> Markdown version of [/jobs/ext/3520775-security-engineer](https://www.wearedevelopers.com/jobs/ext/3520775-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** CloudFlare - **Location:** London, UK (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Code Review, Identity and Access Management, Python (Programming Language), Network Segmentation, Open Web Application Security, Zero Trust Network Access, TypeScript, Large Language Models, Software Security, Production Code, Cloudflare, Static Application Security Testing - **Published:** October 1, 2026 - **Apply:** https://www.apply4u.co.uk/jobs/security-engineer/49542139 ## About the Role written standards, and security embedded in code review. Use LLMs and agents to accelerate security workflows (triage, code review, evidence gathering) with guardrails you trust and help secure and monitor the (code/application/device) fleet. Support compliance work where it intersects security engineering: SOC 2, ISO 27001, customer security reviews, and pen test responses. What we're looking for 3+ years in security engineering with hands-on AWS security: IAM, KMS, networking, secrets, GuardDuty / Security Hub. Strong coding ability in TypeScript or Python or Go comfortable shipping production code, not just configs and scripts. Application security fluency: OWASP Top 10, threat modeling, and code-level reviews on real systems. Experience securing a B2B SaaS multi-tenant production environment. Comfort owning end-to-end work: scope, ship, measure. You don't wait for a queue. Clear communication with engineers, product, and non-technical stakeholders. Bias toward automating security ## Description tooling, and embed security into how engineers work every day. You'll report directly to the CTO and have broad scope across the platform (from CI/CD pipelines to multi-tenant APIs to incident response on authentication flows). Responsibilities Own the secure SDLC: drive SAST, dependency scanning, secrets detection, and PR-blocking standards across every repository. Harden our AWS and Cloudflare estate: IAM, secrets, network segmentation, KMS, WAF, GuardDuty, and zero-trust patterns. Run pen testing end-to-end: scope and coordinate engagements with both AI-driven scanners and human researchers, then drive findings through fix and retest. Threat-model product features before they ship, new Auth provider, expanded multi-tenant APIs, connector executions, agent tool-calling paths etc. Build detection and response capability around credential and authentication flows, with observability that closes incidents fast. Partner with engineering to raise the bar day-to-day: architecture reviews ## Related Videos - [Do TypeScript without TypeScript](https://www.wearedevelopers.com/videos/327-do-typescript-without-typescript) - [Fireside Chat with Cloudflare's Chief Strategy Officer, Stephanie Cohen (with Mike Butcher MBE)](https://www.wearedevelopers.com/videos/1366-fireside-chat-with-cloudflare-s-chief-strategy-officer-stephanie-cohen-with-mike-butcher-mbe) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Art and Craft of Type Development](https://www.wearedevelopers.com/videos/81-the-art-and-craft-of-type-development) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders)