Principal, Quality Eng:, IT Security - European Bank for Reconstruction and Development (London)

About this position

The summary below is published by European Bank for Reconstruction and Development on the official vacancy notice. Our own analysis — salary realism, comparable openings, career trajectory, language profile — follows further down the page.

Requisition ID 36870 Office Country United Kingdom Office City London Division Information Technology Contract Type Fixed Term Contract Length 3 years Posting End Date 22/07/2026

**Purpose of Job**

The Principal, Quality Engineering leads the quality engineering strategy for a business-aligned capability or a technology-aligned practice, including tooling, resourcing, CoP engagement, operational resilience, automation and ensuring security standards are maintained for the capability which helps in ensuring and maintaining the quality of EBRD's platforms and technology solutions.

The Principal acts as the quality authority to multi-disciplinary platform or software engineering capabilities, with direct responsibility for setting the overall quality direction and design approaches for one or more squads, ensuring adherence to best practices, EBRD standards, and quality requirements.

This position provides leadership and direction for a team of internal and external Quality Engineering professionals, ensuring the effective governance, assurance, and delivery of quality outcomes across EBRD enterprise platform programmes. The role drives quality standards, test strategy,…

Excerpt shown; read the full notice on the official page. The structured breakdown below covers the key facts.

Key responsibilities

According to the vacancy notice, the role centres on the following duties:

  • Lead quality engineering strategy for business-aligned capability or technology-aligned practice
  • Set overall quality direction and design approaches for squads
  • Provide leadership and direction for team of internal and external Quality Engineering professionals
  • Manage quality activities for multiple assigned projects or programs
  • Collaborate with Cyber Security Architects, Product Owners, and Business Analysts to embed security in user stories
  • Conduct and oversee comprehensive risk assessments to identify potential security threats
  • Define and own security testing strategy for products or domains
  • Oversee and coordinate integration of security testing into CI/CD pipelines

Are you eligible?

Check these requirements from the notice before investing time in an application:

  • Education: ISTQB Advanced Test Manager or equivalent recognised certification in test management; Qualification in IT Service Management, such as ITIL v3 or v4 Foundation or equivalent
  • Experience: Demonstrable experience in Quality Engineering management and operations within an agile, product focused IT department, ideally within a financial institution
  • Key skills: QA leadership across advanced automation, performance, shift-left, or shift-right testing, Agile or DevOps at scale, Code branching strategies (GitFlow, BitBucket, ADO, etc.), Integration of quality into CI/CD pipelines, Advanced AI/ML approaches for improving quality efficiency and effectiveness, Security testing via MITRE ATT&CK, Advanced vulnerability management, DevSecOps, PCI-DSS, ISO 27001, NIST frameworks knowledge, Large-scale compliance audits

Contract and working arrangements

Contract duration: 3 years.

Working arrangements: Hybrid workplace that offers flexibility to teams and individuals.

Hiring unit: Information Technology.

Position overview

This is the official EU Careers listing for Principal, Quality Eng:, IT Security at EBRD based in London.

Requisition ID 36870 Office Country United Kingdom Office City London Division Information Technology Contract Type Fixed Term Contract Length 3 years Posting End Date 22/07/2026

Purpose of Job

The Principal, Quality Engineering leads the quality engineering strategy for a business-aligned capability or a technology-aligned practice, including tooling, resourcing, CoP engagement, operational resilience, automation and ensuring security standards are maintained for the capability which helps in ensuring and maintaining the quality of EBRD's platforms and technology solutions.

The Principal acts as the quality authority to multi-disciplinary platform or software engineering capabilities, with direct responsibility for setting the overall quality direction and design approaches for one or more squads, ensuring adherence to best practices, EBRD standards, and quality requirements.

This position provides leadership and direction for a team of internal and external Quality Engineering professionals, ensuring the effective governance, assurance, and delivery of quality outcomes across EBRD enterprise platform programmes. The role drives quality standards, test strategy, automation, assurance, and continuous improvement to support the secure, resilient, and successful delivery of business-critical technology solutions.

They will manage the quality activities for multiple assigned projects or programs, responsible for the strategic guidance of quality and the associated quality planning activities and ensuring that key stakeholders are engaged and informed with accurate, targeted, and timely information.

They will work closely with the project resourcing managers in order to effectively manage project resourcing plans in an efficient and lean group.

