> Markdown version of [/jobs/ext/1492334-principal-cloud-security-engineer](https://www.wearedevelopers.com/jobs/ext/1492334-principal-cloud-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Cloud Security Engineer - **Company:** LastPass - **Location:** UK (Remote available) - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Artificial Intelligence, Amazon Web Services, Cloud Computing, Cloud Computing Security, Cyber Security, Computer Networks, Continuous Integration, DevOps, Identity and Access Management, Virtual Private Networks (VPN), Software Engineering, TCP/IP, AWS Cdk, Transport Layer Security, Large Language Models, AWS ECS, Gitlab, Cloudformation, Gitlab-ci, Kubernetes, Cloudwatch, Terraform, Software Version Control, AWS EKS, Docker, Vulnerability Analysis - **Published:** July 30, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=4e92186317763e57 ## About the Role As a Principal Cloud Security Engineer at LastPass, you will partner with DevOps and CI/CD engineers and our Architects team to ensure security best practices are embedded across our cloud infrastructure. We are looking for an experienced security engineering leader with an ability to scale security and make the right trade-off decisions that enable us to offer secure, innovative solutions to customers., * Proven experience working with AWS and AWS security services in a secure production environment, including IAM, Config, KMS, Secrets Manager, CloudWatch, CloudTrail, and GuardDuty * Proven experience working closely with engineering teams and supporting them on their path to shifting security left * Background with infrastructure as code (AWS CDK, CloudFormation, or Terraform), version control and CI tools such as GitLab and GitLab CI * Hands-on experience with Kubernetes (AWS EKS), containers (Docker, AWS ECS), K8s admission controllers and Supply Chain Security * Solid understanding of internet and computer network protocols, including TCP/IP, TLS, and VPN * Good written and verbal communication skills in English * Collaborative team player with a hands-on, can-do approach to problem solving It's great, but not required: * AWS Certified Security - Specialty certification or similar. * General familiarity with AI tools and large language models (e.g., Claude by Anthropic, AWS Bedrock) ## Description The Cloud Security team at LastPass is a collaborative group of talented cloud security engineers working in close partnership with our engineering, platform, and trust & security teams. We are on a mission to safeguard the privacy and security of our company and users' data, embedded directly in the heart of our product development. If you are passionate about complex problem solving and motivated by scale, then this is the role for you! Who will you work with? You will work closely with DevOps and CI/CD engineers, Cloud Architects, and cross-functional engineering teams across LastPass. You will also collaborate with our Trust & Security and Platform teams, acting as a key embedded security partner throughout the product and infrastructure development process to drive secure-by-design outcomes at every stage. What are some of the exciting challenges you will be working on? * Act as a strategic security leader by defining and driving cloud security principles, standards, and reference architectures across the organization * Use your knowledge of security architecture to help engineers build and securely operate products and services from the ground up * Assess, design, and implement security processes and controls to meet security, compliance, and audit requirements * Perform proactive research to identify new threats and attack vectors * Partner with engineering teams to embed shift-left security practices throughout the software development lifecycle * Implement and manage cloud and Kubernetes security posture management tooling to continuously monitor and reduce risk across containerized workloads ## Related Videos - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) ## Related Articles - [The top 200 passwords of 2024 can be cracked in less than a second](https://www.wearedevelopers.com/magazine/502-the-top-200-passwords-of-2024-can-be-cracked-in-less-than-a-second) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: 5 Security and Privacy Tools for Developers](https://www.wearedevelopers.com/magazine/710-the-overflow-5-security-and-privacy-tools-for-developers) - [Dev Digest 162: AI careers, MCP, AWS best practices & floppy sweaters](https://www.wearedevelopers.com/magazine/571-dev-digest-162-ai-careers-mcp-aws-best-practices-floppy-sweaters)