LOCATION - ONSITE: CALMSDEN, CIRENCESTER, UK & IN THE FIELD WHEN NEEDED
THE LAST FRONTIER
The Arctic is a place of extremes: unforgiving, untamed, and undergoing rapid change. A literal defrosting reveals a multi-trillion-dollar opportunity spanning energy, defence, logistics, research, and infrastructure.
ARD was founded on a paradox. The Arctic is both the next great economic frontier and one of the most hostile environments on Earth. Rich in resources and strategically vital, yet bone-chillingly cold, dark for months, and fundamentally inhospitable to humans. This paradox—an explosion of activity in a place that resists human presence—is why we exist.
Our solution is autonomy.
We build systems that operate reliably and intelligently in the Arctic, so that humans don't always have to.
Founded by record-holding pioneers with decades of polar experience, we take calculated risks on hard problems that matter. If you want to build and deploy ground-up technology with real-world impact, at an inflection point in history that won’t reappear, we’d like to talk.
THE ROLE
We’re hiring our first Product Security Engineer. Security Engineering at ARD blends sharp technical skill, an attacker's mindset, and tangible real-world stakes. You'll operate across our entire hardware and software product suite — cloud infrastructure, applications, identity systems, and the autonomous products we field — spotting and cutting down the risks that actually matter. The systems we run and the data we hold call for a security approach that's thorough, flexible, and woven into everything we do. Your work will directly underpin the trust partners, customers, and the public place in us, while keeping our teams free to build and ship with confidence. Given how high the stakes are at ARD, this is core to delivering our mission the right way.
CORE RESPONSIBILITIES
Spot, evaluate, and rank security risks across our physical products, systems and infrastructure — separating hypothetical worries from genuine threats to the business
Build and roll out practical security controls across cloud platforms, applications, products, and data, and help engineering teams do likewise
Build and use threat models to catch architectural weak points, trust boundary gaps, and failure modes before they turn into incidents
Work alongside engineering, product, and operations teams as a trusted security partner — offering patterns, guidance, and guardrails rather than acting as a gatekeeper
Play a part in detecting, investigating, and containing security incidents, and push for lasting fixes based on what we learn
Cut down on manual, reactive security work through automation, better tooling, and secure-by-default habits built into how we develop and run systems
Apply technical rigour to assurance work like audits, certifications, and customer security reviews — making sure our controls hold up in practice, not just on paper
WHAT WE VALUE
Deep, hands-on skill in one or two security domains — application security, cloud security, identity and access management, cryptography, detection and response, or platform security — backed by real evidence of impact
An instinct for trust boundaries, failure modes, blast radius, and attacker behaviour, rather than viewing vulnerabilities in isolation
A knack for turning complex security risk into terms that land with engineers, product managers, and senior leadership alike, and for shaping outcomes through persuasion rather than title
A risk-based approach — weighing decisions proportionately under uncertainty, and always asking whether the work cuts real risk rather than just checking a compliance box
Comfort juggling multiple teams and technical domains at once without losing quality or judgement
A history of finding gaps and pushing security fixes through to completion, even in messy or loosely defined problem spaces
BONUS POINTS
Time spent in or around regulated, high-assurance, or defence-adjacent settings where security demands are intricate and failure carries real weight
Practical offensive security background — red teaming, penetration testing, or adversarial simulation — that shapes how you think about defensive design and threat modelling
Awareness of security issues unique to AI or machine learning systems, such as model integrity, data pipeline security, or adversarial ML
A hand in building security programmes at scale — security champions networks, secure development lifecycle tooling, or company-wide risk frameworks
A background in cloud-native security engineering, especially across AWS, GCP, or Azure, spanning infrastructure-as-code, container security, and cloud identity patterns
Some exposure to supply chain security issues, such as dependency management, build pipeline integrity, or third-party component assurance
Experience working with classified data, government security frameworks, or cross-domain security requirements
WHAT WE OFFER
Competitive compensation
Equity — meaningful options as an early employee at an early-stage company
Private healthcare, dental & optician
Real field exposure — travel to Arctic sites and Outposts when needed (genuinely, not as a gimmick)
Mission-driven culture — focus on impact, not hours logged
Small team, real ownership — what you build matters and ships