Cloud Security Engineer

Reply Ltd
London, UK
24 days ago
Apply on www.efinancialcareers.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Amazon Web Services Microsoft Azure Software as a Service Cloud Computing Security Cloud Engineering Cyber Security Domain Name System (DNS) Internet Protocol Security (IP SEC) Virtual Private Networks (VPN) Network Security Scrum Methodology Software Deployment
+10 more
Software Engineering TCP/IP Delivery Pipeline Software Security Information Technology Integration Frameworks Terraform Devsecops Static Application Security Testing Dynamic Application Security Testing

Requirements

alongside engineering and platform teams to design and implement secure cloud architectures, integrate security into delivery pipelines, and improve cloud security posture across primarily AWS -based environments. You will bring a strong cloud engineering background with a solid, practical understanding of security and a genuine desire to shift security left across the full delivery lifecycle. Responsibilities: Design and implement cloud security architectures on AWS (primary), with exposure to Azure and/or GCP being advantageous Build and maintain secure infrastructure using Infrastructure as Code (Terraform), including reusable, security-hardened modules and reference patterns Integrate security tooling and automated controls into CI/CD pipelines, including SAST/DAST tooling, secrets scanning, and policy-as-code enforcement Conduct threat modelling exercises, cloud security posture reviews, and risk assessments for cloud platforms and workloads Work within scaled agile delivery teams, contributing security requirements and controls to sprint cycles and platform roadmaps Provide technical security assurance for application deployments, third-party integrations, and SaaS product onboarding Support incident response planning and contribute to cloud resilience and recovery design for client-hosted services Communicate security risks and remediation priorities clearly to technical peers and, where needed, to technical leads and delivery managers About the candidate: A minimum Bachelor’s degree (2.1 or above) in Cyber Security, Computer Science, Software Engineering, or a related technical discipline Demonstrable, hands-on experience engineering and securing workloads on AWS Practical experience with Terraform and IaC-based delivery in a real engineering context Background in DevSecOps, secure software engineering, or application security, with direct experience integrating security into CI/CD pipelines Exposure to cloud security posture management, workload protection, or equivalent cloud-native security tooling Familiarity with network security fundamentals including TCP/IP, DNS, VPN, and IPSEC Familiarity working within financial services and/or public sector environments is advantageous Familiarity operating within agile delivery frameworks (Scrum, SAFe, or equivalent) Reply is an Equal Opportunities Employer and committed to embracing diversity in the workplace. We provide equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type regardless of age, sexual orientation, gender, identity, pregnancy, religion, nationality, ethnic origin, disability, medical history, skin colour, marital status or parental status or any other characteristic protected by the Law. Reply is committed to making sure that our selection methods are fair to everyone. To help you during the recruitment process, please let us know of any reasonable adjustments you may need.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.efinancialcareers.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

Videos

See all

Related articles

See all