Senior Security Engineer

Propeller is on a mission to take the guesswork out of moving dirt - reducing wasted fuel, time, and money. We do this through the power of maps.
Our customers use Propeller’s integrated hardware and software products to capture accurate 3D versions of their worksites. With over 50,000 worksites worldwide using Propeller’s smart survey technology, we empower project teams to map, measure, and manage site activity.
Propeller empowers everyone to approach, own, and solve problems creatively. We’re data nerds who care about impact, honesty, and each other. We take pride in being a great place to work and are proud to be recognised as Fast Company a and BuiltIn Best Place to Work. You can learn more about us on Glassdoor
Your Mission
As our first security hire, we're looking for the kind of engineer others want to learn from, and the person who'll shape how the function grows from here. You'll be leading security across our infrastructure, application, and corporate environments.
You'll partner closely with our Infrastructure Manager and our Principal Architect, who’ve shaped our security program to date — your job is to take the security craft deeper. We want security to make engineering faster and safer, not slower, and we want you to be the person driving how we think about it across the company.
Leveraging our modern stack, you’ll secure complex geospatial data in the cloud and proprietary hardware in the field for customers in highly regulated industries. We are already GDPR compliant and hold our SOC 2 Type II; your role is to own and evolve this foundation. As we scale across the US, EU, and AU, you will lead the expansion of our certification landscape, ensuring our security posture remains a seamless enabler for our global growth.
Day to day responsibilities
- Setting and driving the security engineering roadmap across cloud infrastructure and IT, the application stack, and the SDLC.
- Building security into how engineering teams ship, through tooling, paved roads, training, and security reviews.
- Defining how we secure AI in the product and across the company, from the ML pipelines behind our imagery and processing, to how all teams at Propeller adopt AI coding assistants and third-party model APIs safely.
- Owning and addressing infrastructure security issues, implementing vulnerability management, secure architecture review, and threat modelling end-to-end.
- Owning security incident response end-to-end: playbooks, on-call posture, and post-incident learning.
- Running our annual third-party penetration test, translating findings into shipped fixes, and building out an internal penetration testing function.
- Defining the security metrics that matter and reporting on where we're improving and where we're not.
- Owning security compliance and reporting across our certifications, including SOC 2 Type II, and driving future certifications such as ISO 27001, UK Cyber Essentials+ and FedRAMP.
- Representing Propeller in customer security reviews and trust conversations.
We care more about depth and judgment than checklists, but to be effective here you'll need solid experience across most of the following:
- Cloud and infrastructure security at production scale: AWS, Crowdstrike, Terraform, Kubernetes, containers, Linux and networking fundamentals.
- Application security across the SDLC: Threat modeling, secure design review, and shift-left tooling (SAST/DAST/SCA) integrated into CI/CD.
- Detection and response: Defining what good looks like for logging, alerting, and security incident handling in a cloud-native environment.
- Compliance fluency: You've worked inside security compliance programs before and understand how to make controls real rather than performative. Familiarity with SOC 2, GDPR, ISO.
- Code and tooling: You can write Python, TypeScript or bash well enough to build the tooling you need rather than wait for it, and you've done so to automate security work in past roles.
- Identity and secrets: IAM design, secrets management.
- Communication and influence: This role thrives on your ability to work with engineering teams. You'll be the person setting the tone for how we talk about security across the company. You can disagree well, hold the line on what matters, write clearly, and bring people with you.
- Pragmatism: You've kept companies secure while keeping them moving fast. You make deliberate tradeoffs between risk and velocity, and design controls that engineering teams adopt rather than resist.
Bonus points for
- Extensive experience with SOC 2 Type II, ISO, UK Cyber Essentials+ or FedRAMP.
- Extensive experience in Linux and network security.
- Proficiency with web application development and continuous monitoring tools such as Datadog or Prometheus.
- Familiarity with OWASP Top 10, CWE or NIST frameworks.
- Certifications such as CISSP, CCNA, CCNP, AWS Cloud Security, Redhat certifications or similar.
- Employee share options
- Professional development budget and leave
- The opportunity to take part in our mentorship program
- Mental health resources
- Monthly telephone and/or internet allowance
- Paid primary & secondary parental leave policies
- Hybrid work arrangements and WFH equipment provided
About Propeller
Propeller is for everyone, so come as you are. We value all types of experience, skill, and ability. If you don’t think you meet all the requirements, but still think this role would be a good fit, we’d love to hear from you.
Diversity makes our team more creative, fun, and effective, so bring your whole self to the application process, and we will too!
If you’re interested in what life at Propeller is like, check out our employee-owned Medium blog page!
You'll be redirected to
the company's application page