> Markdown version of [/jobs/ext/329517-senior-cloud-security-engineer-automation-tooling-engine-by-starling](https://www.wearedevelopers.com/jobs/ext/329517-senior-cloud-security-engineer-automation-tooling-engine-by-starling). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cloud Security Engineer (Automation & Tooling) - Engine by Starling - **Company:** The Engine - **Location:** London, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Clean Code Principles, Kubernetes Security, Amazon Web Services, Cloud Computing Security, Cloud Engineering, Cyber Security, Github, Hardware Security Module, Identity and Access Management, Network Security, Network Architecture, Network Protocols, Public Key Infrastructure, Zero Trust Network Access, Software Engineering, Istio, Backend, Kubernetes, Teamcity, Terraform, Api Management, Microservices - **Published:** June 5, 2026 - **Apply:** https://find.jobs/jobs-near-me/senior-cloud-security-engineer-automation-tooling-engine-by-starling-london/2804474918-2/ ## About the Role Requirements What skills are essential: * Go Specialist: You are proficient in Go. You understand its concurrency models, testing patterns, and how to build idiomatic, performant services. * The Builder Mindset: You find manual work a personal affront. If a task needs to be done twice, you've already started planning the automation for it. * Cloud Native: Practical experience with AWS or GCP, ideally managed through Terraform. * Container Expertise: You understand Kubernetes internals-from the runtime security to the service mesh. * Identity & Networking: Strong understanding of cloud identity models and network protocols. What skills are desirable: * Experience with Cilium or eBPF-based security monitoring. * Knowledge of Sigstore/Cosign, image provenance, and SBOMs. * Familiarity with hardware security modules (HSMs) or advanced cryptography. * Cloud-native security certifications (AWS/GCP). ## Description As a Cloud Security Software Engineer, you will be a hands-on builder responsible for the security architecture of our multi-tenant core banking platform. You'll spend your days architecting and writing Go-based tooling, automating defenses, and ensuring our infrastructure across AWS and GCP is secure by design and compliant by default. The Mission Your mission is to solve complex security problems through software engineering, focusing on three core pillars: * Identity & Network Security: Engineering high-performance IAM controls and zero-trust network architectures. You will lead the way in refining edge-defense strategies and trust redirection, ensuring every request is verified and encrypted at scale. * Unified Vulnerability Orchestration: Architecting a custom "single pane of glass" for security data. You will build Go-based API integrations and microservices that bridge scanning engines, dependency trackers, and internal portals into a seamless, automated ecosystem. * Compliance as Code: Building the automated systems that provide real-time evidence for frameworks like SOC 2, ISO 27001 & PCI. You'll ensure we stay compliant through continuous, automated validation rather than manual overhead. The Team You will be a key member of our growing Security Engineering team, working at the intersection of Infrastructure, Cross-Cutting, and GRC. We operate like a specialized product team: we identify security friction and build the software to eliminate it. You won't work in a silo; you'll collaborate with engineers across the business to deliver a platform that is resilient by default. About You We are looking for Software Engineers who are passionate about the Go ecosystem and want to apply those skills to mission-critical security challenges. Whether you come from a Security Engineering background or you are a Backend Engineer with a "security-first" mindset, we value your ability to write clean, maintainable, and efficient code. What you'll get to do * Engineering Security Tooling: Lead the design and maintenance of our internal security tool suite, written primarily in Go, to automate evidence collection and real-time remediation of security alerts. * Infrastructure as Code: Write and peer-review Terraform and custom providers to manage identity and core infrastructure across AWS and GCP. * Supply Chain Security: Build automated systems to manage container provenance and integrate security analysis into our CI/CD pipelines (GitHub Actions/TeamCity). * Cloud Native Defense: Engineer Kubernetes security solutions leveraging Cilium, eBPF, and custom controllers to protect our microservices. * Cryptographic Engineering (PKI): Build and maintain our Go-based Certificate Authority (CA) tooling and internal PKI infrastructure. * Incident Response: Support the team in automated incident response, building the tools that help us investigate and mitigate threats faster. ## Related Videos - [Enterprise-Cloud-Native - Fast-Paced Development & Deployment in a Highly Secure Banking Environment](https://www.wearedevelopers.com/videos/671-enterprise-cloud-native-fast-paced-development-deployment-in-a-highly-secure-banking-environment) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) ## Related Articles - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)