> Markdown version of [/jobs/ext/2856632-staff-cloud-security-engineer-gcp-engine-by-starling](https://www.wearedevelopers.com/jobs/ext/2856632-staff-cloud-security-engineer-gcp-engine-by-starling). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Cloud Security Engineer (GCP) - Engine by Starling - **Company:** Starling - **Location:** London, UK - **Experience:** Expert - **Salary:** £77,046.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), Amazon Web Services, Border Gateway Protocol, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Computer Programming, System Configuration, Continuous Integration, Distributed Systems, Identity and Access Management, Intrusion Detection and Prevention, Intrusion Detection Systems, Virtual Private Networks (VPN), Python (Programming Language), Network Security, PostgreSQL, Open Source Technology, Open Web Application Security, PCI Data Security Standards, Role-Based Access Control, Secure Coding, Service-Oriented Architecture, Software Engineering, Systems Integration, TCP/IP, Software Vulnerability Management, Data Logging, Google Cloud, Grafana, Mitre Att&ck, Firewalls (Computer Science), Amazon Virtual Private Cloud (VPC), Backend, Kubernetes, Teamcity, Terraform, Devsecops, Static Application Security Testing, Vulnerability Analysis, Microservices, Dynamic Application Security Testing - **Published:** September 12, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5879984450 ## About the Role We're open-minded when it comes to hiring and we care more about aptitude and attitude than specific experience or qualifications. If you have an innate passion for security and care enough to find elegant solutions to difficult problems, we'd love to hear from you. What skills are essential: * Mature understanding of cloud security architecture, with deep expertise in GCP and a proven track record * Experience creating a GCP landing zone, configuring services such as organisation policies and VPC Service Controls * A deep understanding of GCP IAM and its limitations * Experience with service-oriented architecture using containers, distributed systems and immutable infrastructure on GCP (including GKE, Compute Engine, Shared VPC and Cloud SQL) * Expertise in Kubernetes, securing clusters (GKE) and meshes (Cilium is preferable), networking best practices and RBAC implementation (CKA, CKS qualifications are a plus) * Experience with Infrastructure as Code and infrastructure provisioning tools, particularly Terraform * Experience configuring GCP-native security posture and threat management with Security Command Center * Experience securing the software supply chain with Binary Authorization, Artifact Registry and Artifact Analysis * Experience with key and secret management on GCP - Cloud KMS, Cloud External Key Manager (EKM) and Secret Manager - including cryptographic key ceremonies * Experience with Workload Identity and Workload Identity Federation for keyless authentication of workloads and CI/CD * Experience configuring and utilising cloud-native security logging, monitoring and detection services * Strong programming skills - in security we write our own scripts for automation in Python, Go and other languages while contributing to open-source tools so we can utilise them * In-depth knowledge of security principles, technologies, best practices, and threat detection and mitigation strategies * Knowledge of common attack vectors and methodologies (OWASP Top 10, MITRE ATT&CK Framework and social engineering tactics) * The ability to identify potential threats, attack vectors and vulnerabilities in systems and applications * The ability to document security requirements from various stakeholders * Excellent problem-solving, communication and active listening skills with an innate passion for security * The ability to identify security gaps and create solutions to minimise risk and impact to us * A proactive approach to staying updated with the latest security threats, vulnerabilities and mitigation techniques * Thorough understanding of the incident response process (preparation, identification, containment, eradication, recovery, lessons learned) What skills are desirable: * In-depth knowledge of network security, including core routing and switching concepts (TCP/IP, BGP, VPNs), security controls (firewalls, WAFs, IDS/IPS), and practical experience designing hybrid connectivity between GCP and on-premise environments * Experience with data-residency and regulated-workload controls such as Assured Workloads and Access Transparency, relevant to deploying per-market for different banks' regulators * Hands-on experience taking a company through security and compliance frameworks like NIST, SOC 2, ISO 27001 and PCI DSS * Experience automating security controls and compliance checks against standards and frameworks