> Markdown version of [/jobs/ext/3134487-senior-cloud-security-engineer](https://www.wearedevelopers.com/jobs/ext/3134487-senior-cloud-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cloud Security Engineer - **Company:** Psychiatry Uk - **Location:** Camelford, UK (Remote available) - **Experience:** Expert - **Salary:** £66,365.0 - **Contract:** Permanent contract - **Skills:** Microsoft Access, Microsoft Windows, Application Programming Interfaces (APIs), Amazon Web Services, Amazon Elastic Compute Cloud, Amazon S3, Software System Penetration Testing, Microsoft Azure, Backup Devices, Microsoft Online Services, Cloud Computing Security, Cloud Engineering, Cyber Security, Databases, Query Languages, Digital Forensics, Github, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Key Management, Network Security, Microsoft Security Essentials, Virtual Desktops, Windows PowerShell, Role-Based Access Control, Azure Active Directory, Aws Command Line Interface (CLI), Security Information and Event Management, Software Engineering, Software Vulnerability Management, Datadog, Data Logging, Cloud Platform System, Spring Cloud, Software Security, Mitre Att&ck, Cloudformation, Microsoft InTune, Amazon Relational Database Service, Information Technology, Cloudflare, AWS Fargate, Cloudwatch, Terraform, Devsecops, Security Orchestration, Automation & Response, Static Application Security Testing - **Published:** September 29, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5902316551 ## About the Role A collaborative, pragmatic and technically credible security professional who combines strong analytical thinking with a clear focus on patients, services and operational outcomes. You will be comfortable working autonomously, managing competing priorities and remaining calm and effective during incidents. Strong communication and influencing skills are essential, with the confidence to constructively challenge, explain complex technical risks to a range of audiences and build effective relationships across multidisciplinary teams. You will demonstrate integrity, sound judgement and accountability, alongside a commitment to knowledge sharing, developing others and continuous improvement., * Substantial hands-on experience in cloud or platform security, including designing, implementing and operating production security controls. * Strong AWS security engineering experience, including multi-account governance, IAM, logging, threat detection, vulnerability management, encryption, network controls and workload hardening. * Experience securing cloud-native applications, APIs, containers and CI/CD pipelines, with a strong understanding of DevSecOps and shared-responsibility models. * Experience building or reviewing infrastructure as code and security automation using technologies such as Terraform, CloudFormation, Python, PowerShell, AWS CLI or equivalent. * Experience of security monitoring, investigation and incident response using SIEM, cloud-native telemetry and relevant query languages. * Strong knowledge of network security, encryption, key and secrets management, resilience, vulnerability management and secure configuration. * Experience translating security risk, policy and compliance requirements into proportionate technical controls and auditable evidence. * Experience providing technical leadership, coaching or developing capability within security or engineering teams. * Strong understanding of security governance, risk management and the application of security controls within complex technology environments., * Practical experience of Microsoft Entra ID and Microsoft cloud security, including Conditional Access, MFA, PIM, RBAC and Defender capabilities. * Experience within healthcare, regulated digital services or environments processing sensitive or special category data. * Knowledge of relevant security and regulatory frameworks, including ISO/IEC 27001, Cyber Essentials Plus, DSPT, NCSC CAF, NCSC Cloud Security Principles, NIST CSF and UK GDPR. * Experience with security tooling such as Datadog, Cloudflare, Rapid7, GitHub security capabilities, CSPM/CNAPP platforms or managed SOC services. * Experience of penetration testing, red teaming, threat modelling, MITRE ATT&CK mapping or cloud forensic investigation. * Understanding of service management, change control, supplier assurance, business continuity and disaster recovery. * Degree or equivalent practical experience in cyber security, computer science, cloud engineering or a related discipline. * Relevant professional certifications, such as AWS Certified Security - Specialty, AWS Solutions Architect, Microsoft security certifications, CCSP, CISSP, CISM, GIAC or Terraform Associate. Certifications are welcomed as supporting evidence but are not a substitute for current, hands-on technical capability. ## Description The Senior Cloud Security Engineer is a senior, technically hands-on role with responsibility across cloud security