Accountabilities and Responsibilities

1. Requirements and Analysis

* Collaborates with Cyber Security Architects, Product Owners, and Business Analysts to ensure security considerations are embedded in user stories and acceptance criteria. This includes authentication flows, data encryption requirements, and regulatory compliance. * Conducts and oversees comprehensive risk assessments to identify potential security threats – both functional (e.g. role-based access issues) and non-functional (e.g. performance under attack simulations). Prioritises risk mitigation and remediation activities accordingly.

1. Test Planning and Strategy

* Defines and owns the security testing strategy for products or domains under the cyber security capability, ensuring alignment with organisational risk appetite. Incorporates both functional security tests (e.g. role-based access checks) and non-functional security tests (e.g. penetration testing, threat modelling). * Oversees and coordinates integration of security testing into CI/CD pipelines. This includes static and dynamic code analysis, dependency checks, and container scanning, ensuring teams catch vulnerabilities early.

1. Test Design and Execution

* Participates in solution design discussions with cyber architects and senior engineers to ensure secure coding standards, encryption protocols, and identity management solutions are testable and robust. * Drives adoption and standardisation of security testing frameworks – covering areas like penetration testing, vulnerability scanning, and threat simulation – across squads within the cyber security remit. * Identifies and champions automation projects that detect vulnerabilities in near real-time (e.g. automated vulnerability scanning, container integrity checks), reducing attack surfaces and accelerating feedback loops.

1. Collaboration and Agile Ceremonies

* Advocates for the inclusion of explicit security acceptance criteria in sprint planning and backlog refinement. Ensures squads incorporate security-related user stories, threat models, and test cases. * Works with security governance, risk and compliance teams, as well as broader IT stakeholders, to align on security standards, share best practices, and coordinates enterprise-wide security initiatives.

1. Defect Management

* Implements structured processes for categorising and prioritising security vulnerabilities (e.g. CVSS scoring, regulatory compliance impact). Ensures timely fixes for high-severity issues, balancing business priorities with risk exposure. * Facilitates post-incident reviews for security breaches or near-miss events, driving remediation and systemic improvements (e.g. adopting stricter encryption, improving logging or monitoring).

1. Continuous Improvement and Quality Advocacy

* Serves as the primary advocate for secure engineering practices across the cyber security domain. Promote “shift-left” security testing, encouraging developers to adopt secure coding and testing practices from inception. * Leads initiatives that incorporate frameworks such as ISO 27001, NIST, PCI-DSS, or OWASP into everyday engineering processes. Ensures compliance while driving continuous improvements to security posture.

1. Data Analysis and Reporting

* Develops and presents metrics on security-related coverage (e.g. vulnerability detection rates, patch compliance), application defects, and real-time threat intelligence to senior leadership. * Champions advanced tools for anomaly detection (e.g. SIEM solutions, machine learning-driven threat hunting) that anticipate security risks before they escalate.

1. Technical and Domain Expertise

* Maintains deep domain knowledge of cyber threats, secure coding patterns, and regulatory landscapes. Guides teams in designing secure solutions that meet both functional user needs and non-functional resilience standards. * Researches and recommends new technologies – such as next-generation firewalls, zero-trust frameworks, or AI-driven threat detection – to enhance the organisation's security toolkit.

1. Mentorship and Knowledge Sharing

* Mentors and coaches security-focused Quality Engineers, sharing expertise on vulnerability analysis, secure code reviews, and automated security testing. Provides structured learning paths for emerging threats and tools. * Establishes and leads security guilds or working groups, ensuring consistent security testing approaches and effective communication of threats, remediations, and lessons learnt across squads.

1. ITSM and Service Continuity

* Aligns security testing with service continuity strategies, ensuring plans include resilience against cyber-attacks (e.g. DDoS defense) and compliance with ITSCM (IT Service Continuity Management) requirements. * Takes a lead role in responding to critical security incidents (e.g. data breaches, ransomware attacks). Coordinates cross-functional efforts, communicates status to senior management, and validates that recovery efforts meet compliance and business continuity standards.

Knowledge, Skills, Experience and Qualifications

* Holds ISTQB Advanced Test Manager or an equivalent recognised certification in test management, or demonstrable experience. * May hold ISTQB Advanced Security Tester, CISM, CISSP, GIAC GSEC. * Qualification in IT Service Management, such as ITIL v3 or v4 Foundation or equivalent. * Demonstrates comprehensive QA leadership across advanced automation, performance, shift-left, or shift-right testing. * Integrates Agile or DevOps at scale, possibly merges with ITIL v4 for QA–Ops synergy.