including SOC 2, ISO 27001 and PCI DSS / 3DS * Container security knowledge including container image provenance (e.g. Sigstore, Notary) with an in-depth knowledge of container runtimes, and an understanding of integrating security into the software development lifecycle * Experience performing secure code reviews and security approvals, including the use of static and dynamic application security testing (SAST / DAST) tools * Experience in cryptography management and enhancements * Relevant security certifications such as ISC2 CC, CISSP, CCSP, CISM, AWS Security Specialty or GCP Professional Cloud Security Engineer The main part of our tech stack is listed below. We don't ask that you have experience in all of it, but if you do, that's great! * Java, which makes up the majority of our backend codebase * GCP and AWS - we're cloud-native * Microservice-based architecture * Kubernetes (GKE on GCP, EKS on AWS) * TeamCity for CI/CD (with multiple production releases per day) * Terraform and Grafana * RDS and CloudSQL for PostgreSQL ## Description As a Security Engineer at Engine, you'll be working on helping to keep our infrastructure secure and compliant and our staff safe and productive. You'll be working on projects covering identity and access management, cloud and network security, vulnerability management, security monitoring, security hardening, compliance reviews, and more. It's a very varied role with lots of close interaction with the infrastructure, security engineering, cross-cutting and compliance teams. We are looking for an experienced Senior / Staff level GCP Security Engineer to join our established Security Engineering team, working closely with Information Security, Infrastructure and the various Engine Technology teams to make sure security is at the heart of all our technical processes. As our subject matter expert, you will take ownership of engineering the security foundations of our Google Cloud Platform environment. This is a hands-on role for a specialist with a proven track record of designing, building, and automating security controls specifically for GCP, including hardened GKE clusters. Engine by Starling engineers are excited about helping us deliver new features, regardless of what their primary tech stack may be. Hear from the team in our latest Blog or our case studies with Women in Tech. As a GCP Security Engineer, you will: * Collaborate with stakeholders to define our Google Cloud security architecture (cloud identity, runtime security, security posture) * Design, document, build and maintain a secure and scalable infrastructure on GCP using Infrastructure as Code * Be part of the team responsible for safeguarding our systems, applications and data by ensuring secure user access, authentication and authorisation mechanisms are in place * Engineer and automate technical controls within GCP to ensure and demonstrate continuous compliance with stringent standards such as PCI DSS and 3DS * Drive security infrastructure deployments across our growing environments * Perform regular security assessments, audits, threat modelling and architecture design reviews to identify risks and vulnerabilities, triage found risks, identify improvements appropriately and design controls to implement as corrective actions * Lead incident response efforts, including investigation and remediation of security breaches * Support our internal security awareness and training programs, advocating the DevSecOps mindset that we have created across our technology teams, Interviewing is a two-way process and we want you to have the time and opportunity to get to know us, as much as we are getting to know you! Our interviews are conversational and we want to get the best from you, so come with questions and be curious. In general you can expect the below, following a chat with one of our Talent Team: * Initial interview with an Engineer - ~45 minutes * Take-home technical test, to be discussed in the next interview * Technical interview with some Engineers - ~1.5 hours * Final interview with our CTO / deputy CTO - ~45 minutes ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [5 steps for running a Kubernetes environment at scale](https://www.wearedevelopers.com/videos/88-5-steps-for-running-a-kubernetes-environment-at-scale) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Nest.js - TypeScript in the backend can also be clean](https://www.wearedevelopers.com/videos/1033-nest-js-typescript-in-the-backend-can-also-be-clean) - [All your telemetry data from any source in one place](https://www.wearedevelopers.com/videos/57-all-your-telemetry-data-from-any-source-in-one-place) ## Related Articles - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Fullstack Developer Salary UK](https://www.wearedevelopers.com/magazine/251-fullstack-developer-salary-uk)