engineering, platform assurance, DevSecOps, threat detection and continuous control improvement. The post holder will translate security policies, risk requirements and best practice into practical security guardrails, reusable patterns, automation and clear assurance evidence. Working collaboratively across the organisation, the role will partner closely with Cyber Security, Platform Engineering, Software Engineering, Digital Workplace/IT, Data Science, Information Governance and Service Management teams, as well as selected managed-service partners, to embed effective security controls and secure-by-design principles across our technology environment. This is a home-based role (applicants must reside in the UK), though occasional travel may be required for face-to-face meetings at various locations within the UK., * Own and evolve security guardrails, reference architectures and technical standards across AWS, Azure and Microsoft 365. * Design and assure security controls across identity, networking, compute, containers, storage, databases, encryption, secrets management, backup and recovery. * Provide senior technical review and challenge of cloud designs, threat models, Architecture Decision Records and significant changes. * Lead remediation of control gaps, ensuring security controls are practical, measurable and proportionate to risk and service criticality. AWS Platform Security * Support and strengthen the AWS security operating model, including landing zones, account boundaries, access controls, permission models and break-glass arrangements. * Engineer and assure cloud-native security capabilities including IAM, KMS, CloudTrail, Config, GuardDuty, Inspector, Security Hub, CloudWatch and AWS Backup. * Drive security improvements across AWS workloads, including EC2, RDS, S3, ECS/Fargate, Lambda, ECR and internet-facing services. Microsoft Cloud & Identity Security * Support and improve security across Microsoft 365 E5, Azure, Defender, Intune, Azure Virtual Desktop, Purview and SIEM capabilities. * Work with Digital Workplace teams and managed-service partners to validate controls, evidence their effectiveness and drive remediation. DevSecOps, Application Security & Assurance * Embed Secure-by-Design principles across key projects through PUK's Security and Technology Assurance Framework, maintaining proportionate and effective assurance criteria. * Integrate security into engineering workflows, CI/CD pipelines and cloud deployment patterns while minimising unnecessary delivery friction. * Implement and improve security testing, including SAST, SCA, secrets scanning, infrastructure-as-code, container and application security testing. * Partner with engineering teams on threat modelling, vulnerability remediation, dependency management and release assurance, promoting secure-by-default patterns and reusable solutions. Detection, Vulnerability Management & Incident Response * Ensure security telemetry across cloud, identity, network, workloads and applications is complete, protected and effectively monitored. * Lead technical assessment of complex vulnerabilities and misconfigurations, driving proportionate, risk-based remediation. * Act as a senior technical responder for cloud security incidents, supporting containment, investigation, recovery and lessons learned. * Work closely with PUK's 24/7 SOC, digital forensics and incident response partners. Governance, Compliance & Assurance * Translate regulatory, industry and organisational requirements-including ISO/IEC 27001, Cyber Essentials Plus, DSPT, NCSC frameworks and UK GDPR-into effective technical controls and evidence. * Maintain security engineering evidence to support audits, control testing, risk treatment and continuous improvement. * Provide security assurance for new systems, suppliers and material changes, covering areas such as access, encryption, logging, resilience, data residency and exit arrangements. * Contribute to security standards, hardening guidance, runbooks, architecture documentation and control reporting. Technical Leadership & Collaboration * Provide senior technical leadership, coaching and constructive challenge across Cyber, Platform, Engineering and Digital Workplace teams. * Lead technical investigations and security improvement initiatives, communicating clear recommendations to technical and non-technical stakeholders. * Work effectively with cloud, security and managed-service partners while retaining PUK ownership of security risk and control outcomes. * Manage priorities independently, escalating risks early and maintaining clear technical and assurance documentation. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Debugging in the Dark](https://www.wearedevelopers.com/videos/1658-debugging-in-the-dark) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Data Engineer Salary UK](https://www.wearedevelopers.com/magazine/253-data-engineer-salary-uk) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london)