Founding Security Engineer (Application & Infrastructure) - Careers - Pavo

Pavoai · London · Remote · First seen 1 week ago
Remote Mid level Cybersecurity
Apply on the employer's site

About this role

Apply via email → 01 About Pavo Pavo is building Enterprise Superintelligence: compounding systems that take ownership of business outcomes and work with humans to deliver them. We believe that while foundation models are necessary, they are not sufficient. The hard problem is systems intelligence: end-to-end architectures that understand a company’s code, data, and decisions, and improve themselves through experience. We are assembling a small, senior team of researchers and engineers obsessed with systems-first intelligence. Our current team consists of PhDs and ML engineers from top applied ML and coding agent companies, with a heritage of shipping systems at Spotify, ShareChat, and Sourcegraph scale. Our team has built impressive momentum with a small group of highly capable engineers and researchers. 02 The role As a Founding Security Engineer, you will help establish the security foundations for Pavo’s agentic and knowledge systems. You help secure autonomous systems that write code, execute tools, and interact with sensitive enterprise data. This role sits at the bleeding edge of AI Security, wherein you harden the infrastructure that allows our knowledge and agentic systems to work safely inside Fortune 500 environments. You will build the shield that makes Enterprise Superintelligence trustworthy. We are looking for a security practitioner who is a builder at heart, someone who would rather ship a secure fix than write a policy document. 03 What you’ll build You will own the holistic security posture of the Pavo platform, spanning Application, AI, and Infrastructure security: AI & Application Security: Lead the defense against LLM-specific vulnerabilities (Prompt Injection, Insecure Output Handling) and standard web threats (OWASP Top 10). You will implement “Guardrails” that sanitize agent inputs/outputs and conduct continuous red-teaming of our agent behaviors. Secure SDLC & DevSecOps: Embed security into our CI/CD pipelines without slowing down our high-velocity engineering team. You will integrate automated SAST/DAST scanning, dependency management (SCA), and secret detection into our daily workflow. Cloud & Infrastructure Hardening: Work closely with Systems Engineers to secure our Kubernetes clusters and compute environments. You will design strict IAM policies (least privilege for agents) and ensure network isolation so that agent execution environments are impenetrable. Vulnerability Management: Own the lifecycle of vulnerability detection and remediation. You will manage bug bounty programs, coordinate third-party pentests, and ensure our open-source dependencies (and the code our agents generate) are secure. Enterprise Trust: Help design features that give our customers confidence, such as audit logging, data residency controls, and rigorous access governance. 04 What we look for Experience: 5+ years of experience in Security Engineering, with a strong focus on Application Security and Cloud Security. AppSec Proficiency: Deep understanding of modern web vulnerabilities (CSRF, SSRF, XSS) and experience utilizing tools like Burp Suite, Semgrep, or CodeQL. You can review code in Python or Go and spot logic flaws that scanners miss. AI Security Curiosity: You understand the unique risks of LLMs. You are familiar with the OWASP Top 10 for LLMs and have explored defenses against prompt injection and data exfiltration in agentic systems. Cloud Native Security: Hands-on experience securing AWS/GCP environments and Kubernetes clusters. You understand container security (capabilities, seccomp, namespaces) and how to secure microservices architectures. Offensive Mindset: You have experience with Red Teaming or CTFs. You know how to think like an attacker to uncover weaknesses in business logic and agent reasoning. 05 Nice to have Experience securing execution sandboxes (gVisor, Firecracker, or similar). Background in “Purple Teaming”, collaborating with developers to fix what you break. Contributions to the open-source security community or research on AI safety. Knowledge of compliance frameworks (SOC 2, ISO 27001) in an early-stage startup context. 06 What we offer Founding Equity: Significant ownership in a company tackling the next layer of the AI stack. Frontier Security: Define the security standards for a new category of software, autonomous enterprise agents. World-Class Team: Collaborate with a dense talent cluster of researchers and engineers who have shipped products serving hundreds of millions of users. Pavo is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. Apply Sound like you? Send us a note, we read every application. Email rishabh-ml@pavoai.com with the subject “ Application: Founding Security Engineer ” and a few lines on what you’ve shipped.

What this role is, and what else it is called

Employers in London advertise this kind of work as Security Engineer, Fire & Security Engineer, IT Security Analyst and Cyber Security Consultant too, so it is worth searching more than one wording. It is a mid-level Cybersecurity role in London, advertised as fully remote, so it is open to candidates working from home.

About hiring at Pavoai

Pavoai has 3 other live technology roles on its careers page, across Cloud & IT Infrastructure, Data, AI & Machine Learning and Cybersecurity. Of those, 50% are advertised as fully remote and 0% as hybrid. Elsewhere in its adverts Pavoai asks for Machine Learning, Azure, Terraform and Jenkins. We have been observing Pavoai hiring technology staff since July 2026. See all Pavoai roles, salaries and stack.

How this role compares to the market

1,970 live UK roles list Python right now, from 583 employers. The median advertised salary is £80,000; 30% are advertised as remote. Browse Python roles.

1,459 live UK roles list AWS right now, from 503 employers. The median advertised salary is £80,000; 28% are advertised as remote. Browse AWS roles.

London has 4,331 live IT vacancies across 1,366 employers, with a median advertised salary of £70,000. Browse London roles.

Market figures are today's snapshot of live UK roles on employer careers pages; see hiring trends.

Technologies mentioned

Detected on Pavoai's careers page. ProdReady Recruitment lists this vacancy as an aggregator and is not the employer; applications go to the employer's own site. More IT jobs in London.

Get these jobs by email

New matching UK IT roles, straight to your inbox. No spam -- unsubscribe any time.

We'll email you a confirmation link first -- nothing is sent until you click it.