> Markdown version of [/jobs/ext/1382094-senior-security-engineer](https://www.wearedevelopers.com/jobs/ext/1382094-senior-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - **Company:** Thredd - **Location:** London, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Cloud Computing Security, Cyber Security, Continuous Integration, Intrusion Detection and Prevention, Network Security, Security Software, Systems Integration, Software Vulnerability Management, Working Model 2D, Policy as Code, Data Logging, Software Security, Technical Debt, Infrastructure Automation Frameworks, Devsecops, Vulnerability Analysis - **Published:** July 22, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=440b5b7f093fab1b ## About the Role Are you an experienced Security Engineer who enjoys sharing knowledge as much as solving complex technical challenges?, * Demonstrate experience designing, building, and operating automated security and compliance controls. * Strong hands-on experience with AWS security controls, including network security, vulnerability management, cloud security posture management (CSPM), runtime protection, logging and monitoring, and event-driven response and remediation. * Proficiency in Infrastructure-as-Code (IaC) and CI/CD tooling, with experience embedding security guardrails and policy enforcement. * Solid understanding of application security (AppSec) principles, including secure SDLC practices, vulnerability management, and remediation. * Experience integrating and operating core security tooling such as vulnerability scanners, log collection platforms, endpoint protection, and detection capabilities. * Ability to design and maintain security telemetry pipelines, dashboards, and reporting mechanisms to support continuous assurance. Where you'll work Our working model varies depending on the specific role and team requirements. We strive to provide flexibility whilst ensuring that each position is best supported for optimal collaboration and performance. ## Description As a Senior Security Engineer at Thredd, you will become a security ambassador across the business - you will use your technical credibility, communication skills, and a collaborative approach to influence engineering decisions, share security best practices, and help teams embed security into everyday decision-making. This role will play a key part in building scalable security solutions, controls, guardrails, and security visibility across AWS platforms and development workflows. By embedding security into the way we build and operate technology, you will enable continuous assurance and resilience by design, strengthen collaboration between security and engineering teams, and help create a culture where security accelerates innovation rather than slows it down. What you'll be doing as a Senior Security Engineer * Embed security-by-design across all initiatives, ensuring client trust, regulatory alignment, and strong collaboration with IT, business, legal, and external stakeholders. * Design secure-by-default cloud and platform architectures, implementing automated security and compliance controls using policy-as-code and infrastructure-as-code to improve reliability and reduce manual effort. * Build and maintain robust security telemetry, dashboards, and reporting to support data-driven risk assessments, vulnerability prioritisation, audit readiness, and alignment with frameworks (e.g., SOC 2, ISO 27001, NIST, CIS). * Plan and execute complex initiatives, enhance guardrails and validation mechanisms across environments, and drive measurable improvements in security posture, compliance maturity, and operational resilience. * Shape engineering best practices, identify systemic risks, and lead continuous improvement and change management efforts across systems and departments. * Mentor and lead within the security architecture function, foster learning and leadership development, remove barriers to performance, and build a strong, future-ready security culture. * Deliver reliable, well-documented security metrics and reporting aligned to business and regulatory needs; ensure controls are testable, monitored, and continuously enhanced through automation and engineering improvements. * Influence engineering practices through technical leadership, identifying opportunities to reduce manual effort, improve reliability, and embed security-by-design across all technology initiatives. * Work closely with IT and business stakeholders to integrate security requirements into project planning, manage organisational impact assessments, and ensure compliance without operational disruption. * Maintain strong knowledge of cloud security, DevSecOps, application security, and compliance automation practices. * Design and implement secure-by-default cloud and platform architectures that embed preventative and detective controls, and build and maintain robust security controls, guardrails, and validation mechanisms across cloud, network, and application environments. * Prioritise vulnerabilities, technical debt, and control improvements based on threat models and risk assessments. * Build and maintain strategic relationships: with senior leadership, legal teams, and external regulatory bodies to ensure security strategies align with business and compliance requirements * Shape talent development strategies to build a pipeline of future security leaders, ensuring a high standard of cybersecurity knowledge and capability across the team. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)