
Posted: 26 August 2026
The Opportunity
Surevine's mission is to build and deliver secure, scalable, collaboration solutions for the most security conscious organisations, enabling collaboration on their most highly sensitive information.
Our customers trust us with their most sensitive information. That trust has to be earned twice: in how we build our products, and how we run ourselves.
This is a new role. Your first job is to take ownership of security across our own estate — our corporate services, our cloud environments and the standards we hold ourselves to. Your second is to work alongside our engineering teams so that what we build for customers is secure-by-design. You'll do both by getting into the detail of how we engineer, not by writing policy about it.
We are not expecting you to arrive able to do all of this. This is a role with room to grow into, and we would rather hire someone with the right foundation and appetite than wait for someone who ticks every box.
Security in Surevine
We are a small company, so this is a broad job rather than a narrow one. You will move between looking after our own estate, working alongside our engineering teams on the security of what we build and over time, working directly with customers.
ISO 27001, Cyber Essentials, Cyber Essential Plus, Defence Cyber Certification and the standards our sector demands are real and they matter. But we want them woven into how we work rather than bolted on afterwards. If your instinct when you see a gap is to write a procedure, this isn't the role. If your instinct is to work out what would actually close it and then help get that change made, it just might be.
There is a path into client-facing work as you grow into the role. Our customers in government, defence and critical national infrastructure need help with secure design, security architecture, assurance evidence and integrating with their own security operations. This isn't where you'll start: the first job is our own house. But if being in the room with a customer and producing work that goes to their security authority with our name on it is somewhere you want to get to, even better.
We are actively using AI tools across our development work and inside the business. That changes the security picture; new data handling questions, new governance questions that nobody has settled answers to yet. We want someone curious about that rather than defensive.
What you will be doing
Below are the key aspects of the role, roughly in order of priority, but we will work with you to find approaches that play to your strengths while achieving our shared goals.
- Take ownership of security across our corporate estate — our SaaS applications, our identity provider, our endpoints and our AWS-hosted environments — driving the plan and getting stuck into the work alongside our InfraCare team
- Make our ISO27001 and Cyber Essentials obligations business-as-usual; automated where it can be and evidenced as a by-product of how we work
- Help us build the visibility we need: logging, monitoring and alerting good enough that we find out about problems ourselves rather than being told about them
- Take part in security reviews and help our engineers run their own
- Play a leading role when something goes wrong: running the process, knowing when to escalate, and liaising with clients, internal teams and support partners
- Advise our engineering teams on the security of what we build; contributing to design workshops, challenging assumptions early, and helping teams reach good security decisions without stalling delivery
- Own our security risk picture and make it useful: understood by the board, owned by the people who can act on it, and reviewed often enough to mean something
- Be the person who answers hard security questions from customers, prospects and their assurance teams — security questionnaires, supplier assessments, and the evidence behind our claims
The environment you will be working in
We don't expect experience across all of this. We do expect curiosity about it.
- Our corporate estate: Google Workspace, SaaS applications, endpoints, identity and access managemen
- Our cloud platforms: AWS, GCP, containerised workloads
- Our delivery tooling: GitLab CI/CD, Terraform and Pulumi
- Our products, built in Typescript, Python and Java, deployed to customer environments including some that are highly restricted
- AI-assisted development tooling across our engineering teams, and AI tooling across the wider business
How we will support you
We know we are asking for range, and that nobody arrives with all of it. We will back you with:
- Time and budget for structured learning and professional certification
- Working alongside our InfraCare team, who know our estate inside out
- External specialist support where it makes sense, particularly around certification and assessment
- Direct access to our CISO, who has been carrying much of this thinking so far
- Clear agreement, up front, on what we expect you to own in year one and what can wait
About you
We value diverse thinking styles and backgrounds. You don't need to match every point below perfectly; we are interested in your overall fit and potential.
- 3-5 years experience in security, security risk, or a related technology role
- Working knowledge of ISO 27001, Cyber Essentials and comparable frameworks as a practitioner who has implemented controls, not only assessed them
- Some exposure to cloud and SaaS security; identity and access management, logging, configuration hardening etc. and an appetite to take that further
- Comfortable thinking about security risk end to end; spotting it, getting it owned by the right person, tracking what happens next, and reporting it honestly to people who will act on it
- Credible with engineers. You will be advising people who build secure systems for a living, so you need to be curious about how they work and specific about what you're asking for
- Comfortable facilitating a room; design workshops, threat modelling sessions, risk reviews
- Able to explain security trade-offs to engineers, to executives and to customers, and to adjust the explanation for each
- Security-conscious pragmatism. We need someone who can tell the difference between a risk worth stopping for and a risk worth documenting and moving past
- Able to communicate effectively in a remote environment through written and verbal channels. We accommodate different communication preferences and styles, and value clarity over any particular communication approach
Working at Surevine
We're committed to building an inclusive environment where diverse perspectives and working styles strengthen our team. We:
- Provide reasonable accommodations throughout the application and employment process
- Support different communication and collaboration preferences
- Offer flexible working arrangements
- Value both collaborative work and focused individual contribution time
- Provide clear expectations, structured onboarding, and ongoing mentorship
If you need any accommodations during the application process or have questions about how we work, please let us know.
.png&w=3840&q=75)





