> Markdown version of [/jobs/ext/2857073-platform-security-engineer](https://www.wearedevelopers.com/jobs/ext/2857073-platform-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Platform Security Engineer - **Company:** Era4 - **Location:** UK - **Salary:** £47,310.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Artificial Intelligence, Software System Penetration Testing, Build Automation, Bash Shell, Cloud Computing, Cloud Computing Security, Continuous Integration, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Key Management, PCI Data Security Standards, Role-Based Access Control, Red Team (Cyber Security), Azure Machine Learning, Security Information and Event Management, Software Engineering, Software Vulnerability Management, Policy as Code, Data Logging, Cloud Platform System, Containerization, Kubernetes, CIS Benchmarks, Devsecops, Security Orchestration, Automation & Response, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 12, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5879939530 ## About the Role * Expertise in Security Engineering, Cloud Security, DevSecOps, or Infrastructure Security. * In depth knowledge of cloud security principles and experience securing Kubernetes environments. * Experience with container security, workload protection, and cloud-native security tooling. * Hands-on experience with vulnerability management platforms and security assessment methodologies. * Familiarity with CI/CD security controls, secure software development practices, and supply chain security. * Experience with SIEM, logging, monitoring, and security analytics platforms. * Strong scripting and automation skills using Python, Bash, or similar languages. Preferred Qualifications: * Experience securing AI/ML or GPU-based infrastructure. * Familiarity with compliance frameworks such as SOC 2, ISO 27001, NIST CSF, CIS Benchmarks, or PCI DSS. * Experience with threat modelling, penetration testing, or red team engagements. ## Description You will work closely with engineering, platform, and operations teams to integrate security into cloud infrastructure, CI/CD pipelines, containerized workloads, and AI/ML platforms. The successful candidate will combine hands-on technical expertise with a proactive approach to threat detection, vulnerability management, and security automation., Cloud & Infrastructure Security: * Design, implement, and maintain security controls for Kubernetes, cloud infrastructure, and workloads. * Develop and enforce security standards, policies, and hardening baselines for cloud and on-premises environments. * Review infrastructure architectures and perform security assessments to identify risks and recommend mitigations. * Manage identity and access controls, including RBAC, IAM, secrets management, and privileged access. * Conduct threat modelling and security reviews for new applications, services, and infrastructure changes. * Integrate security controls into CI/CD pipelines, including SAST, DAST, dependency scanning, container image scanning, and secrets detection. Vulnerability & Risk Management: * Lead vulnerability identification, prioritization, remediation, and reporting activities across infrastructure and applications. * Develop processes for continuous security assessment and compliance monitoring. * Track security metrics and drive remediation efforts with engineering teams. Detection & Response: * Develop and maintain security monitoring, alerting, and detection capabilities. * Investigate security incidents, perform root cause analysis, and coordinate remediation activities. * Create and maintain incident response playbooks and procedures. Security Automation: * Build automation to improve security monitoring, compliance validation, vulnerability management, and incident response workflows. * Leverage Infrastructure as Code and policy-as-code frameworks to enforce security standards at scale. ## Related Videos - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Learning Kubernetes made easy with KubeCampus](https://www.wearedevelopers.com/magazine/348-learning-kubernetes-made-easy-with-kubecampus) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)