About the job
Causaly develops an AI-powered platform designed to help researchers and decision-makers in biomedicine quickly find and interpret evidence from scientific publications, clinical trials, regulatory documents, and complex data sources. The company’s mission centers on building a high-precision Knowledge Graph and applying generative AI to advance biomedical knowledge. Leading biopharmaceutical organizations use Causaly’s technology to accelerate drug discovery, improve safety, and support informed decisions. With backing from investors such as ICONIQ, Index Ventures, Pentech, and Marathon, Causaly continues to expand its product offerings and market reach.
Role overview
The Senior Security Engineer position at Causaly is based in London and offers the chance to shape the company’s security strategy and processes. This role provides significant autonomy and involves working closely with the security team, as well as collaborating across engineering and product groups. The Security Engineer will take ownership of vulnerability management, advise teams on security matters, and support SecOps activities. Expect to define strategies, build and refine processes, and serve as a trusted advisor throughout the engineering organization.
Key responsibilities
- Lead the vulnerability management program: set strategy, select tools, prioritize work, and track remediation for dependencies, containers, and cloud infrastructure.
- Develop and maintain a dependency security strategy, including policies for third-party library use and update schedules.
- Integrate and manage security tools within CI/CD pipelines, such as SAST, SCA, secrets detection, and container scanning.
- Act as a security consultant for product and engineering teams, supporting design reviews, architecture decisions, and secure coding practices.
- Define and maintain security standards and guidelines that are practical for development teams.
- Oversee and improve the Security Champions program to build security awareness and skills across engineering teams.
- Support SecOps with incident triage and response, providing security engineering expertise when needed.

