The work

You work with our Head of Security across every project: reviewing designs before they are built, testing them before they ship, and writing the policies clients can show their auditors.

The work covers classic application security and the newer risks that come with AI: prompt injection, data leaking through tools, and agents holding more permission than they need.

What you'll do

  • Write and maintain security policies, records of processing and access rules, for MGLO and for clients.
  • Run GDPR work: data maps, retention, processing agreements, impact assessments and requests from data subjects.
  • Prepare and maintain the evidence for ISO/IEC 27001 controls, and support audits.
  • Test applications and AI agents against attack, including prompt injection and misuse of tools, and follow each fix through.
  • Design backup, disaster-recovery and incident-response plans, and rehearse them.
  • Set up the monitoring and security measures that show whether each control works.

What you bring

  • Experience securing production web or cloud systems, with cases you can discuss.
  • Working knowledge of GDPR, and of ISO/IEC 27001 or a similar framework.
  • Hands-on testing: the OWASP Top 10, and ideally OWASP's guidance for applications built on language models.
  • Cloud security on Google Cloud, AWS or Azure: identity, keys, network boundaries and logging.
  • The ability to explain a risk to a business owner in plain words.

What success looks like

  • Findings are fixed, not only reported.
  • An audit finds the evidence already in place.
  • The recovery plan works when tested, within the agreed recovery time.

Tools you'll use

  • ISO/IEC 27001
  • GDPR
  • OWASP ASVS
  • OWASP Top 10 for LLM applications
  • Burp Suite
  • Cloud IAM
  • Logging and SIEM
  • Backup and recovery tooling