Logo for IRIS Software Group

IND - Senior Information Security Engineer

Role overview

Qualifications

  • Strong technical background in application security, vulnerability management or software engineering
  • Practical experience with security tooling such as SAST, DAST, SCA and secrets scanning
  • Solid grounding in public cloud security, particularly across AWS and/or Azure
  • Understanding of software supply chain security frameworks

Responsibilities

  • Own the end-to-end vulnerability management lifecycle across products and supporting technology
  • Triage and validate findings from multiple sources, including SAST, DAST, SCA, and penetration testing
  • Work closely with Engineering and Product teams to drive remediation of vulnerabilities
  • Continuously improve vulnerability management processes, dashboards and workflows

Key facts

Hard skills

About the company

IRIS Software Group logo

IRIS Software Group

Computer Software / SaaS

IRIS Software Group is a leading global provider of mission critical software & services & one of the UK’s largest privately held software companies. We help organisations to make better business decisions by developing integrated software solutions to minimise admin, make business processes more efficient & give more time to do what’s valued. We started 45 years ago with accountancy software & have evolved to be relied on by more than 100,000 customers across 135 countries in accountancy, education & business. We invest heavily in development using the latest processes & technologies, driven by our Indian & Romanian Centres of Excellence to build the next generation of cloud-based accountancy, HR & education solutions. Almost one million UK employees are managed by our HR solutions, & one in six UK employees are paid through IRIS payroll solutions. We are the largest third-party online tax filer with the UK Government, & we are used by 54 of the top 100 US & 93 of the top 100 UK accountancy firms. We also serve over 12,000 schools & academies, & almost four million UK families use our apps to connect to their child’s school. Since 2023, we have been awarded Tech CEO of the Year 2023 (Elona Mortimer-Zhika) in the UK Tech Awards; Cloud Innovation of the Year 2023 by UK IT Industry Awards; Tech Employer of the Year (2023 & 2024) in the Thames Valley Tech Awards; Technical Innovation – National Supplier 2024 Award at the Onrec Awards. IRIS Education has been named Company of the Year at the UK National MAT Awards 2023, crowned Company of the Year (more than 12m) in the Bett Awards 2023 & awarded Best EdTech Product – School Management Solutions in the Global EdTech Awards 2024. Troncmasters By IRIS also won the Payroll Innovation Award in the Global Payroll Association Awards 2024. We are proud of our Great Place to Work accolades, including Best Workplaces in Tech, Best Workplaces for Wellbeing and Best Workplaces for Women.

Company details

Company typeLarge
IndustryComputer Software / SaaS
Company size1001 - 5000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

About IRIS

IRIS Software Group is one of the UK's largest privately held software companies, trusted by 100,000+ businesses, schools and accountancy firms to keep their operations running. Our software pays 1 in 6 UK employees, supports over 12,000 schools, and is relied on by 91 of the top 100 UK accountancy firms.

We're a Great Place to Work® certified employer, recognised for our commitment to well-being, inclusion and development - and we're growing fast.

Hello Eveyone,

I am writing this Job Post to brief about the job opportunity with IRIS KPO Resourcing Pvt Ltd (IRIS Software Group) for Senior information security Engineer - Vulnerability Management

Please find the job description and specifications for your references,

Please share your interest for the job opportunity with your updated resume.

Shift timing : UK Business Hours (2:00 PM - 11:00 PM IST)

Web Link : https://www.iris.co.uk/

Location : Remote (Work From Home)

One way (Drop) Transport will be provided for the women colleagues.

Employment Type : Full-Time | Permanent

Desired Candidate

You bring a strong technical background in application security, vulnerability management or software engineering, with a clear understanding of how vulnerabilities arise and how they should be remediated. Practical experience with security tooling such as SAST, DAST, SCA and secrets scanning matters here, ideally integrated into modern CI/CD environments. Just as valuable is the judgement to assess vulnerabilities in context, weighing exploitability, internet exposure, asset criticality, available exploits and compensating controls rather than taking scanner output at face value. You are also comfortable with software supply chain security, including frameworks such as SLSA, dependency security and secure build pipelines.

Your background includes a solid grounding in public cloud security, particularly across AWS and/or Azure. You recognise the vulnerabilities that recur in cloud environments, from overly permissive identities and exposed services to insecure storage, vulnerable workloads and configuration drift.

What you will do

• Own the end-to-end vulnerability management lifecycle across our products and supporting technology, from identification and validation through prioritisation, remediation tracking, risk acceptance and reporting.

• Triage and validate findings from multiple sources, including SAST, DAST, SCA, secrets scanning, penetration testing and web application scanning.

• Work closely with Engineering and Product teams to drive remediation of vulnerabilities, helping teams understand technical risk, agree appropriate remediation actions and meet defined remediation timelines.

• Partner with teams responsible for integrating security tooling into our CI/CD pipelines, helping improve the quality, coverage and effectiveness of that tooling.

• Develop and continuously improve risk-based vulnerability prioritisation, considering exploitability, asset exposure, business criticality, threat intelligence and compensating controls rather than relying solely on scanner severity.

• Identify recurring vulnerability patterns and root causes, working with engineering teams to reduce systemic weaknesses rather than repeatedly fixing individual findings.

• Continuously improve vulnerability management processes, dashboards and workflows, bringing strong technical ownership and ideas for making the programme more scalable and effective.

• Support the security review of software supply chain risks, including dependency management, build pipeline security and relevant secure software development practices.

• Review and validate findings from cloud security and CSPM platforms, helping Infrastructure and Engineering teams prioritise and remediate cloud vulnerabilities and configuration weaknesses.

• Research emerging cloud threats, vulnerabilities and misconfiguration patterns and recommend appropriate mitigations.

• Support the implementation and improvement of cloud security controls and security baselines where required.

Why You’ll Love Working Here

  • Impact: Your work will influence millions globally.

  • Growth: Continuous learning and career development opportunities.

  • Belonging: A culture that celebrates diversity and empowers every individual.

Ready to Apply?

Click Apply - we’re excited to learn about your unique perspective and experience. If you need adjustments during the process, let us know. We’re committed to making this opportunity accessible to everyone.

What to expect from our hiring process

Our process is designed to be fair, transparent and straightforward. Stages vary depending on the role — more senior positions may involve additional steps, and some areas include role-specific assessments such as a technical test or case study — but typically you can expect:

  1. Application review — we assess your experience and potential

  2. Initial call — a short conversation to learn about you and share more about the role

  3. Skills assessment — tailored to the position, e.g. case study, coding challenge or portfolio review

  4. Final interview — meet the team and explore how you'll make an IMPACT at IRIS

We'll always walk you through the specific stages at the start of the process so you can prepare with confidence.

If you need any adjustments or accommodations during the process, let us know, we’re committed to making this experience accessible for everyone.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Security Engineer Related jobs

Other jobs at IRIS Software Group

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.