Security Engineering & Cloud / Application Security (All Levels) - UK Wide

Concept LTD
London, UK
about 1 month ago
Apply on uk.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Compensation
£50,000.0 - £120,000.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Microsoft Azure Bash Shell Software as a Service Cloud Computing Cloud Computing Security Code Review Continuous Integration Identity and Access Management Information Systems Security Architecture Professional Python (Programming Language) Key Management
+13 more
Network Security Open Web Application Security Public Key Infrastructure Systems Development Life Cycle Secure Coding Software Vulnerability Management Software Security Kubernetes Terraform Devsecops Docker Static Application Security Testing Dynamic Application Security Testing

Job description

We’re looking for talented Security Engineers at all levels-from Security Engineer through to Senior, Lead and Principal, and spanning Cloud Security, DevSecOps, Application / Product Security and Infrastructure Security-for upcoming roles across the tech and finance sectors. These are hands-on, builder-side security roles where you’ll design, build and harden the systems that keep organisations and their customers safe-embedding security in, rather than bolting it on.

You’ll work across the full secure-engineering lifecycle-from threat modelling and secure design through to implementation, automation, testing and response. The role suits someone who pairs a genuine security mindset with strong engineering craft and the pragmatism to make security an enabler that helps teams ship safely, not a blocker., * Design, build and harden secure systems, infrastructure and applications

  • Embed security into the SDLC and CI/CD pipelines (DevSecOps / shift-left)
  • Secure cloud environments across AWS, Azure and / or GCP
  • Implement and manage security controls, tooling and automation
  • Conduct threat modelling and secure design reviews
  • (Application Security) Review code and run SAST / DAST / SCA, remediating findings with development teams
  • Manage identity and access, secrets, encryption and key management
  • Run vulnerability management and drive remediation to closure
  • Automate security testing and guardrails as code
  • Support incident response and help resolve security issues
  • Partner with engineering so security is built in from the start
  • (For Senior / Lead roles) Set security engineering standards, mentor engineers and lead secure architecture, * The opportunity to work where security genuinely protects organisations and their customers
  • Exposure to modern cloud-native security tooling, DevSecOps practice and secure architecture
  • Roles at the level you’re ready for-we’re hiring across the full security engineering spectrum
  • A collaborative environment where security rigour and engineering craft are both valued
  • Clear scope to develop specialist depth (cloud, DevSecOps, AppSec, infrastructure) or stay broad
  • Flexible working arrangements (on-site, hybrid or remote) and supportive team culture

Requirements

  • Strong foundation in security engineering principles and secure architecture
  • Cloud security across AWS, Azure or GCP (IAM, network security, configuration, CSPM)
  • DevSecOps-securing CI/CD, infrastructure-as-code (Terraform) and containers (Docker, Kubernetes)
  • Application security-OWASP Top 10, SAST / DAST / SCA and secure coding practices
  • Scripting and automation (Python, Go or Bash)
  • Identity and access management, secrets management and encryption / PKI
  • Vulnerability management tooling and process
  • Solid networking and operating-system fundamentals
  • Certifications a plus-Security+, cloud security (AWS Security Specialty, AZ-500, GCP), CISSP / CSSLP at senior level, OSCP for AppSec

Security & Soft Skills:

  • A genuine security mindset balanced with real-world pragmatism
  • Strong collaboration with engineering-treating security as an enabler
  • Able to communicate risk clearly to technical and non-technical audiences
  • Strong problem-solving and genuine curiosity about how things break
  • Comfortable keeping pace with a fast-moving threat landscape
  • Collaborative approach across engineering, platform and risk teams

Domain Flexibility:

  • Roles span SaaS and tech, fintech and banking, e-commerce, healthtech and public sector-including the regulated environments common across tech and finance
  • Background in any of these is welcomed; appetite to learn an adjacent stack or regulatory context valued just as much

Experience Level:

  • Minimum 2+ years for Security Engineer, 5+ for Senior, 8+ for Lead / Principal
  • Background in security engineering, cloud security, DevSecOps or application security
  • Examples of systems, controls or security tooling you’ve built and owned end-to-end

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on uk.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all