Product Security Engineer

Full-time — Cotswolds, UKUK & Arctic

The last frontier

The Arctic is a place of extremes: unforgiving, untamed, and undergoing rapid change. A literal defrosting reveals a multi-trillion-dollar opportunity spanning energy, defence, logistics, research, and infrastructure.

ARD was founded on a paradox. The Arctic is both the next great economic frontier and one of the most hostile environments on Earth. Rich in resources and strategically vital, yet bone-chillingly cold, dark for months, and fundamentally inhospitable to humans. This paradox—an explosion of activity in a place that resists human presence—is why we exist.

Our solution is autonomy.

We build systems that operate reliably and intelligently in the Arctic, so that humans don't always have to.

Founded by record-holding pioneers with decades of polar experience, we take calculated risks on hard problems that matter. If you want to build and deploy ground-up technology with real-world impact, at an inflection point in history that won’t reappear, we’d like to talk.

The role

We’re hiring our first Product Security Engineer. Security Engineering at ARD blends sharp technical skill, an attacker's mindset, and tangible real-world stakes. You'll operate across our entire hardware and software product suite — cloud infrastructure, applications, identity systems, and the autonomous products we field — spotting and cutting down the risks that actually matter. The systems we run and the data we hold call for a security approach that's thorough, flexible, and woven into everything we do. Your work will directly underpin the trust partners, customers, and the public place in us, while keeping our teams free to build and ship with confidence. Given how high the stakes are at ARD, this is core to delivering our mission the right way.

CORE RESPONSIBILITIES

  • Spot, evaluate, and rank security risks across our systems, products, and infrastructure — separating hypothetical worries from genuine threats to the business
  • Build and roll out practical security controls across cloud platforms, applications, products, and data, and help engineering teams do likewise
  • Build and use threat models to catch architectural weak points, trust boundary gaps, and failure modes before they turn into incidents
  • Work alongside engineering, product, and operations teams as a trusted security partner — offering patterns, guidance, and guardrails rather than acting as a gatekeeper
  • Play a part in detecting, investigating, and containing security incidents, and push for lasting fixes based on what we learn
  • Cut down on manual, reactive security work through automation, better tooling, and secure-by-default habits built into how we develop and run systems
  • Apply technical rigour to assurance work like audits, certifications, and customer security reviews — making sure our controls hold up in practice, not just on paper

WHAT WE VALUE

  • Deep, hands-on skill in one or two security domains — application security, cloud security, identity and access management, cryptography, detection and response, or platform security — backed by real evidence of impact
  • An instinct for trust boundaries, failure modes, blast radius, and attacker behaviour, rather than viewing vulnerabilities in isolation
  • A knack for turning complex security risk into terms that land with engineers, product managers, and senior leadership alike, and for shaping outcomes through persuasion rather than title
  • A risk-based approach — weighing decisions proportionately under uncertainty, and always asking whether the work cuts real risk rather than just checking a compliance box
  • Comfort juggling multiple teams and technical domains at once without losing quality or judgement
  • A history of finding gaps and pushing security fixes through to completion, even in messy or loosely defined problem spaces

BONUS POINTS

  • Time spent in or around regulated, high-assurance, or defence-adjacent settings where security demands are intricate and failure carries real weight
  • Practical offensive security background — red teaming, penetration testing, or adversarial simulation — that shapes how you think about defensive design and threat modelling
  • Awareness of security issues unique to AI or machine learning systems, such as model integrity, data pipeline security, or adversarial ML
  • A hand in building security programmes at scale — security champions networks, secure development lifecycle tooling, or company-wide risk frameworks
  • A background in cloud-native security engineering, especially across AWS, GCP, or Azure, spanning infrastructure-as-code, container security, and cloud identity patterns
  • Some exposure to supply chain security issues, such as dependency management, build pipeline integrity, or third-party component assurance
  • Experience working with classified data, government security frameworks, or cross-domain security requirements


WHAT WE OFFER

  • Competitive compensation
  • Equity — meaningful options as an early employee at an early-stage company
  • Private healthcare, dental & optician
  • Real field exposure — travel to Arctic sites and Outposts when needed (genuinely, not as a gimmick)
  • Mission-driven culture — focus on impact, not hours logged
  • Small team, real ownership — what you build matters and ships

A note on who we want to hear from
We're building for one of the most demanding environments on Earth and we believe diverse teams build more resilient systems. We actively welcome applications from people who are underrepresented - whether that's by gender, ethnicity, disability, or background. If you're not sure you meet every requirement, apply anyway and tell us what excites you about the problem.

Apply for this job

Do you hold the applicable right to work in the United Kingdom? *
Are you open to relocation? *

Loading next job…