> Markdown version of [/jobs/ext/2254475-security-engineer-cloud-migration-to-aws](https://www.wearedevelopers.com/jobs/ext/2254475-security-engineer-cloud-migration-to-aws). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - Cloud Migration to AWS - **Company:** Version 1 Solutions Limited - **Location:** Manchester, UK (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Amazon Elastic Compute Cloud, Audit Trail, Cloud Computing Security, Code Review, Continuous Integration, Data Discovery, DDoS Mitigation, Linux, Identity and Access Management, Information Security Management, Intrusion Detection and Prevention, Virtual Private Networks (VPN), Python (Programming Language), Key Management, Network Security, Microsoft Software, Oracle (Applications), PCI Data Security Standards, Red Hat Enterprise Linux, Security Information and Event Management, Systems Integration, Policy as Code, Scripting, Snowflake, Outsystems, Boto3, AWS Lambda, Amazon Virtual Private Cloud (VPC), Gitlab, Git, Cloudformation, Gitlab-ci, Cloud Migration, Opsworks, CIS Benchmarks, Terraform, Operating System Security, Software Version Control, Devsecops, Security Orchestration, Automation & Response, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** August 26, 2026 - **Apply:** https://www.collegerecruiter.com/job/2815087992-security-engineer--cloud-migration-to-aws ## About the Role * AWS Security Hub - aggregated findings, standards, and posture management * Amazon GuardDuty - threat detection * AWS Config - configuration compliance and drift detection, custom/conformance rules * AWS IAM / IAM Identity Center - least-privilege roles, policies, permission boundaries, federation * AWS KMS & ACM - encryption key management and certificates * AWS WAF & Shield - application and DDoS protection * Amazon Inspector - vulnerability scanning for EC2/ECR/Lambda * AWS CloudTrail - audit logging and monitoring * AWS Organizations & Service Control Policies (SCPs) - multi-account guardrails * AWS Secrets Manager / Systems Manager Parameter Store - secrets handling * Amazon Macie - sensitive data discovery (desirable) * AWS Control Tower / Landing Zone - governed account provisioning, * Python - security automation, boto3, Lambda functions, remediation scripts, custom Config rules * Terraform - modules for security services, guardrails, IAM, networking * CloudFormation - templates and (desirable) StackSets across accounts * Familiarity with policy-as-code (e.g. OPA/Conftest, cfn-guard, Checkov, tfsec) is a strong plus CI/CD & Version Control * GitLab - repositories, merge requests, and GitLab CI/CD pipeline development * Integrating security scanning into pipelines: SAST, DAST, IaC scanning, secrets scanning, SCA, container image scanning * Git branching, code review, and shift-left security practices Migration & Infrastructure * Workload discovery and assessment ahead of migration * AWS migration tooling (Application Migration Service / MGN, DMS, Migration Hub) - desirable * Hybrid networking: Direct Connect, VPN, Transit Gateway, VPC design, security groups, NACLs * Operating system security hardening (Linux and/or Windows), * 4+ years in security engineering, cloud security, or infrastructure security (adjust to seniority). * Demonstrable hands-on experience securing production AWS environments. * Proven experience delivering or securing a cloud migration programme. * Strong scripting/automation ability in Python. * Experience with IaC (Terraform and/or CloudFormation) in a production setting. * Comfortable working in a GitLab-based DevSecOps workflow. * Solid understanding of security frameworks and compliance standards. ## Description Company Description Version 1 has celebrated 30 years in business and continues to be trusted by global brands to deliver technology and transformation solutions that drive customer success. Our deep expertise enables our customers to navigate the rapidly evolving technology landscape. We foster strong partnerships with global technology leaders including Microsoft, AWS, Oracle, Red Hat, OutSystems, Snowflake, ensuring that our customers are provided with the highest quality solutions and services. Company Description Version 1 has celebrated 30 years in business and continues to be trusted by global brands to deliver technology and transformation solutions that drive customer success. Our deep expertise enables our customers to navigate the rapidly evolving technology landscape. We foster strong partnerships with global technology leaders including Microsoft, AWS, Oracle, Red Hat, OutSystems, Snowflake, ensuring that our customers are provided with the highest quality solutions and services. * UK & Ireland's premier AWS, Microsoft & Oracle partner * 3300+ strong, €350/£300m revenue business * 10+ years as a Great Place to Work in Ireland & UK * Best Workplace for Women in the UK & Ireland by GPTW * Best Workplace for Wellbeing in the UK by GPTW We're an award-winning employer reflecting how our employees are at the very heart of what we do: We're a core values driven company, we hire people who share our values, and we reward those who display and foster them, it's deeply embedded within our DNA. Invest in us and we'll invest in you. Job Description We are seeking a hands-on Security Engineer to embed within a large-scale cloud migration programme, moving workloads into AWS. You will be responsible for designing, automating, and enforcing security controls throughout the migration lifecycle - ensuring that every workload lands in AWS with a secure, compliant, and auditable posture. This is a technical, build-focused role combining cloud security architecture, infrastructure-as-code, and Python automation. Key Responsibilities * Define and implement the security controls, guardrails, and landing zone baseline for workloads migrating to AWS. * Design and operate AWS-native security tooling across accounts and Organizations (see Technical Skills below). * Build security automation in Python - remediation Lambdas, compliance-check