4 months ago
London, United KingdomSenior
Responsibilities
- Design and implement next-generation cloud security architecture across AWS and GCP.
- Contribute security-focused infrastructure as code using AWS CDK and Terraform.
- Implement network security, IAM, VPCs, encryption, logging, and monitoring across cloud environments.
- Own and enhance Microsoft Sentinel SIEM/SOAR capabilities and help mature SOC detection and response.
- Automate role-based access control across AWS, Microsoft Entra, and internal systems.
- Embed zero-trust policies and security controls into GitLab CI/CD pipelines.
- Implement SAST, dependency scanning, container security, infrastructure-as-code reviews, and automated policy enforcement.
- Partner with engineering teams on secure architecture, deployment patterns, secure SDLC practices, and pre-deployment security reviews.
- Challenge the security standards of production applications and infrastructure and support incident response.
Requirements
- Strong track record in DevSecOps and cloud security engineering with hands-on experience improving organisational security posture.
- Strong Python development skills, including scripting automation, interacting with APIs, and building security tooling.
- Strong understanding of network security fundamentals in modern distributed cloud architectures.
- Experience owning both the build and run aspects of security, including system design and incident response.
- Ability to balance rigorous security practices with engineering velocity in a dynamic, ambiguous, fast-paced startup environment.
Benefits
- Equity ownership in the company.
- Hybrid work with 3 days per week in the office.
- 25 days of annual holiday plus 8 bank holidays.
- 2 paid volunteering days per year.
- One month of paid sabbatical after 4 years.
- Employee loan.
- Free gym membership.
- Team wellness budget for activities such as yoga, tennis, or bouldering.
