BibliU
Senior Security Engineer
Remote
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Role family
- Engineering
- Seniority
- Senior
- Country
- GB
- Work mode
- Remote-friendly
- First seen by hirly
- 10 Oct 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Position Title: Senior Security Engineer
Reports to: VP Engineering
Location: UK, Remote
Contract Type: Full-Time, Permanent
About BibliU
BibliU is an award-winning, technology-led B2B company transforming the $65bn educational content industry. With a 90% CAGR the past 5 years, we are just getting started. We've cracked the code on Day 1 access to affordable digital course materials for students, while delivering comprehensive campus store solutions that foster human relationships, and increase our stickiness in the world of AI.
The result? Measurable impact: 10% higher student retention, 1-point GPA increases, and partnerships with 170 universities serving 600,000 students each year.
We've fundamentally changed how universities procure, distribute, and manage learning content. We partner with 4,000+ publishers, including Pearson, Oxford University Press, and Wiley to deliver content to universities, and provide rich engagement data and interactive tools like quizzes that help students actually learn.
Here's what makes our story compelling:
Founded in late 2015 as an Oxford University spin out, we've grown explosively with 90% CAGR over the last five years, including 65% in FY25, reaching $100m in annual revenue. Our Series B raised $23m led by Nesta Impact Investments (with Guinness Asset Management, Stonehage Fleming, and Oxford Sciences Enterprises). In late 2023, we acquired Texas Book Company (now 'BibliU Campus') to become the only fully vertically integrated player in the market, driving US organic growth which now represents 90% of our business.
We're hungry for more. We're actively building our M&A pipeline as we compete head-to-head against legacy bricks-and-mortar providers to improve the faculty and student experience while boosting the financial sustainability of universities.
Our culture is collaborative, high-growth, and agile. You’ll join an experienced and motivated executive team with backgrounds from Instructure (Canvas) and other successful edtech companies with exit experience. We operate as a distributed team across the UK and US, with offices in London.
Position Overview
We're hiring a Security Engineer to own the security posture of our platform and production workloads. This is a hands-on engineering role sitting at the intersection of architecture, engineering and security. You’ll make sure security is designed into systems rather than bolted on afterwards, test whether our security assumptions and controls actually work, and help teams build systems that remain secure and resilient when things go wrong. Your role will include running offensive testing against our own infrastructure.
A significant part of the role is securing how we build and ship AI products. As teams move faster with AI-assisted development, you'll define the sandboxing, isolation, permissions and guardrail patterns that let that happen safely, and tune them as the tooling and threat landscape change.
You'll work in close partnership with Engineering and our AI practice, embedded in design reviews and delivery work rather than reviewing from the outside. Our IT function leads compliance administration, you’ll provide the engineering expertise and technical controls needed to support SOC 2, GDPR and PCI DSS obligations. We value evidence over assumptions - we want to know whether security measures work in practice, not simply whether they exist.
What you will be doing:
Own the engineering implementation and continuous improvement of security controls supporting SOC 2 Type II, working with IT on evidence collection and external audits
Act as the security partner in architecture and design reviews, setting secure-by-default patterns for new services, data flows, and integrations, while making pragmatic trade-offs between risk and delivery
Design, propose, and tune sandboxing and isolation models for AI-assisted and AI-generated code, including execution boundaries, secrets handling, permissions, dependency controls, and output validation
Own our offensive security testing, combining internal application, cloud and infrastructure testing with third-party penetration testing where useful; test whether important security assumptions actually hold, and verify remediation
Maintain and extend our GDPR and PCI DSS control posture, working with Legal, Finance, and Engineering on data mapping, retention, cardholder-data scope, and DPIAs
Work with Platform Engineering to tune security tooling and automation across the SDLC: SAST, DAST, dependency and container scanning, IaC policy checks, and CI/CD gates - focussing on high-signal, actionable checks and removing controls or gates that create friction without materially reducing risk
Lead threat modelling for high-risk services and AI features, and translate findings into prioritised, actionable engineering work
Work with Engineering to improve detection and response capability: logging coverage, alerting quality, runbooks, and participation in incident response
Support customer and prospect security reviews, questionnaires, and due diligence with accurate, evidence-backed responses
Raise the security baseline across engineering through guidance, tooling, and enablement rather than gatekeeping
What we are looking for
Must have:
5+ years in a security engineering, application security, or cloud security role, with meaningful time spent hands-on rather than purely advisory
Direct experience operating or contributing to SOC 2 Type II controls in a live environment, not just preparing for an initial audit, but sustaining and evidencing controls over time
Practical penetration testing skills: web application, API, and cloud infrastructure testing, with the ability to run assessments internally and validate third-party findings
Strong cloud security background (AWS): IAM design, network segmentation, encryption, secrets management, and workload isolation
Working knowledge of PCI DSS requirements and how to scope, segment, and evidence a cardholder-data environment
Solid grasp of GDPR as it applies to engineering: lawful basis, data minimisation, retention, subject rights, cross-border transfers, and sub-processor management
Secure architecture and threat modelling experience across distributed, service-based systems
Strong hands-on engineering ability: able to read and reason about application code, write scripts and automation, and integrate security checks into CI/CD
Experience securing containerised workloads and infrastructure-as-code (Kubernetes, OpenTofu, or equivalents)
Ability to influence engineers and product teams without authority, make pragmatic risk trade-offs rather than absolutist ones, and challenge security controls that create cost or friction without proportionate benefit
Clear written communication: you'll be producing control documentation, findings, and customer-facing security responses
Experience securing AI/LLM systems: prompt injection, tool-use and agent permissions, model and data exfiltration risks, RAG pipeline security, and evaluation of AI-generated code
Good to have:
Exposure to ISO 27001, or experience running a multi-framework compliance programme
Offensive security certifications (OSCP, OSWE, GWAPT) or equivalent demonstrable experience
Detection engineering and SIEM experience, including writing and tuning detections
Familiarity with AI security frameworks such as the OWASP Top 10 for LLM Applications, NIST AI RMF, or ISO/IEC 42001
Experience in a high-growth SaaS environment, particularly one handling sensitive personal data at scale
Background in EdTech, or experience with sector-specific requirements such as accessibility, student data privacy (FERPA), or institutional procurement security reviews
Experience using controlled security experiments, incident simulations, chaos engineering, or similar techniques to test how systems behave when assumptions or safeguards fail
Prior
Listed on hirly, a job board. hirly is not the employer: BibliU is hiring for this role.
Similar jobs
- Senior Offensive Security EngineerDrweng · LondonFirst seen 3d ago
- Senior Product Security EngineerTrainline · LondonFirst seen 7d ago
- Senior Cloud Security EngineerBupa · 3 LocationsFirst seen 9d ago
- Senior Information Security EngineerMyhcm · North London, UKFirst seen 10d ago
- Senior Security Engineer - SecOpsMozilla · Remote UKFirst seen 10d agoremote
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job