Tech Stack
Job Description, Responsibilities & Requirements
About the Position
Principal, Quality Engineering: IT Security
Posting Date: 13 Jul 2026
Location: London, GB
Company: EBRD
Requisition ID: 36870
Office Country: United Kingdom
Office City: London
Division: Information Technology
Contract Type: Fixed Term
Contract Length: 3 years
Posting End Date: 22/07/2026
Purpose of Job
The Principal, Quality Engineering leads the quality engineering strategy for a business-aligned capability or a technology-aligned practice, including tooling, resourcing, CoP engagement, operational resilience, automation, and ensuring security standards are maintained for the capability. This role helps ensure and maintain the quality of EBRD's platforms and technology solutions.
The Principal acts as the quality authority to multi-disciplinary platform or software engineering capabilities, with direct responsibility for setting the overall quality direction and design approaches for one or more squads, ensuring adherence to best practices, EBRD standards, and quality requirements.
Responsibilities
-
Requirements and Analysis:
- Collaborates with Cyber Security Architects, Product Owners, and Business Analysts to ensure security considerations are embedded in user stories and acceptance criteria.
- Conducts and oversees comprehensive risk assessments to identify potential security threats and prioritizes risk mitigation and remediation activities.
-
Test Planning and Strategy:
- Defines and owns the security testing strategy for products or domains under the cyber security capability.
- Oversees and coordinates integration of security testing into CI/CD pipelines.
-
Test Design and Execution:
- Participates in solution design discussions to ensure secure coding standards, encryption protocols, and identity management solutions are testable and robust.
- Drives adoption and standardization of security testing frameworks across squads.
-
Collaboration and Agile Ceremonies:
- Advocates for the inclusion of explicit security acceptance criteria in sprint planning and backlog refinement.
- Works with security governance, risk, and compliance teams to align on security standards and share best practices.
-
Defect Management:
- Implements structured processes for categorising and prioritising security vulnerabilities.
- Facilitates post-incident reviews for security breaches or near-miss events.
-
Continuous Improvement and Quality Advocacy:
- Serves as the primary advocate for secure engineering practices.
- Leads initiatives that incorporate frameworks such as ISO 27001, NIST, PCI-DSS, or OWASP into everyday engineering processes.
-
Data Analysis and Reporting:
- Develops and presents metrics on security-related coverage and application defects.
- Champions advanced tools for anomaly detection that anticipate security risks.
-
Technical and Domain Expertise:
- Maintains deep domain knowledge of cyber threats, secure coding patterns, and regulatory landscapes.
- Researches and recommends new technologies to enhance the organisation's security toolkit.
-
Mentorship and Knowledge Sharing:
- Mentors and coaches security-focused Quality Engineers.
- Establishes and leads security guilds or working groups.
-
ITSM and Service Continuity:
- Aligns security testing with service continuity strategies.
- Takes a lead role in responding to critical security incidents.
Requirements
- Knowledge, Skills, Experience and Qualifications:
- ISTQB Advanced Test Manager or equivalent recognised certification in test management.
- ISTQB Advanced Security Tester, CISM, CISSP, GIAC GSEC (optional).
- Qualification in IT Service Management, such as ITIL v3 or v4 Foundation or equivalent.
- Comprehensive QA leadership across advanced automation, performance, shift-left, or shift-right testing.
- Experience in Quality Engineering management and operations within an agile, product-focused IT department.
- Experience in code branching strategies (GitFlow, BitBucket, ADO, etc.) and integration of quality into CI/CD pipelines.
- Advanced AI/ML approaches for improving quality efficiency and effectiveness.
- Expert security testing via MITRE ATT&CK, advanced vulnerability management, DevSecOps.
- Familiar with PCI-DSS, ISO 27001, NIST frameworks, large-scale compliance audits.
- Applies chaos engineering (Gremlin, Chaos Mesh) for failover or resilience.
We Offer
- Varied, stimulating, and engaging work that gives you an opportunity to interact with a wide range of experts in the financial, political, public, and private sectors across the regions we invest in.
- A working culture that embraces inclusion and celebrates diversity.
- A hybrid workplace that offers flexibility to teams and individuals.
- An environment that places sustainability, equality, and digital transformation at the heart of what we do.
- A workplace that prioritises employee wellbeing and provides a comprehensive suite of competitive benefits.
About the Company
At EBRD, our Values – Inclusiveness, Innovation, Trust, and Responsibility – are at the heart of how we work. We bring these to life through our Workplace Behaviours: listening well and speaking up, collaborating smartly, acting decisively with full commitment, and simplifying to amplify our impact. These principles shape our culture and define our success. We seek individuals who not only share these values but are also committed to embedding them in their daily work, fostering a positive and high-performing environment.
Diversity is one of the Bank’s core values which are at the heart of everything it does. As such, the EBRD seeks to ensure that everyone is treated with respect and given equal opportunities and works in an inclusive environment. The EBRD encourages all qualified candidates who are nationals of the EBRD member countries to apply regardless of their racial, ethnic, religious and cultural background, gender, gender identity, sexual orientation, age, socio-economic background, or disability.
Job Segment: Testing, Test Engineer, Compliance, Military Intelligence, Quality Engineer, Technology, Engineering, Legal, Government