1. Role overview
You own the part of the work that decides whether anything ships at all: access, controls, data residency, and the review a client's security team runs before a system touches real records.
Every system we build acts inside somebody else's business, so the audit trail, the approvals and the boundaries are part of the system, not paperwork added afterwards.
You work on live engagements alongside the engineers who are building, not from a policy document.
2. Key Responsibilities
Design the access and approval boundaries for systems acting on real records
Take our designs through client security reviews, and answer what is asked
Set residency and retention so a system can run where it has to run
Make the audit trail clear enough for someone reviewing the work later
Review integrations before the client's own engineers do
Keep credentials, secrets and scopes out of the places they end up by default
Write the security section of the blueprint, in language a client can approve
3. Qualifications
You have taken a system through an enterprise security review and out the other side.
Practical knowledge of identity, access control, encryption and key management.
Experience of residency and retention requirements in more than one jurisdiction.
You read the code, not only the diagram.
Comfortable saying no to an engineer, including one of ours.
Experience in finance, insurance, healthcare or another audited industry.
You write clearly for people who are not security engineers.
Willing to travel to a client when the work needs it.
4. The work
Understand the client's process before choosing the technology.
Build systems for real operational work.
Work with the people who know the process.
Learn from the behaviour of systems in production.
Choose tools to fit the client's platforms and controls.
Document decisions so other engineers can follow the work.
Connect engineering decisions to the work the system must carry.
Keep the client's people involved as the system evolves.



