> Markdown version of [/jobs/ext/2727150-developer-experience-security-engineer](https://www.wearedevelopers.com/jobs/ext/2727150-developer-experience-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Developer Experience Security Engineer - **Company:** Motorway - **Location:** UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Cloud Computing Security, Cyber Security, Databases, Identity and Access Management, Intrusion Detection Systems, Key Management, Security Information and Event Management, Software Engineering, Web Applications, Data Logging, Scripting, Google Cloud, Mitre Att&ck, AWS Fargate, Serverless Computing, Vulnerability Analysis - **Published:** September 5, 2026 - **Apply:** https://startup.jobs/senior-developer-experience-security-engineer-motorway-co-uk-9767838 ## About the Role * Proven experience as a Platform engineer, Developer Experience engineer, or similar role focused on enabling other engineers. * Proven experience working with Containers and serverless with Infrastructure as code. * Good knowledge of AWS cloud security best practices and tooling * Technical knowledge of best practice security for networks, systems, web applications, APIs and databases. * Good understanding of secure software development practices. * Familiarity with security tools and technologies, such as SIEM, IDS/IPS, WAF and vulnerability scanners. * Knowledge of common adversarial Tactics, Techniques and Procedures (Mitre Att&ck TTPs). * Knowledge of security standards and frameworks (e.g. ISO27001, NIST CSF, AWS FSBP) is beneficial. * Relevant security certifications (e.g. GCLD, Security+, AWS/GCP Security Certifications) are a plus. * Excellent problem-solving and analytical skills. * Strong communication and collaboration abilities ## Description Motorway is rapidly growing its technology team and business, and we are looking for a Developer Experience Security Engineer to help enable a secure, scalable, and frictionless developer experience across Motorway.. We have recently built and rolled out a new container platform on top of AWS Fargate, and are currently enhancing our observability, reliability, and developer-focused tooling. We will continue to build and evolve secure, standardised platform capabilities that reduce cognitive load and help teams ship faster with confidence. As a Developer Experience Security Engineer, you will ensure that security is built into how engineers build, deploy, and operate software, making the secure path the easiest path you will ensure that security is built into how engineers build, deploy, and operate software. The role will involve: * Design, implement, and maintain secure-by-default platform capabilities (e.g. IAM patterns, network primitives, secrets management, runtime protections, encryption) that are easy for product teams to adopt. * Build automated security checks, guardrails, and visibility that continuously assess risk and reduce the need for manual security audits. * Collaborate with engineering to embed secure software development practices into CI/CD pipelines, templates, and shared tooling (Shift left and Secure by design principles). * Reduce manual work (toil) for the technology and Security Operations Team using automation (e.g. scripting, workflows, tooling). * Ensure platform-level security telemetry, logging, and monitoring are consistent, high-quality, and provided as a standard capability for all teams. * Define and implement platform-wide security use cases (e.g. SIEM detections, alerts, and signals) that scale across teams without bespoke configuration * Work as part of a virtual SOC with the Security Operations Team to support in security incident response. * Stay up-to-date with the latest security trends and best practices. * Enable secure engineering practices through documentation, examples, platform defaults, and targeted training where appropriate. * Help translate security policies and standards into practical, enforceable platform patterns and guardrails.. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Road to MLOps: How Verivox Transitioned to AWS](https://www.wearedevelopers.com/videos/1050-the-road-to-mlops-how-verivox-transitioned-to-aws) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Serverless landscape beyond functions](https://www.wearedevelopers.com/videos/491-serverless-landscape-beyond-functions) ## Related Articles - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)