Security Engineer

Anson McCade
Manchester, UK
2 days ago
Apply on www.collegerecruiter.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
£67,000.0
Working hours
Regular working hours

Tech stack

Kubernetes Security Application Programming Interfaces (APIs) Amazon Web Services Application Layers User Authentication Microsoft Azure Bash Shell Cloud Computing Cloud Engineering Encodings Identity and Access Management Python (Programming Language)
+16 more
Key Management OAuth Role-Based Access Control Reliability Engineering Single Sign-On Software Engineering Scripting Software Security Build Management Api Design Software Coding Restful APIs Devsecops Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

Security Engineer - API, IAM & Automation

Locations: Glasgow, Greater Manchester or Northampton (Hybrid)

Salary: Up to £67,000 base + bonus (DOE)

The Role

We’re looking for a Security Engineer to join a growing security engineering function, helping to design and build secure, scalable systems with a strong focus on API security, automation, and identity.

This role suits someone from a Security Engineering, DevSecOps, Platform Engineering or Cloud Engineering background who enjoys working close to code and infrastructure, and embedding security into the software development lifecycle.

Key Responsibilities

  • Design and secure APIs, including authentication, authorization, and secure communication patterns.
  • Develop and maintain automation and security tooling using Python and Bash.
  • Build and operate Identity & Access Management (IAM) and secrets management solutions.
  • Work closely with software and platform teams to embed security into CI/CD pipelines.
  • Perform vulnerability assessments and support remediation across cloud and application layers.
  • Define and implement security engineering standards, patterns, and best practices.
  • Contribute to audits, risk assessments, and continuous improvement of security controls.

Required Experience

  • Strong experience with API development and API security (REST, OAuth, authentication, secure design).
  • Solid programming / scripting skills in Python and Bash.
  • Hands-on experience with IAM (e.g. cloud IAM, SSO, RBAC, secrets management).
  • Cloud experience with AWS and/or Azure.
  • Background in Security Engineering, DevSecOps, SRE, or Platform Engineering.
  • Experience integrating security into CI/CD pipelines.
  • Knowledge of vulnerability scanning (SAST, DAST, SCA).
  • Familiarity with container and Kubernetes security.

This is an opportunity to play a key role in shaping secure-by-design engineering practices across a modern cloud and API-driven environment, with real technical ownership and influence.

Requirements

This role suits someone from a Security Engineering, DevSecOps, Platform Engineering or Cloud Engineering background who enjoys working close to code and infrastructure, and embedding security into the software development lifecycle., * Strong experience with API development and API security (REST, OAuth, authentication, secure design).

  • Solid programming / scripting skills in Python and Bash.
  • Hands-on experience with IAM (e.g. cloud IAM, SSO, RBAC, secrets management).
  • Cloud experience with AWS and/or Azure.
  • Background in Security Engineering, DevSecOps, SRE, or Platform Engineering.
  • Experience integrating security into CI/CD pipelines.
  • Knowledge of vulnerability scanning (SAST, DAST, SCA).
  • Familiarity with container and Kubernetes security.

This is an opportunity to play a key role in shaping secure-by-design engineering practices across a modern cloud and API-driven environment, with real technical ownership and influence.

Benefits & conditions

Salary: Up to £67,000 base + bonus (DOE)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.collegerecruiter.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Videos

See all

Related articles

See all