Security Engineer

Outerlimit
Outerlimit

Software Engineering

London, UK

Posted on Sep 25, 2026

We are looking for a Security Engineer to design and build the platform that feeds Outerlimit security telemetry from the Global portal into the tools our customers run their security operations in (SIEM, SOAR, XDR etc).

Today we discover shadow AI, enforce policy at the appliance and MCP gateway, and record every tool call an agent attempts. That signal needs to land natively in Splunk, Microsoft Sentinel, CrowdStrike, XSIAM, Chronicle and Elastic, and drive response through Torq, Tines, ServiceNow SecOps and Logic Apps.

This is greenfield, and it is not an architecture-only role. You will write most of v1 yourself.

This is for someone who can:

  • Design and build a versioned, documented public API over our existing Data Platform
  • Build signed, idempotent event delivery with bounded retry, dead-lettering and replay
  • Build a cursor-paginated pull and export API to carry bulk SIEM and XDR telemetry
  • Build native connectors for destinations such as Microsoft Sentinel, Splunk and XSIAM
  • Build self-service API key and webhook management in the portal, including scoping, rotation, revocation and audit
  • Extend our tenant-scoped authorisation model to machine credentials, so an API key never sees more than its creator can
  • Make the decisions that set our external API standards, including versioning, deprecation and delivery guarantees

The decisions made in the first six months become compatibility obligations we live with for years, and the standards you set become the ones other Outerlimit teams follow.

What you'll bring

Experience

  • Proven experience designing, building and operating externally consumed APIs in production
  • Able to talk specifically about versioning and deprecation, not only endpoints
  • Genuinely senior without being a manager, able to scope your own work and carry a project this size

Event Delivery & Distributed Systems

  • Deep experience with asynchronous, event-driven delivery using queues or streams
  • Strong understanding of at-least-once semantics, idempotency, retry and dead-letter design
  • Able to debug delivery under load, and treats delivery guarantees as a product feature

Security Domain

  • Direct experience with SIEM, SOAR or XDR, either building integrations for them or working inside one
  • Understanding of how a SOC consumes data, and what separates a useful integration from a noisy one
  • Sound judgment on multi-tenant isolation, data residency and least privilege
  • Awareness of egress as an attack surface, including SSRF, credential handling and rate-limiting

Programming & Cloud

  • Strong ability in C# .NET with modern engineering practices
  • Strong cloud platform depth, ideally Azure with Terraform, and willing to be hands-on with infrastructure
  • Docker, and experience writing production-quality code that others can pick up

Nice to have

  • Experience shipping a certified marketplace integration end to end, such as Splunkbase, a Sentinel solution or ServiceNow Store
  • Familiarity with security data standards such as OCSF or ECS, and the practical limits of schema normalisation
  • Python
  • Working knowledge of the AI agent ecosystem, including MCP, agent frameworks and LLM tool use

How we work

  • Small teams with real ownership
  • Infrastructure as code and per-region deployments
  • Zero-build-warning discipline, and tests that exist to catch regressions rather than to raise a coverage number
  • Engineers own what they ship in production
  • Technical decisions are argued on merit and written down

This is a role for someone who wants to own a hard, externally visible system end to end and still be in the code.