> Markdown version of [/jobs/ext/56865-principal-security-engineer](https://www.wearedevelopers.com/jobs/ext/56865-principal-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Security Engineer - **Company:** Auros - **Location:** Sheffield, UK (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Bash Shell, Cloud Computing Security, Cyber Security, System Configuration, Continuous Integration, Identity and Access Management, Python (Programming Language), Key Management, Linux System Administration, Pulumi, Scripting, Cloud Platform System, Multi-Cloud, Gitlab, Casper Suite, Hardware Infrastructure, Software Coding, Terraform - **Published:** May 24, 2026 - **Apply:** https://find.jobs/jobs-near-me/principal-security-engineer-sheffield/2783501378-2/ ## About the Role * 8+ years' hands-on experience in security engineering or security operations * Strong, opinionated views on IAM (you've designed and implemented identity and access management across cloud environments and have a clear philosophy on how it should work) * Strong working knowledge of cloud security controls across multiple providers (AWS and Azure preferred) * Experience securing CI/CD platforms, GitLab preferred * Familiarity with corporate IT security tooling (Jamf, endpoint protection, DLP, SSO/IdP) * Comfortable in Linux environments and scripting (Python, Bash, or similar) * Experience with infrastructure-as-code (Terraform, Pulumi etc.) is a plus * Exposure to financial services, crypto, or other regulated environments is a plus but not required * We value demonstrated skills and practical experience over certifications. ## Description We're hiring a hands-on principal security engineer to implement and operate security controls across our infrastructure. This is a technical execution role where you'll be writing code, configuring systems, and shipping security improvements, not writing policies or managing people. You'll work closely with Infrastructure and Engineering teams to harden our cloud environments, secure our CI/CD pipelines, and protect both corporate and production systems. The scope is broad, the environment is fast-paced, and you'll be expected to own problems end-to-end. We believe security should enable the business, not obstruct it. You'll design controls that are effective but unobtrusive, security that works in the background without creating friction for engineers or traders. What You'll Do * Implement and maintain security controls across multi-cloud environments (primarily AWS, with some Azure, GCP and AliCloud) and on-prem infrastructure * Own IAM strategy and implementation: design and enforce identity, access, and permissions models that are secure, scalable, and practical * Design and operate key management and custody security controls such as HSMs, secrets management, and secure key handling for trading operations * Harden CI/CD pipelines (GitLab) and secure the software delivery process * Configure and operate corporate security tooling (endpoint protection, MDM/Jamf, DLP, identity management) * Respond to security incidents: triage, investigate, contain, remediate * Conduct security assessments of infrastructure and applications * Automate security operations: detection, alerting, and response * Work with Infrastructure to embed security into cloud provisioning and system configuration ## Related Videos - [Why segmenting your infrastructure into tiers makes your infrastructure design better](https://www.wearedevelopers.com/videos/1960-why-segmenting-your-infrastructure-into-tiers-makes-your-infrastructure-design-better) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Terraform for Developers](https://www.wearedevelopers.com/videos/3-terraform-for-developers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)