2 months ago
Remote, United Kingdom or Birmingham, United KingdomMid Level
Responsibilities
- Define and implement the cloud security framework with IT Systems, SOC leadership, and GRC.
- Recommend and implement cloud security and governance controls across Azure, AWS, and SaaS environments.
- Automate security tooling to validate requirements and identify potential security issues.
- Define cloud threat detection and incident response processes and playbooks, and collaborate with the SOC on detection rules and incident handling.
- Support GRC with evidence and compliance requirements for ISO27001, NCSC Cloud Security Principles, and SOC2.
- Review and prioritize security tool outputs into actionable security stories for delivery teams.
- Guide junior engineers and developers in adopting secure practices and train the wider security team on cloud security topics and tooling.
- Contribute to IAM strategy and policy, including RBAC, Conditional Access, MFA, and least privilege.
- Optionally support IaC scanning, CI/CD integration, and documentation of standards, runbooks, and training materials.
Requirements
- Previous experience in cloud security engineering or related roles.
- Working knowledge of cloud security frameworks and best practices, including CSA STAR and NCSC Cloud Security Principles.
- Experience with automation and scripting using Python, PowerShell, or Bash.
- Proficiency with Azure security services including Defender for Cloud, Entra ID, and Sentinel.
- Proficiency with AWS security services including Security Hub, GuardDuty, IAM, Config, CloudTrail, and CloudWatch.
- Working knowledge of cloud incident response processes and procedures.
- Strong understanding of security best practices in multi-cloud environments.
- Familiarity with Infrastructure as Code using Terraform is desirable.
- Knowledge of cloud network security concepts including firewalls, NSGs, VPCs, and private endpoints is desirable.
- Exposure to ISO27001, SOC2, and NCSC Cloud Security Principles is desirable.
- Security certifications such as AZ-500, SC-100, AWS Security Specialty, CISSP, or CCSK are desirable.
Benefits
- People-first culture with valued ideas, supported growth, and opportunities to make an impact.
- Diverse, equitable, and inclusive workplace committed to equal opportunity.
- Recruitment accommodations and process adjustments are available through the talent acquisition team.
