around you.
You are technically grounded.
Demonstrable Hands-on secure development experience (preferably 7+ years); you have written production code at some point in your career.
Deep enough experience in a security engineering or application security role to act as a subject matter expert for complex security challenges..
Comfortable using AI tools to accelerate security work, generating, and analysing at pace while keeping your human judgment at the center of every decision.
Strong working knowledge of AWS security, IAM, GuardDuty, Security Hub, WAF, and related services.
Familiarity with common vulnerability classes, OWASP, and secure SDLC frameworks.
Comfortable working across SaaS, multi-tenant architectures.
You bring the soft skills.
Strong communicator, written, verbal, and async.
Able to build trust with engineering teams without relying on authority.
Proactive in keeping stakeholders informed; you surface problems early rather than waiting to have answers.
Comfortable working in a distributed team where you own outcomes end to end.
NICE TO HAVE
Experience working in a payments or regulated SaaS environment (PCI DSS, GDPR, HIPAA).
Familiarity with Team Topologies or other platform/enabling team models.
Exposure to offensive security techniques, penetration testing, red teaming, or bug bounty.
Experience building security enablement or champion programmes that improve security capability and ownership across an engineering organisation.
🧘 Your wellbeing is important to us - we provide private healthcare, 2 Wellness Days, an employee assistance program and a free online GP service.
💰 As part of our Financial Wellbeing, we provide competitive Compensation, an Employee Share Purchase Scheme, Pension, Life Assurance, and Income Protection.
🚵🏿 We help you travel by providing a bike to work scheme as well as tax saver transport tickets.
🦸♀️ We support the women who work in Phorest by offering 2 weeks leave for Fertility Treatment, Pregnancy Loss and Menopause.
🍼 We care for your family and provide Enhanced Maternity and Paternity Benefits.
🌳 We grow our own timber! We provide a great learning environment and extensive development opportunities. We run development programs and provide access to many online resources including LinkedIn learning.
🏠 Moving house? Phorest employees get 3 moving days.
Want to learn more about Phorest? Check out nothingventured.rocks for our blog and Insights on building an evergreen company from the team here at Phorest.
Phorest is an equal opportunity employer. For this position, flexi-time and working from home is possible. We are also open to remote work. Get in touch to ask for more information or to chat about your future with Phorest!
Research shows that while men apply to jobs when they meet an average of 60% of the criteria, women and other marginalised folks tend to only apply when they check every box. So if you think you have what it takes, but don't necessarily meet every single point on the job description, please still get in touch. We'd love to have a chat and see if you could be a great fit.
Stop the endless job search. Our AI finds and applies to the best jobs for you.
Featuring 220,032+ Jobs in Software Development
Answer easy questions
220,032+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”