
Security Engineer – EU/UK
Posted Jul 28

Posted Jul 28
This is a fully remote position, open to applicants in United States.
• Integrate security best practices throughout the software development lifecycle (SDLC) to safeguard products, infrastructure, and customer data.
• Design, implement, and sustain security automation tools to tackle issues at scale (e.g., patch management, vulnerability management, compliance evidence collection).
• Embed security controls and guidelines into the developer platform to facilitate secure and efficient delivery.
• Define and advocate for “Paved Roads” - reusable, secure development standards and Terraform/Docker modules.
• Strengthen containerized workloads (ECS and EKS) - ensure clusters adhere to security best practices for isolation, networking, and access control; maintain secure, up-to-date base images; enforce image signing and provenance; implement admission control, least-privilege IAM roles, and runtime anomaly detection.
• Deploy and manage cloud security platforms (e.g., Wiz) and drive remediation workflows.
• Automate the collection of audit-ready evidence for frameworks such as PCI DSS, ISO 27001, SOC 2, and DORA.
• Support vulnerability management (triage, SLAs, RCA) and lead incident response and post-mortems.
• Conduct threat modeling, architecture reviews, and provide guidance on secure design and cryptography.
• Build and maintain security documentation, internal tools, and feedback mechanisms to enhance security culture.
• Serve as a security subject matter expert (SME) across application, cloud, and compliance domains.
• 5+ years of experience in a technical security position, ideally within a cloud-native or fintech/SaaS environment.
• Strong expertise with AWS services and security (IAM, KMS, CloudTrail, S3, GuardDuty, SCPs, etc.).
• Comprehensive understanding of DevSecOps practices and the integration of security into CI/CD workflows.
• Proficient in Terraform and other Infrastructure as Code (IaC) tools, capable of creating secure, reusable modules and enforcing guardrails.
• Skilled in Python, Bash, or TypeScript – able to script and develop automation tools.
• Experience in securing containers (Docker, ECS, EKS, or Kubernetes) and implementing hardened images.
• Expert-level understanding of OWASP Top 10, secure coding, and software supply chain risks.
• Experience managing and integrating cloud security platforms (e.g., Wiz, Orca, Lacework, Prisma Cloud).
• Familiarity with vulnerability management and remediation workflows at scale.
• Experience with application security practices, including code review, threat modeling, static and dynamic analysis (SAST, DAST), and attack surface analysis.
• Experience performing Application Penetration Testing or Vulnerability Research / Bug Bounty Hunting. (Ability to identify and rectify SQLi, XSS, CSRF, SSRF, authentication and authorization flaws, and other web-based security vulnerabilities)
• Experience with threat modeling or security reviews.
• Excellent communication skills and empathy, as security is a complex subject that must be conveyed to audiences with varying levels of prior exposure or knowledge.
• Attractive remuneration
• Your choice of preferred operating system, Windows or Mac
• Flat hierarchy and open communication in a relaxed, professional environment
• Opportunity to cultivate your talents in a dynamic team with ambitious goals
• Flexibility and the option to work remotely
• Company card with a monthly allowance for lunches, coffee, etc., with colleagues
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.