
Cloud Security Engineer (Automation & Tooling) - Engine by Starling
- London
- Permanent
- Full-time
- Design, build, and maintain security automation and tooling to enforce security controls and simplify compliance (e.g., automating evidence collection for frameworks like SOC 2, ISO 27001, or PCI DSS)
- Build, manage, and automate identity and access management controls to ensure secure access to our cloud platforms and applications
- Write and review Infrastructure-as-Code (Terraform) to securely configure our AWS and GCP environments
- Secure our CI/CD pipelines by implementing and interpreting results from SAST/DAST/SCA tools and ensuring the integrity of our software supply chain
- Develop and maintain preventative and detective security controls within our cloud environments, responding to and automating the remediation of security alerts
- Implement and automate technical controls based on the findings from security assessments, audits, and architecture reviews
- Engineer solutions to secure our Kubernetes environments, focusing on RBAC, network policies, and runtime security
- Collaborate with engineering teams to implement security best practices and provide hands-on support for remediation efforts
- Contribute to incident response efforts, including the investigation, remediation, and post-mortem analysis of security breaches
- Strong, demonstrable hands-on experience in a software or infrastructure engineering role
- A genuine passion for security, demonstrated by a proactive desire to learn about emerging threats, vulnerabilities, and best practices
- Proficiency in at least one programming language, with a strong preference for Go, followed by Python
- A mature understanding of cloud security architecture, and a deep, practical hands-on experience securing core infrastructure and services within AWS or GCP
- Experience with Infrastructure-as-Code, specifically Terraform, for managing cloud environments
- An aptitude for building tools and automating workflows to solve complex problems
- A practical understanding of how to integrate security into the software development lifecycle
- Experience securing containerised environments (Kubernetes) and CI/CD pipelines (e.g., GitHub Actions, TeamCity)
- Strong scripting skills in Bash
- Proven experience creating custom tools or scripts specifically to solve security challenges
- You have an in-depth knowledge of security principles, technologies, best practices and threat detection and mitigation strategies
- A deep understanding of security principles, common attack vectors (OWASP Top 10, MITRE ATT&CK), and the threat landscape
- The ability to identify potential threats, attack vectors, and vulnerabilities in systems and applications
- Experience in automating security controls for compliance frameworks like SOC 2, ISO 27001, or PCI DSS.
- Expertise in Kubernetes, securing clusters and meshes (Cilium is preferable), networking best practices and RBAC implementation (CKA, CKS qualifications are a plus)
- Container security knowledge including container image provenance (e.g. Sigstore, Notary) with an in-depth knowledge of container runtimes
- Strong understanding of network protocols & practices, firewalls, intrusion detection/prevention systems and WAFs
- Understanding of integrating security into the software development lifecycle
- Experience in Cryptography management & enhancements
- Experience configuring and utilising cloud-native security logging, monitoring, and detection services
- Experience performing secure code reviews and security approvals including the use of static and dynamic application security testing (SAST/DAST) tools
- Relevant security certifications such as AWS Security Specialist or GCP Professional Cloud Security Engineer
- Initial interview with our Staff Security Engineer - ~45 minutes
- Take home technical task to be discussed in the next interview
- Technical interview with some of our Security Engineer team members - ~1.5 hours
- Final interview with our CTO / deputy CTO ~45 minutes
- 33 days holiday (including public holidays, which you can take when it works best for you)
- An extra day’s holiday for your birthday
- Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off
- 16 hours paid volunteering time a year
- Salary sacrifice, company enhanced pension scheme
- Life insurance at 4x your salary & group income protection
- Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton
- Generous family-friendly policies
- Incentives refer a friend scheme
- Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks
- Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing
We are sorry but this recruiter does not accept applications from abroad.