> Markdown version of [/jobs/ext/2255937-security-engineer](https://www.wearedevelopers.com/jobs/ext/2255937-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Anson McCade - **Location:** Glasgow, UK - **Salary:** £67,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Amazon Web Services, Application Layers, User Authentication, Microsoft Azure, Bash Shell, Cloud Computing, Cloud Engineering, Encodings, Identity and Access Management, Python (Programming Language), Key Management, OAuth, Role-Based Access Control, Reliability Engineering, Single Sign-On, Software Engineering, Scripting, Software Security, Build Management, Api Design, Software Coding, Restful APIs, Devsecops, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** August 26, 2026 - **Apply:** https://www.collegerecruiter.com/job/2815099371-security-engineer ## About the Role This role suits someone from a Security Engineering, DevSecOps, Platform Engineering or Cloud Engineering background who enjoys working close to code and infrastructure, and embedding security into the software development lifecycle., * Strong experience with API development and API security (REST, OAuth, authentication, secure design). * Solid programming / scripting skills in Python and Bash. * Hands-on experience with IAM (e.g. cloud IAM, SSO, RBAC, secrets management). * Cloud experience with AWS and/or Azure. * Background in Security Engineering, DevSecOps, SRE, or Platform Engineering. * Experience integrating security into CI/CD pipelines. * Knowledge of vulnerability scanning (SAST, DAST, SCA). * Familiarity with container and Kubernetes security. This is an opportunity to play a key role in shaping secure-by-design engineering practices across a modern cloud and API-driven environment, with real technical ownership and influence. ## Description Security Engineer - API, IAM & Automation Locations: Glasgow, Greater Manchester or Northampton (Hybrid) Salary: Up to £67,000 base + bonus (DOE) The Role We're looking for a Security Engineer to join a growing security engineering function, helping to design and build secure, scalable systems with a strong focus on API security, automation, and identity. This role suits someone from a Security Engineering, DevSecOps, Platform Engineering or Cloud Engineering background who enjoys working close to code and infrastructure, and embedding security into the software development lifecycle. Key Responsibilities * Design and secure APIs, including authentication, authorization, and secure communication patterns. * Develop and maintain automation and security tooling using Python and Bash. * Build and operate Identity & Access Management (IAM) and secrets management solutions. * Work closely with software and platform teams to embed security into CI/CD pipelines. * Perform vulnerability assessments and support remediation across cloud and application layers. * Define and implement security engineering standards, patterns, and best practices. * Contribute to audits, risk assessments, and continuous improvement of security controls. Required Experience * Strong experience with API development and API security (REST, OAuth, authentication, secure design). * Solid programming / scripting skills in Python and Bash. * Hands-on experience with IAM (e.g. cloud IAM, SSO, RBAC, secrets management). * Cloud experience with AWS and/or Azure. * Background in Security Engineering, DevSecOps, SRE, or Platform Engineering. * Experience integrating security into CI/CD pipelines. * Knowledge of vulnerability scanning (SAST, DAST, SCA). * Familiarity with container and Kubernetes security. This is an opportunity to play a key role in shaping secure-by-design engineering practices across a modern cloud and API-driven environment, with real technical ownership and influence. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)