Senior Security Engineer- UK

Remote from
UK flag
UK
Annual salary
Undisclosed
Salary information is not provided for this position. Check our Salary Directory to estimate the average compensation for similar roles.
Employment type
Full Time,
Job posted
Apply before
2 Jul 2026
Experience level
Senior
Views / Applies
9 / 1

About Hopper

Spend less. Travel better.

Verified job posting
This job post has been manually reviewed for authenticity and compliance.

AI Summary

Hopper is seeking a Senior Security Engineer to own and evolve their application security program, focusing on tooling, automation, and CI/CD integration. The role involves building security tools, using AI as a force multiplier, and working closely with engineering teams to make security seamless. The ideal candidate has at least 5 years of software/platform engineering experience, deep application security knowledge, and a bias toward automation. This is a high-impact role in a small, agile team at a well-funded startup.

Role DNA

Job Complexity
Easy Hard
Pace & Pressure
Relaxed Fast-paced
Autonomy Level
Guided Full Ownership
Communication Load
Independent Highly Collaborative
AI Insight The role requires deep technical expertise in application security, cloud infrastructure, and AI tooling, along with the ability to influence engineering culture and work autonomously. The combination of building systems and responding to security findings makes it challenging.

Salary Analysis

Median Market Rate
$175,000
US Market
$140k – $220k
0 $242k
AI Insight The job listing does not specify salary, but for a Senior Security Engineer role in the UK market, the median salary is estimated at $175,000 USD. This is competitive for a senior-level position at a well-funded startup.

Key Skills

Application Security Vulnerability Management CI/CD Security Cloud Security (GCP/GKE) Automation AI/ML Tools Container Security Secure Development Lifecycle DevSecOps

I am writing to express my strong interest in the Senior Security Engineer position at Hopper. With over 5 years of experience in software and platform engineering, I have a proven track record of building production-quality security tools and integrating them into CI/CD pipelines. I am particularly drawn to Hopper's focus on using AI as a force multiplier and making security invisible to developers.

In my previous role, I owned the vulnerability management program and implemented automated scanning for container images and dependencies, reducing the mean time to remediation by 40%. I am experienced with GCP/GKE and have a bias toward building tools that prevent issues rather than manually chasing them.

I thrive in autonomous environments and am comfortable with ambiguity, often taking ownership of problems from start to finish. I am excited about the opportunity to influence engineering culture at Hopper and help scale security practices as the company grows.

Thank you for considering my application. I look forward to the possibility of contributing to Hopper's mission.

Can you describe a time you built a security tool that integrated into a CI/CD pipeline? What challenges did you face?
I built a tool that automatically scans container images for vulnerabilities and fails the build if critical issues are found. The main challenge was balancing security with developer velocity, so I implemented a mechanism to allow exemptions with approval.
How do you prioritize which vulnerabilities to fix when there are many?
I prioritize based on exploitability, asset value, and business context. I use a risk-based approach, focusing on critical vulnerabilities that are actively exploited or affect high-value systems.
How have you used AI tools to improve security processes?
I use AI coding assistants to write scripts for automated analysis, such as parsing logs to detect anomalies. I also use LLMs to generate summaries of security findings, saving time on manual review.
Describe a situation where you influenced engineering teams to adopt secure practices without slowing them down.
I introduced a set of secure defaults in our code templates and automated security checks in the CI pipeline. This made it easy for developers to follow best practices without extra effort.
How do you handle a security incident when you are the only person available?
I would first isolate the affected system to prevent further damage, then analyze the root cause. I document the steps taken and communicate status to stakeholders. After resolution, I implement preventive measures.

About the Role

Hopper’s Security team is small by design and consequential by impact- and this role sits at the centre of it. As a Senior Security Engineer, you’ll own the tooling, automation, and processes that keep our applications secure across their entire lifecycle, building the systems that make security invisible to developers and unavoidable by default. This is a builder’s role in every sense: you’ll write code, ship tools, and use AI as a core part of how you work — not as a novelty, but as a force multiplier.

What would your day-to-day look like

  • Own and evolve our vulnerability management program with a focus on application security — container images, dependencies, code scanning, and runtime detection

  • Build and maintain security tooling that integrates directly into CI/CD pipelines and developer workflows, so security happens automatically rather than as a gate

  • Use AI extensively to write code faster, automate analyses that would otherwise require manual review, and build intelligent tooling that scales beyond what a small team could achieve manually

  • Assess and improve how we leverage available telemetry across our systems

  • Work directly with engineering teams to influence secure development practices — not by writing standards and documents, but by shipping tools and defaults that make the secure path the easy path

  • Investigate and respond to security findings when needed, but spend more of your time building systems that prevent and detect issues than manually chasing them

  • Adapt quickly as priorities shift — our team is agile and tomorrow’s challenge may look different from todays

An ideal candidate has

  • At least 5 years experience software and/or platform engineering, with the ability to design, build, and maintain production-quality tools

  • Deep experience in application security and vulnerability management — you understand CVEs, dependency risks, container security, and SDLC integration, and you have opinions about what’s worth fixing and what’s noise

  • Hands-on experience with cloud infrastructure, ideally GCP/GKE or equivalent, with the ability to adapt to our stack

  • A demonstrated habit of using AI tools — coding assistants, LLMs — as a core part of how you build and analyse, not an occasional shortcut

  • A bias toward automation — when you see a repetitive manual task, your instinct is to write a tool, not a runbook

  • Comfort with ambiguity and ownership — you’ll often be the only person on a problem and will need to make judgment calls on priority, approach, and scope without waiting for direction

  • Experience influencing engineering culture around security, knowing how to make developers care without slowing them down

  • Strong written and verbal communication skills, including the ability to articulate our security posture clearly to customers when needed

Perks and benefits of working with us

  • Well-funded and proven startup with large ambitions, competitive salary, upsides of pre-IPO equity packages.

  • Hopper covers 100% of the premiums for the employee for a group insurance plan through Vitality Health.

  • Automatic contributions when you start with Hopper through Smart Pension.

  • Please ask us about our very generous parental leave, much above industry standards!.

  • Access to co-working space on demand through FlexDesk AND Work-from-home stipend.

  • Carrot Cash travel stipend.

  • Unlimited PTO.

  • Entrepreneurial culture where pushing limits and taking risks is everyday business.

  • Open communication with management and company leadership.

  • Small, dynamic teams = massive impact.

 

More about Hopper

At Hopper, we are on a mission to become the leading travel platform globally – powering Hopper’s mobile app, website and our B2B business, HTS (Hopper Technology Solutions). By leveraging massive amounts of data and advanced machine learning algorithms, Hopper combines its world-class travel agency offering with proprietary fintech products to bring transparency, flexibility and savings to travelers globally. We have developed several unique fintech solutions that address everything from pricing volatility to trip disruptions – helping people travel better and save more on their trips.

The Hopper platform serves hundreds of millions of travelers globally and continues to capture market share around the world. The Hopper app has been downloaded over 120 million times and has become largely popular among younger travelers – with 70% of its users being Gen Z and millennials.

While everyone knows us as the Gen Z and Millennial travel app, Hopper has evolved to become much more than that. In recent years, we’ve grown into a travel fintech provider, commerce platform, and global travel agency that powers some of the world’s largest brands.

Through HTS, our B2B division, the company supercharges its partners’ direct channels by integrating our fintech products on their sites or powering end-to-end travel portals. Today, our partners include leading travel brands like Capital One, Nubank, Air Canada, and many more.

Here are just a few stats that demonstrate the company’s recent growth:

  • Billions of dollars worth of travel and travel fintech are sold through Hopper and HTS’ channels every year.

  • Our fintech products – including Cancel for Any Reason and Flight Disruption Assistance – have exceptionally strong CSAT because the terms are always clear, and customers receive instant, no-questions-asked resolutions.

  • Almost 30% of our app customers purchase at least one fintech product when making a booking; and consumers are 1.6x more likely to repurchase if they add fintech to their booking vs if they booked just travel.

  • Given the success of its fintech products, Hopper launched a B2B initiative, HTS (Hopper Technology Solutions), which represents more than 75% of the business.

  • Through HTS, any travel provider (airlines, hotels, banks, travel agencies, etc.) can integrate and seamlessly distribute Hopper’s fintech or travel inventory on their direct channels. As its first HTS partnership, the company partnered with Capital One to co-develop Capital One Travel, a new travel portal designed specifically for cardholders. Other HTS partners include Air Canada, Uber, CommBank, Nubank, Flair Airlines and many more.

Come take off with us!
#LI-REMOTE

Apply now >

Annual salary information is not provided for this position. Explore salary ranges for similar roles in our Salary Directory ›

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

How to apply

Did you apply? Let us know, and we’ll help you track your application.

See a few more

Similar Technical Support remote jobs

Job Search Safety Tips

Here are some tips to help you search and apply for jobs safely:
Watch out for suspicious jobs Don't apply for jobs that offer high pay for little work or offer to hire you without an interview. Read more ›
Check the employer's profile Make sure you're applying for a trustworthy job by visiting the employer's profile and learning more about them. Read more ›
Protect your information Don't share personal details like your bank account or government-issued ID on suspicious websites or messengers. Read more ›
Report jobs that feel unsafe If you see a job that seems misleading, inappropriate or discriminatory, report it for going against our policies and we'll review it.

Share this job

Jobicy+ Subscription

Jobicy

614 professionals pay to access exclusive and experimental features on Jobicy

Free

USD $0/month

For people just getting started

  • • Unlimited applies and searches
  • • Access on web and mobile apps
  • • Weekly job alerts
  • • Access to additional tools like Bookmarks, Applications, and more

Plus

USD $8/month

Everything in Free, and:

  • • Ad-free experience
  • • Daily job alerts
  • • Personal career consultant
  • • AI-powered job advice
Go to account ›