About this job
<div><strong style="font-size: 16px;">About Numan </strong></div>
<div> </div>
<div><span style="font-size: 16px;">Founded in 2018, we’ve already grown to be a 300+ team distributed across the globe, united by a singular mission: empowering people to take control of their health.</span></div>
<div> </div>
<div><span style="font-size: 16px;">Numan is transforming health: we’ve built a cutting-edge platform that integrates diagnostics, medication, supplements, digital programmes, and doctor consultations. Giving people the tools they need to maximise life.</span></div>
<div> </div>
<div><span style="font-size: 16px;">To deliver on our transformative mission, we are guided by our 5 company values: </span></div>
<div> </div>
<div><span style="font-size: 16px;">• Patients first.</span></div>
<div><span style="font-size: 16px;">• Learn fast.</span></div>
<div><span style="font-size: 16px;">• Own the quality.</span></div>
<div><span style="font-size: 16px;">• Succeed together.</span></div>
<div><span style="font-size: 16px;">• Care deeply.</span></div>
<div> </div>
<div><span style="font-size: 16px;">Backed by top-tier investors, Numan is already having a positive impact on hundreds of thousands of patients here in the UK, and we want you to help us deliver this mission!</span></div><div><br></div><div>
<p><strong>The Role</strong></p>
<p>We build and operate a regulated digital health platform. Patients trust us with clinical data, identity documents and payment details, and our clinicians trust our systems to be correct. That makes application security a patient safety concern, not just a compliance one.</p>
<p>We are shipping quickly, adopting AI and agentic systems across clinical operations and patient-facing products, and running a lean security function that scales through engineering leverage rather than headcount. We need a senior engineer who can go deep on design and code, then bring the rest of the business along with them.</p>
<p>This is a hands-on individual contributor role with genuine influence over how the platform is built.</p>
<p><strong>The Team</strong></p>
<p>You will work within the Cyber Security function, collaborating directly with Engineering, Product, Clinical, Legal, and the executive team. Security at Numan is not a gatekeeping function — it scales through influence, credibility, and being useful early.</p>
</div><br><strong>You'll be:</strong><br><div>
<li>
<p>Running threat modelling sessions with product and engineering teams on new features and architectural changes — STRIDE-based, with clinical safety, abuse, and business-logic threats kept in mind alongside the technical ones.</p>
</li>
<li>
<p>Owning and evolving our Secure by Design process: self-evaluation screening, secure design review, and the threat modelling pathway, including our use of automated tooling against technical artefacts.</p>
</li>
<li>
<p>Turning threat models into tracked, prioritised controls that engineering teams actually implement.</p>
</li>
<li>
<p>Pushing design decisions upstream so the cheap fix is designed in rather than the expensive one retrofitted.</p>
</li>
<li>
<p>Assessing and securing AI systems in production: LLM-backed features, retrieval pipelines, agentic workflows, tool-calling integrations, and the MCP and API surfaces that connect them.</p>
</li>
<li>
<p>Building practical threat models and controls for agent-specific failure modes — prompt injection, tool misuse, excessive agency, data exfiltration through context, unsafe autonomy, and supply chain risk in model and plugin ecosystems.</p>
</li>
<li>
<p>Performing automated application and API penetration testing against our own products — web, mobile backends, cloud-native services on GCP, internal tooling, and AI features.</p>
</li>
<li>
<p>Leading penetration engagements with third parties and working on the fix with engineering.</p>
</li>
<li>
<p>Chaining findings into realistic attack paths and demonstrating impact, rather than delivering a list of scanner output.</p>
</li>
<li>
<p>Embedding security into our pipelines: SAST, SCA, secrets detection, IaC scanning, container and dependency hygiene — tuned so signal beats noise and engineers trust the gates.</p>
</li>
<li>
<p>Working with platform and engineering to raise baseline standards: authentication and authorisation patterns, secrets management, tenancy isolation, and logging and detection coverage.</p>
</li>
<li>
<p>Actively participating in the security community — OWASP chapters or projects, local meetups, CTFs, research groups — and publishing research, write-ups, or blog posts under your own name.</p>
</li>
</div><br><strong>We're looking for someone who:</strong><br><div>
<li>
<p>Brings substantial hands-on application security experience in a product engineering environment, at senior level.</p>
