Security Engineer

Era4
UK
1 day ago
Apply on www.adzuna.co.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
£52,730.0
Working hours
Regular working hours

Tech stack

Kubernetes Security Artificial Intelligence Software System Penetration Testing Build Automation Bash Shell Cloud Computing Cloud Computing Security Continuous Integration Data Centers Intrusion Detection and Prevention Python (Programming Language) Network Security
+21 more
Network Segmentation PCI Data Security Standards Ansible Red Team (Cyber Security) Azure Machine Learning Runbook Security Information and Event Management Software Engineering Software Vulnerability Management AI Infrastructure Data Logging Firewalls (Computer Science) Containerization Kubernetes Bare Metal CIS Benchmarks Terraform Devsecops Security Orchestration, Automation & Response Static Application Security Testing Dynamic Application Security Testing

Job description

We are seeking a Security Engineer to design, implement, and continuously improve security controls across our next-generation AI infrastructure and datacentre operations. This role focuses on protecting Kubernetes-based and cloud-native environments, securing our datacentre networking and infrastructure stack, strengthening security posture, identifying and mitigating risks, and enabling secure software delivery practices.

You will work closely with engineering, platform, and operations teams to integrate security into Era4’s proprietary cloud infrastructure, datacentre networks, CI/CD pipelines, containerized workloads, GPU-accelerated compute, and AI/ML platforms. The successful candidate will combine hands-on technical expertise with a proactive approach to threat detection, vulnerability management, and security automation across our brownfield-to-modern bare metal and cloud infrastructure environments., Cloud & Infrastructure Security:

  • Design, implement, and maintain security standard and controls for Kubernetes, Era4’s proprietary cloud infrastructure.
  • Secure datacenter perimeter and internal networks using Palo Alto, OpnSense, and Nokia networking platforms.
  • Review infrastructure architectures and perform security assessments to identify risks and recommend mitigations.

Application & DevSecOps Security:

  • Integrate security controls into CI/CD pipelines, including SAST, DAST, dependency scanning, container image scanning, and secrets detection.
  • Partner with development teams to implement secure coding practices and remediate security findings.
  • Conduct threat modelling and security reviews for new applications, services, and infrastructure changes.

Vulnerability & Risk Management:

  • Lead vulnerability identification, prioritization, remediation, and reporting activities across infrastructure and applications.
  • Develop processes for continuous security assessment and compliance monitoring.
  • Track security metrics and drive remediation efforts with engineering teams.

Detection & Response:

  • Develop and maintain security monitoring, alerting, detection capabilities and incident response playbooks.
  • Investigate security incidents, perform root cause analysis, and coordinate remediation activities.
  • Support threat hunting and proactive identification of suspicious activity across cloud and Kubernetes environments.

Security Automation:

  • Build automation to improve security monitoring, compliance validation, vulnerability management, and incident response workflows.
  • Leverage Infrastructure as Code and policy-as-code frameworks to enforce security standards at scale.
  • Integrate security tooling into existing operational and engineering workflows.

Requirements

Must have the ability to achieve Security Clearance. (Won’t be an immediate request but within the next 12 months)., * In depth experience in Security Engineering, Cloud Security, DevSecOps, Infrastructure Security, or Datacentre Security.

  • Expert knowledge of cloud security principles and experience securing Kubernetes environment , container security, workload protection, and cloud-native security tooling.
  • Hands-on experience with datacentre network security, firewalls, and network segmentation (Palo Alto firewalls, OpnSense, Nokia networking, or similar).
  • Familiarity with CI/CD security controls, secure software development practices, and supply chain security.
  • Experience with SIEM, logging, monitoring, and security analytics platforms.
  • Hands-on experience with vulnerability management platforms and security assessment methodologies.
  • Scripting and automation skills using Python, Bash, or similar languages.
  • Experience implementing security controls using Infrastructure as Code (Terraform, Ansible, or similar)

Nice to Have:

  • Experience securing AI/ML or GPU-based infrastructure.
  • Familiarity with compliance frameworks such as SOC 2, ISO 27001, NIST CSF, CIS Benchmarks, or PCI DSS.
  • Experience with threat modelling, penetration testing, or red team engagements.
  • Security certifications such as CISSP, GSEC, GCIH, GCIA, CCSK, CCSP, or relevant cloud security certifications.

About the company

Era4 is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.co.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

1:42 min

Automating Skupper deployments using Ansible

Alex Soto Alex Soto · World Congress 2024

2:50 min

Introduction and the value of runbooks

Hila Fish · World Congress 2023

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

Videos

See all

Related articles

See all