Jobs

Product Security Engineer (3496)

About GBG

GBG is the leading expert in global digital identity. We combine our powerful technology, the most accurate data coverage, and our talented team to deliver award-winning location intelligence, identity verification, and fraud prevention solutions.

With over 30 years’ of experience, we bring together a team of over 1,250 dedicated experts with local industry insight from around the world to make it easy for businesses to identify and verify customers and locations, protecting everyone, everywhere from fraud.

Why you should be@GBG

(with the 95% of our team members that recommend us as a great place to work)

  • We make the world a safer place
  • We trust each other and win together
  • We are local experts in a global business
  • We want you to be yourself
  • We grow when you grow

The Team

GBG’s Information Security team of c30 team members, enable delivery of GBG’s business strategy by ensuring GBG is secure and trusted. The team provides four core capabilities:

  • Governance, Risk and Compliance.
  • Cyber Defence.
  • Product Security.
  • Security Architecture.

What you will do

  • Collaborate with business units and development teams to design and implement effective security controls for products throughout their lifecycle.
  • Conduct security assessments and threat modelling exercises to identify potential risks and vulnerabilities in our products.
  • Guide and advise business units on risk decisions, considering the business's risk appetite and regulatory requirements.
  • Develop and maintain product security guidelines, standards, and best practices.
  • Participate in the design and implementation of secure development practices, including secure coding standards and processes.
  • Work closely with development teams to ensure that security requirements are appropriately addressed during the software development lifecycle.
  • Conduct security reviews of product architecture and design, identifying and addressing security gaps.
  • Perform security testing and code reviews to identify and remediate security vulnerabilities.
  • Collaborate with incident response teams to investigate and respond to security incidents related to products.
  • Stay updated with the latest security threats, vulnerabilities, and industry best practices, and proactively propose security enhancements.

Requirements

What We're Looking For

  • Extensive commercial experience in product facing security engineering or a similar role.
  • Strong understanding of software security principles, secure coding practices, modern development technologies and common security vulnerabilities.
  • Experience with threat modelling, security assessments, and risk analysis.
  • Knowledge of industry standards and frameworks such as CIS Top 18, OWASP, NIST, and ISO 27001.
  • Familiarity with secure development lifecycle methodologies.
  • Proficiency in security testing tools and techniques.
  • Excellent communication skills to effectively collaborate with cross-functional teams and communicate complex security concepts to technical and non-technical stakeholders.
  • Relevant certifications such as cloud native paths, GIAC, or alternative are a plus.

Behaviours we'd like to see

Benefits

To find out more

Click here to see more about what’s important to us, including our Work When and Where You Want policy, our commitment to ESG, I&D and much more.

To chat to the Talent Attraction team and find out more about our benefits, drop an email to [email protected] and we’ll be in touch!

Make life@GBG work for you.

Cyber Security Jobs by Category

Cyber Security Salaries