</li>
<li>
<p>Has demonstrable threat modelling practice — not just familiarity with the theory.</p>
</li>
<li>
<p>Has practical offensive skills against modern web and API stacks, with an appropriate certification or equivalent demonstrable experience (OSCP, OSWE, CREST, Burp Suite Certified Practitioner or similar).</p>
</li>
<li>
<p>Is comfortable reading and reasoning about code in at least one language used in production systems, and can review a pull request meaningfully.</p>
</li>
<li>
<p>Has working knowledge of cloud-native architecture and its security model — ideally GCP, but AWS or Azure experience transfers.</p>
</li>
<li>
<p>Has experience integrating security tooling into CI/CD, and the scars to know what makes engineers ignore it.</p>
</li>
<li>
<p>Has a track record of shipping security improvements through other teams.</p>
</li>
<li>
<p>Has experience securing AI or agentic systems in production.</p>
</li>
<li>Has hands-on experience securing Kubernetes environments and managing cloud security posture using CNAPP and CSPM solutions, with a primary focus on GCP but AWS and Azure experience is translatable.</li>
</div><br><strong>It’s a bonus if you have:</strong><br><div>
<li>
<p>Regulated environment experience — healthcare, fintech, or similar — and comfort with frameworks such as ISO 27001 without treating compliance as the goal.</p>
</li>
<li>
<p>Detection engineering or incident response exposure for incidents related to application attacks.</p>
</li>
<li>
<p>An existing community footprint: talks, published research, maintained projects.</p>
</li>
</div><div><strong style="font-size: 16px;">Our benefits include...</strong></div>
<div> </div>
<div><span style="font-size: 16px;">📈 - Share options.</span></div>
<div><span style="font-size: 16px;">🏖 - 25 days holiday, plus bank holidays (increasing to 30 the longer you stay with Numan). </span></div>
<div><span style="font-size: 16px;">🩺 - Health insurance with </span><a href="https://www.vitality.co.uk/" style="font-size: 16px;">Vitality</a><span style="font-size: 16px;">.</span></div>
<div><span style="font-size: 12pt;">🚘 - Electric car salary sacrifice scheme with </span><a href="https://octopus.energy/" style="font-size: 12pt;">Octopus</a><span style="font-size: 12pt;">. </span></div>
<div><span style="font-size: 16px;">🧸 - Enhanced maternity and parental leave.</span></div>
<div><span style="font-size: 16px;">🥳 - A day off on your Birthday! </span></div>
<div><span style="font-size: 16px;">🐥 - Nursery benefit provided by </span><a href="https://t.eu.lever-analytics.com/email-link?dest=https%3A%2F%2Fwww.yellownest.co.uk%2F&eid=6e6c0e9a-759a-40bb-9652-414e62aca13d&idx=1&token=Gvi_-dygDyEsLomYdt9DxV5Kh4g" style="font-size: 16px;">YellowNest</a><span style="font-size: 16px;">.</span></div>
<div><span style="font-size: 16px;">💼 - Employee assistance programme (access to therapy, financial planning and discounts).</span></div>
<div><span style="font-size: 16px;">⚖️ - Generous pension (includes both employee and employer contributions).</span></div>
<div><span style="font-size: 16px;">💻 - Flexible working options, including a dog-friendly office in Farringdon. </span></div>
<div><span style="font-size: 16px;">📚 - Personal training and development budget via Learnerbly. </span></div>
<div><span style="font-size: 16px;">👟 - Wellhub membership, giving you access to over 2,000 locations in the UK. </span></div>
<div><span style="font-size: 16px;">🚲 - Cycle to work scheme.</span></div>
<div><span style="font-size: 16px;">🚆 - Season ticket loan. </span></div>
<div><span style="font-size: 16px;">% - Discount on Numan products for your friends and family.</span></div>
<div><span style="font-size: 16px;">🤲 - Paid volunteering days. </span></div>
<div><span style="font-size: 16px;">📅 - An additional 2 weeks off once you reach your 5th anniversary with Numan.</span></div>
<div> </div>
<div><strong style="font-size: 16px;">Diversity at Numan</strong></div>
<div> </div>
<div><span style="font-size: 16px;">At Numan, people are at the heart of who we are. We recognise and value the unique perspectives and experiences that individuals from all backgrounds bring.</span></div>
<div> </div>
<div><span style="font-size: 16px;">We promote innovation and creativity, enabling us to tackle things from various viewpoints and are committed to equal opportunities and continuously strive to create a workplace where everyone feels respected, heard, and valued.</span></div>
<div> </div>
<div><span style="font-size: 16px;">Embracing diversity isn't just our goal; it's our strength, driving us towards a more inclusive future.</span></div><p>Find <a href="https://www.arbeitnow.co.uk">Jobs in United Kingdom</a> on Arbeitnow</a>