Senior Security Engineer
Role details
Job location
Tech stack
Job description
As a Senior Security Engineer at Thredd, you will become a security ambassador across the business - you will use your technical credibility, communication skills, and a collaborative approach to influence engineering decisions, share security best practices, and help teams embed security into everyday decision-making. This role will play a key part in building scalable security solutions, controls, guardrails, and security visibility across AWS platforms and development workflows. By embedding security into the way we build and operate technology, you will enable continuous assurance and resilience by design, strengthen collaboration between security and engineering teams, and help create a culture where security accelerates innovation rather than slows it down.
What you'll be doing as a Senior Security Engineer
- Embed security-by-design across all initiatives, ensuring client trust, regulatory alignment, and strong collaboration with IT, business, legal, and external stakeholders.
- Design secure-by-default cloud and platform architectures, implementing automated security and compliance controls using policy-as-code and infrastructure-as-code to improve reliability and reduce manual effort.
- Build and maintain robust security telemetry, dashboards, and reporting to support data-driven risk assessments, vulnerability prioritisation, audit readiness, and alignment with frameworks (e.g., SOC 2, ISO 27001, NIST, CIS).
- Plan and execute complex initiatives, enhance guardrails and validation mechanisms across environments, and drive measurable improvements in security posture, compliance maturity, and operational resilience.
- Shape engineering best practices, identify systemic risks, and lead continuous improvement and change management efforts across systems and departments.
- Mentor and lead within the security architecture function, foster learning and leadership development, remove barriers to performance, and build a strong, future-ready security culture.
- Deliver reliable, well-documented security metrics and reporting aligned to business and regulatory needs; ensure controls are testable, monitored, and continuously enhanced through automation and engineering improvements.
- Influence engineering practices through technical leadership, identifying opportunities to reduce manual effort, improve reliability, and embed security-by-design across all technology initiatives.
- Work closely with IT and business stakeholders to integrate security requirements into project planning, manage organisational impact assessments, and ensure compliance without operational disruption.
- Maintain strong knowledge of cloud security, DevSecOps, application security, and compliance automation practices.
- Design and implement secure-by-default cloud and platform architectures that embed preventative and detective controls, and build and maintain robust security controls, guardrails, and validation mechanisms across cloud, network, and application environments.
- Prioritise vulnerabilities, technical debt, and control improvements based on threat models and risk assessments.
- Build and maintain strategic relationships: with senior leadership, legal teams, and external regulatory bodies to ensure security strategies align with business and compliance requirements
- Shape talent development strategies to build a pipeline of future security leaders, ensuring a high standard of cybersecurity knowledge and capability across the team.
Requirements
Are you an experienced Security Engineer who enjoys sharing knowledge as much as solving complex technical challenges?, * Demonstrate experience designing, building, and operating automated security and compliance controls.
- Strong hands-on experience with AWS security controls, including network security, vulnerability management, cloud security posture management (CSPM), runtime protection, logging and monitoring, and event-driven response and remediation.
- Proficiency in Infrastructure-as-Code (IaC) and CI/CD tooling, with experience embedding security guardrails and policy enforcement.
- Solid understanding of application security (AppSec) principles, including secure SDLC practices, vulnerability management, and remediation.
- Experience integrating and operating core security tooling such as vulnerability scanners, log collection platforms, endpoint protection, and detection capabilities.
- Ability to design and maintain security telemetry pipelines, dashboards, and reporting mechanisms to support continuous assurance.
Where you'll work
Our working model varies depending on the specific role and team requirements. We strive to provide flexibility whilst ensuring that each position is best supported for optimal collaboration and performance.