> Markdown version of [/jobs/ext/2175894-senior-security-engineer](https://www.wearedevelopers.com/jobs/ext/2175894-senior-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - **Company:** Docebo - **Location:** London, UK - **Experience:** Expert - **Salary:** £67,800.0 - £90,400.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Microsoft Azure, Bash Shell, Cloud Computing, Cloud Computing Security, Cloud Engineering, Configuration Management, Cyber Security, Computer Networks, Continuous Integration, Learning Management Systems, Data Auditing, Federated Identity Management, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Key Management, Automation of Marketing, Network Segmentation, Role-Based Access Control, Cloud Services, Runbook, Security Information and Event Management, Systems Integration, Software Vulnerability Management, Cloud Platform System, Mitre Att&ck, Multi-Cloud, Infrastructure as Code (IaC), Amazon Virtual Private Cloud (VPC), Cloudformation, Infrastructure Automation Frameworks, Cybercrime, CIS Benchmarks, Terraform - **Published:** August 22, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5851154921 ## About the Role * 5+ years of relevant work experience in cybersecurity, with a strong focus on cloud security in production AWS environments. * Deep hands-on experience with AWS security services: IAM, SCPs, CloudTrail, GuardDuty, Config, KMS, VPC security, and more. * Good knowledge of Kubernetes security - including RBAC, pod security standards, network policies, admission controllers, and secrets management. * Experience with cloud security posture management (CSPM) and cloud workload protection (CWPP/CNAPP) tools. * Experience securing IaC pipelines (Terraform, CloudFormation) and integrating security scanning into CI/CD workflows. * Good experience with container and image security - scanning, runtime protection, supply chain risk. * Experience with SIEM and detection engineering - building and tuning cloud-native detection rules, threat hunting across CloudTrail and application logs. * Familiarity with automation platforms and AI-driven security tools to streamline detection, enrichment, and response. * Experience with Infrastructure as Code (IaC) and scripting (Python, Bash, or similar) to develop custom security tooling and automate workflows. * Strong IAM fundamentals: least privilege, cross-account roles, permission boundaries, federated identity, and privileged access management. * Comfortable working across Azure/GCP in addition to AWS - multi-cloud exposure is a plus. * In-depth knowledge of information security principles and cybersecurity frameworks relevant to cloud environments: MITRE ATT&CK for Cloud, CIS Benchmarks, AWS Well-Architected Security Pillar, NIST CSF, SOC 2, ISO 27001. * Willingness and ability to participate in an on-call rotation, including after-hours response. * Ability to produce clear, comprehensive, and well-structured documentation (e.g. incident reports, architecture reviews, runbooks, and security standards) and to communicate complex technical issues effectively to non-technical stakeholders. ## Description The Senior Security Engineer will play a central role in securing Docebo's cloud infrastructure, with a primary focus on AWS environments. Working closely with Cloud Infrastructure & Operations, Engineering, and other security teams, this role is responsible for designing, implementing, and continuously improving cloud security controls across all layers of the stack - from infrastructure provisioning and container orchestration to runtime detection and compliance enforcement. This is a hands-on, high-ownership role for someone who thinks in terms of risk and moves quickly to reduce it. The role also includes participation in an on-call rotation for security incidents affecting Docebo systems. * Cloud Security Architecture & Hardening: Own the security posture of Docebo's AWS environments. Define and enforce secure account structures, service control policies (SCPs), guardrails, and baseline configurations across multi-account setups. Evaluate and improve network segmentation, IAM boundaries, and data protection controls. Identify and remediate misconfigurations using CSPM tooling and manual review. * Infrastructure as Code Security: Partner with Cloud Infrastructure to integrate security controls into IaC workflows. Define guardrails to catch insecure configurations before deployment. Own security scanning in CI/CD pipelines and promote a shift-left approach to cloud security across engineering teams. * Incident Response & On-Call: Participate in the on-call rotation for security incidents, including triage, containment, and escalation for after-hours events. Lead investigation and root cause analysis for cloud security incidents with clear written post-mortems. Leverage automation and AI tooling to reduce mean time to detect and respond. * Cloud Detection & Threat Monitoring: Build and maintain detection coverage for cloud-native threats (privilege escalation, unusual API activity, lateral movement, data exfiltration, and more). Leverage CloudTrail, GuardDuty, and SIEM integrations to maintain visibility across the AWS estate. Align detection logic with MITRE ATT&CK for Cloud. * Vulnerability & Configuration Management: Own vulnerability management for cloud workloads - prioritizing findings from cloud configuration assessments, and runtime protection tools. Drive remediation with Engineering and Infrastructure teams, and build automated enforcement where manual review doesn't scale. * Identity & Access Management: Define and enforce least-privilege principles across AWS IAM, service accounts, and federated identity. Review and improve IAM policies, permission boundaries, cross-account roles, and access patterns. Reduce standing access and enforce JIT access where appropriate. * Development of Security Best Practices: Develop and document best practices, policies, and procedures for cloud security. Provide guidance and training to engineering and infrastructure teams to promote a security-aware culture. * Vendor relationships: Maintain relationships with security vendors for technical issues, ensure smooth operations of security tools and services, and escalate problems or incidents to vendors when required. You're a cloud security practitioner who operates with a builder's mindset. You understand AWS deeply - not just its security services, but how misconfigurations and design decisions create real risk. You're comfortable reading IaC, reviewing IAM policies, and diving into CloudTrail logs to reconstruct what happened. You know how to work with engineering and infrastructure teams as a partner, not a gatekeeper - and you can communicate risk clearly to stakeholders who don't live in the cloud console. You're comfortable being on-call and making decisions under pressure. Additionally, holding security-related certifications such as those from ISC2, ISACA, SANS, or CompTIA, and having Cloud Architecture certifications (AWS Security Specialty, AWS Solutions Architect, or equivalent) will significantly enhance your effectiveness in this role. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)