> Markdown version of [/jobs/ext/1912710-cloud-security-engineer](https://www.wearedevelopers.com/jobs/ext/1912710-cloud-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security Engineer - **Company:** Starling Bank - **Location:** London, UK - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Cloud Computing Security, Code Review, Computer Programming, Distributed Systems, Middleware, Identity and Access Management, Public Key Infrastructure, Software Engineering, Delivery Pipeline, Infrastructure as Code (IaC), Kubernetes, Api Design, Terraform, Golang - **Published:** August 4, 2026 - **Apply:** https://find.jobs/jobs-near-me/apply/ats-redirect/?id=2909117973-2 ## About the Role * Demonstrated ability to architect secure, distributed systems with a focus on programmatic IAM and automated, API-driven PKI management. * Extensive experience with Infrastructure as Code (IaC) in Terraform and a deep commitment to writing clean, maintainable, and production-grade code-ideally in Golang. * A test-first mentality toward security, with experience building unit and integration tests into CI/CD pipelines to ensure that security guardrails are as reliable as the features they protect. * A strong conceptual grasp of cryptographic primitives and hands-on experience securing containerized workloads and service meshes within ECS and Kubernetes. * A track record of taking end-to-end ownership of complex technical projects, from initial design docs and RFCs through to deployment and observability. * A belief that if it isn't tested, it's broken, and a drive to proactively identify and fix vulnerabilities by treating security as a continuous engineering challenge. Our Team Philosophy The Security Engineering team is a diverse and dynamic group passionate about building secure and resilient systems. We're enthusiastic about security, but we're not about rigid, one-size-fits-all controls. We believe in striking a balance between protecting our systems and empowering our developers to build and innovate. Our goal is to make security a seamless part of the development lifecycle, not a roadblock. If you are someone who thrives in a collaborative environment and is excited about finding innovative security solutions, we would love to hear from you. ## Description As a Cloud Security Engineer at Starling, you'll be building and supporting tooling and infrastructure that spans across AWS and GCP supporting our internal operations and interfacing with other teams to deliver the services that support our business., While we are looking for deep cloud expertise, we are also highly interested in candidates with strong programming skills and a background in software engineering who want to apply those talents to security. This is a hands-on role for a builder who excels at writing clean, scalable code to automate away manual gates. You will work across AWS and GCP, developing the internal tools, guardrails, and services that empower our engineering teams to ship securely without sacrificing speed., * Engineer Secure Foundations: You will lead the design and implementation of critical security services, with a heavy focus on building robust Identity and Access Management (IAM) systems and automated, API-driven certificate management workflows. * Security-as-Code & Scalability: Leveraging a software-first philosophy, you will develop and maintain high-quality, scalable security tooling and middleware within ECS and Kubernetes environments, ensuring security logic is integrated directly into the deployment pipeline. * Collaborative Code Ownership: You will serve as a technical authority in cross-functional code reviews, acting as an engineering peer who helps teams bake security into their services from the first line of code to the final pull request. * Proactive System Hardening: You will stay ahead of the evolving threat landscape by treating security as a continuous engineering challenge-proactively identifying vulnerabilities and architecting technical solutions to fortify our global ecosystem. ## Related Videos - [Enterprise-Cloud-Native - Fast-Paced Development & Deployment in a Highly Secure Banking Environment](https://www.wearedevelopers.com/videos/671-enterprise-cloud-native-fast-paced-development-deployment-in-a-highly-secure-banking-environment) - [Developer’s Perspective: Overview of the Tezos Blockchain Ecosystem](https://www.wearedevelopers.com/videos/237-developer-s-perspective-overview-of-the-tezos-blockchain-ecosystem) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [A Guide To Functional Programming](https://www.wearedevelopers.com/videos/408-a-guide-to-functional-programming) ## Related Articles - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: 5 Security and Privacy Tools for Developers](https://www.wearedevelopers.com/magazine/710-the-overflow-5-security-and-privacy-tools-for-developers) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)