> Markdown version of [/jobs/ext/2175004-senior-security-engineer](https://www.wearedevelopers.com/jobs/ext/2175004-senior-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - **Company:** Kainos - **Location:** Hurley, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), .NET Framework, Agile Methodology, Amazon Web Services, Software System Penetration Testing, Architectural Patterns, Microsoft Azure, Bash Shell, Cloud Computing Security, Static Program Analysis, Cyber Security, Continuous Integration, Digital Signature, Dynamic Program Analysis, Python (Programming Language), Open Web Application Security, Windows PowerShell, Scrum Methodology, Ansible, Web Application Security, Software Engineering, Systems Integration, Software Vulnerability Management, Scripting, Cloud Platform System, Software Security, Git, CIS Benchmarks, Terraform, Software Version Control, Azure Resource Manager, Static Application Security Testing, Programming Languages, Dynamic Application Security Testing - **Published:** August 22, 2026 - **Apply:** https://www.apply4u.co.uk/jobs/senior-security-engineer/44859760 ## About the Role facilitate penetration tests. Reviewing the outputs from security tools and security practices. You will filter and prioritise these into security stories that can be understood and actioned by the delivery teams. Verifying the implementation of security principles, architectural patterns, and requirements. Driving the adoption of cyber security practices (e.g. vulnerability management, threat modelling etc.) within Agile delivery teams. Putting people first & developing others Youll help coach and develop more junior members of the team. Minimum (essential) requirements: Experience of implementing application security or Cloud platform security. Experience in Defence Sector Active Security Clearance A detailed understanding of web application security. An understanding of modern cryptography and its application for encryption in-transit, encryption at-rest, hashing and digital signatures. An understanding of security practices such as threat modelling, vulnerability management, application security testing, and penetration testing. Experience of integrating application security tools (e.g. static analysis, dynamic analysis etc.) into the SSDLC. Experience of using modern version control systems (e.g. git) and either a scripting language (e.g. Bash, Powershell etc.), or a programming language (e.g. Python, Java, .NET, JS etc.), or an Infrastructure as Code language (e.g. Terraform, ARM Templates, Ansible etc.) to automate tasks. The ability to convey security issues to technical and non-technical people. Desirable: An industry recognised qualification in Cyber Security. AWS or Azure mid-level certifications. Participation in the cyber security community (e.g. OWASP, HackTheBox, CTFs etc.). Experience working with agile software development methodologies (e.g. Scrum or Kanban). Embracing our differences At Kainos, we believe in the power of diversity, equity and inclusion. We are committed to building a team that is as diverse as the world we live in, where everyone is valued, respected, and given an equal chance to thrive. We actively seek out talented people from all backgrounds, regardless of age, race, ethnicity, gender, sexual orientation, religion, disability, or any other characteristic that makes them who they are. We also believe every candidate deserves a level playing field. Our friendly talent acquisition team is here to support you every step of the way, so if you require any accommodations or adjustments, we encourage you to reach out. We understand that everyone's journey is different, and by having a private conversation we can ensure that our recruitment process is tailored to your needs. TPBN1_UKTJ ## Description embedding security practices (e.g. vulnerability management, threat modelling etc.) and automating security artifact generation (e.g. secret scanning, container security, SAST, DAST etc.). You will provide subject matter expertise in application security or cloud security sharing knowledge on threats and vulnerabilities, identifying appropriate security controls, and increasing cyber security awareness within teams. Your key responsibilities will include: Daily collaboration with the application development and cloud platform teams to plan and prioritise security requirements as part of the secure software development lifecycle (SSDLC). Recommending security best practices for cloud platforms and automating compliance with cloud security baselines (e.g. CIS Benchmarks). Implementation of automated security tooling (e.g. within a Continuous Integration (CI) pipeline) to validate security requirements and identify potential issues. Working with external organisations to plan, scope and ## Related Videos - [Dev & Test in the Cloud? Deploy your cloud environments with Ansible & Terraform](https://www.wearedevelopers.com/videos/1607-dev-test-in-the-cloud-deploy-your-cloud-environments-with-ansible-terraform) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Terraform for Developers](https://www.wearedevelopers.com/videos/3-terraform-for-developers) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)