* Demonstrable experience in Quality Engineering management and operations within an agile, product focused IT department, ideally within a financial institution

* Experience in code branching strategies (GitFlow, BitBucket, ADO, etc.) and integration of quality into CI/CD pipelines. * Experienced in advanced AI/ML approaches for improving quality efficiency and effectiveness, analytics, defect identification, understanding how AI can enhance quality processes. * Provides expert security testing via MITRE ATT&CK, advanced vulnerability management, DevSecOps. * Familiar with PCI-DSS, ISO 27001, NIST frameworks, large-scale compliance audits. * Applies chaos engineering (Gremlin, Chaos Mesh) for failover or resilience.

What is it like to work at the EBRD? / About EBRD

Our agile and innovative approach is what makes life at the EBRD a unique experience! You will be part of a pioneering and diverse international organisation, and use your talents to make a real difference to people's lives and help shape the future of the regions we invest in.

At EBRD, our Values – Inclusiveness, Innovation, Trust, and Responsibility – are at the heart of how we work. We bring these to life through our Workplace Behaviours: listening well and speaking up, collaborating smartly, acting decisively with full commitment, and simplifying to amplify our impact. These principles shape our culture and define our success. We seek individuals who not only share these values but are also committed to embedding them in their daily work, fostering a positive and high-performing environment.

The EBRD environment provides you with:

* Varied, stimulating and engaging work that gives you an opportunity to interact with a wide range of experts in the financial, political, public and private sectors across the regions we invest in. * A working culture that embraces inclusion and celebrates diversity. Our workforce reflects a broad range of backgrounds, perspectives, and experiences, bringing fresh ideas, energy, and innovation and enhancing our ability to serve our clients, shareholders, and counterparties effectively. * A hybrid workplace that offers flexibility to teams and individuals; that is based on trust, flexibility and connectedness. * An environment that places sustainability, equality and digital transformation at the heart of what we do. * A workplace that prioritises employee wellbeing and provides a comprehensive suite of competitive benefits.

Diversity is

Application timeline

This vacancy was first listed on 13 July 2026, 9 days ago.

No closing date is published in the source feed for this position. EU vacancies typically remain open for four to eight weeks; check the official vacancy notice for the cut-off date and time.

Last verified against the EU Careers feed on 22 July 2026.

Where to learn more

For headcount, mission, and other open vacancies at EBRD see the EBRD institution page; for the cost of living, correction coefficient, and other postings in London see our London location page.

New to EU careers? Our beginner's guide walks through entry routes, EPSO competitions, and what to prepare. For application logistics see application tips and EPSO competitions.

Career trajectory

Career progression for this grade staff is governed by Articles 44 to 46 of the Staff Regulations (consolidated text on EUR-Lex) and Annex IB on the promotion procedure. Step increases are automatic every two years (Art. 44); grade promotion is competitive, based on the appraisal exercise (Art. 45) and the Career Development Review. For roles at EBRD, progression to the next grade typically takes three to five years on merit, with two-yearly step increases in between. Article 46 governs the classification at recruitment, which sets the starting step within the grade (usually step 1 for external recruits without prior EU service, step 2 or 3 where relevant professional experience is recognised).
Mobility within the institutions is encouraged via the inter-institutional and intra-institutional vacancy publication system: temporary agents who pass the probation period and reservists from EPSO laureate lists can typically apply to internal vacancies after one year of service. Lateral moves between Directorates-General reset the seniority clock for promotion only if the new post carries a different grade.

Language profile

Beyond the formal language requirements stated in the vacancy notice, the day-to-day working languages at this employer are English and French in roughly equal measure, with German appearing in some technical files. Internal meetings and most policy drafting in Brussels run in English; French remains the preferred internal language in Luxembourg-based services and parts of DG TRADE.

Application cadence

EBRD has not advertised another comparable role with the same grade and subject signature in the past twenty-four months. This opening has rarely been seen on the EU Careers feed and may be the first such posting in our two-year window. Applicants who pass the eligibility checks should not assume the same profile will reopen on a predictable cadence.

Source: This job listing was sourced from the official EU Careers portal (EPSO). First published: .

Remove ads and unlock all features Go Premium