scripts, event-driven response, and integrations with ticketing/SIEM systems. * Author, review, and maintain infrastructure-as-code (Terraform and/or CloudFormation) for security services, guardrails, IAM, networking, and encryption. * Integrate security into GitLab CI/CD pipelines - SAST, IaC scanning, secrets detection, dependency/container scanning, and policy-as-code gates. * Assess the security posture of workloads before, during, and after migration; identify and remediate misconfigurations and vulnerabilities. * Design secure network segmentation and connectivity between source environments and AWS (Direct Connect / VPN, Transit Gateway, security groups, NACLs). * Implement IAM least-privilege models, identity federation, and secrets management for migrated workloads. * Define encryption standards (at rest and in transit) using KMS, ACM, and TLS policy. * Support compliance and audit requirements (e.g. CIS Benchmarks, NIST, ISO 27001, SOC 2, PCI-DSS as applicable) and produce evidence. * Partner with migration, platform, and application teams to unblock security issues without slowing delivery. * Contribute to incident detection and response runbooks for the AWS environment. Qualifications Required Technical Skills AWS Security Tooling * AWS Security Hub - aggregated findings, standards, and posture management * Amazon GuardDuty - threat detection * AWS Config - configuration compliance and drift detection, custom/conformance rules * AWS IAM / IAM Identity Center - least-privilege roles, policies, permission boundaries, federation * AWS KMS & ACM - encryption key management and certificates * AWS WAF & Shield - application and DDoS protection * Amazon Inspector - vulnerability scanning for EC2/ECR/Lambda * AWS CloudTrail - audit logging and monitoring * AWS Organizations & Service Control Policies (SCPs) - multi-account guardrails * AWS Secrets Manager / Systems Manager Parameter Store - secrets handling * Amazon Macie - sensitive data discovery (desirable) * AWS Control Tower / Landing Zone - governed account provisioning Automation & Infrastructure-as-Code * Python - security automation, boto3, Lambda functions, remediation scripts, custom Config rules * Terraform - modules for security services, guardrails, IAM, networking * CloudFormation - templates and (desirable) StackSets across accounts * Familiarity with policy-as-code (e.g. OPA/Conftest, cfn-guard, Checkov, tfsec) is a strong plus CI/CD & Version Control * GitLab - repositories, merge requests, and GitLab CI/CD pipeline development * Integrating security scanning into pipelines: SAST, DAST, IaC scanning, secrets scanning, SCA, container image scanning * Git branching, code review, and shift-left security practices Migration & Infrastructure * Workload discovery and assessment ahead of migration * AWS migration tooling (Application Migration Service / MGN, DMS, Migration Hub) - desirable * Hybrid networking: Direct Connect, VPN, Transit Gateway, VPC design, security groups, NACLs * Operating system security hardening (Linux and/or Windows) Required Experience & Qualifications * 4+ years in security engineering, cloud security, or infrastructure security (adjust to seniority). * Demonstrable hands-on experience securing production AWS environments. * Proven experience delivering or securing a cloud migration programme. * Strong scripting/automation ability in Python. * Experience with IaC (Terraform and/or CloudFormation) in a production setting. * Comfortable working in a GitLab-based DevSecOps workflow. * Solid understanding of security frameworks and compliance standards. Additional Information Why Version 1? At Version 1, we believe in providing our employees with a comprehensive benefits package that prioritises their wellbeing, professional growth, and financial stability. * Share in our success with our Quarterly Performance-Related Profit Share Scheme, where employees collectively benefit from a share of our company's profits * Strong Career Progression & mentorship coaching through our Strength in Balance & Leadership schemes with a dedicated quarterly Pathways Career Development programme * Flexible/remote working, Version 1 is tremendously understanding of life events and people's individual circumstances and offer flexibility to help achieve a healthy work life balance * Financial Wellbeing initiatives including; Pension, Private Healthcare Cover, Life Assurance, Financial advice and an Employee Discount scheme * Employee Wellbeing schemes including Gym Discounts, Bike to Work, Fitness classes, Mindfulness Workshops, Employee Assistance Programme and much more. Generous holiday allowance, enhanced maternity/paternity leave, marriage/civil partnership leave and special leave policies * Educational assistance, incentivised certifications, and accreditations, including AWS, Microsoft, Oracle, and Red Hat * Reward schemes including Version 1's Annual Excellence Awards & 'Call-Out' platform. * Environment, Social and Community First initiatives allow you to get involved in local fundraising and development opportunities as part of fostering our diversity, inclusion and belonging schemes. Version 1 is an equal opportunities employer. We are committed to building a diverse, inclusive and respectful workplace where everyone feels valued and able to thrive. We welcome applications from people of all backgrounds, identities and lived experiences, and we value the different perspectives people bring. We want every candidate to have a positive and accessible recruitment experience. If you need reasonable adjustments at any stage of the process, please contact at Version 1. We will consider all requests carefully, respectfully and confidentially. ## Related Videos - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [30 powerful AWS hacks in just 30 minutes: Boost your developer productivity](https://www.wearedevelopers.com/videos/1624-30-powerful-aws-hacks-in-just-30-minutes-boost-your-developer-productivity) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers)