Senior II Security Engineer

<b>What you’ll be doing:</b> <ul> <li>Own application and product security, partnering closely with engineering teams to improve security outcomes across the full SDLC</li> <li>Act as a strong technical voice in how we design, build, ship, and operate secure systems, driving initiatives end-to-end through influence, collaboration, and hands‑on execution</li> <li>Work hands‑on with our core backend stack (Python, Django), reading and writing code, contributing improvements, and building automation to scale security with product engineering teams to embed security into planning, design, and delivery, without slowing teams down</li> <li>Participate in architecture discussions and design reviews to identify risk early and propose pragmatic mitigations</li> <li>Lead and facilitate threat modeling for new features and significant changes, and translate results into prioritized engineering work</li> <li>Improve the secure SDLC end‑to‑end: requirements, secure design, implementation guidance, testing, release, and operational readiness</li> <li>Build “paved paths” and guardrails that make secure choices the default (libraries, patterns, templates, CI checks)</li> <li>Mature code and application security tooling, including selection, rollout, and adoption: <ul> <li>SAST, SCA (We now use Snyk), secret scanning, and relevant DAST/API testing where it adds signal</li> <li>Integrate findings into developer workflows with clear ownership, SLAs, and low‑friction remediation</li> </ul> </li> <li>Proactively discover security issues through code review support, automation, security testing, and targeted assessments Improve vulnerability management for application and product security findings: triage, prioritization, remediation, verification, and trend reporting</li> <li>Create and deliver training and enablement for engineers (secure coding, common pitfalls, new patterns), and help grow security champions across teams</li> <li>Partner with GRC to ensure security requirements and controls are feasible, well understood, and evidenced through real engineering practice</li> <li>Lead engineering wide initiatives, managing stakeholders and aligning with business to deliver high impact results</li> </ul> <b>What you need to succeed:</b> <ul> <li>Strong experience in application and product security in modern web environments, with a track record of improving security outcomes across the SDLC</li> <li>Strong coding ability and comfort working in a Python/Django codebase (reading, writing, reviewing, and proposing improvements)</li> <li>Demonstrated experience influencing engineering teams through design reviews, threat modeling, and practical guidance</li> <li>Strong understanding of common web and API security risks (OWASP Top 10, auth and session risks, SSRF, injection, access control issues, secrets exposure, unsafe deserialization, etc.) and how they show up in real systems</li> <li>Experience selecting, introducing, and scaling security tooling in CI/CD (SAST, SCA, secret scanning, and related controls), including tuning to reduce noise and improve developer adoption</li> <li>Ability to turn findings into action: clear severity, ownership, prioritization, and verification, with an emphasis on automation and repeatability</li> <li>Strong communication skills and the ability to collaborate across Product Engineering, Platform Engineering, SRE, Data teams, and GRC</li> <li>Business‑oriented mindset and comfort making cost‑benefit tradeoffs</li> <li>Willingness to participate in on‑call rotations and partner effectively with SRE during incidents</li> </ul> <b>Nice to have:</b> <ul> <li>Security experience with identity and authorization patterns (OAuth/OIDC, SSO, RBAC/ABAC), especially in SaaS products</li> <li>Experience with cloud‑native environments and security controls that impact applications (AWS, Kubernetes, infrastructure boundaries)</li> <li>Experience building internal security libraries, developer platforms, or guardrails that scale across teams</li> <li>Experience with bug bounty programs, pentesting workflows, or coordinated disclosure processes</li> <li>Mobile security experience</li> </ul> <b>Why you’ll love it at Preply:</b> <ul> <li>An open, collaborative, dynamic and diverse culture;</li> <li>A generous monthly allowance for lessons on Preply.com, Learning & Development budget and time off for your self‑development;</li> <li>A competitive financial package with equity and leave allowance;</li> <li>The opportunity to unlock the potential of learners and tutors through language learning and teaching in 175 countries (and counting!).</li> </ul> <b>Diversity, Equity, and Inclusion</b> <p>Preply.com is committed to creating an inclusive environment where people of diverse backgrounds can thrive. We believe that the presence of different opinions and viewpoints is a key ingredient for our success as a multicultural Ed‑Tech company. That means that Preply will consider all applications for employment without regard to race, color, religion, gender identity or expression, sexual orientation, national origin, disability, age or veteran status.</p> #J-18808-Ljbffr Salary: GBP 60000 - 80000 per year Experience: 5 years required

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...