
Senior Cloud Security Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United Kingdom.
• Take ownership and enhance security guardrails, reference architectures, and technical standards across AWS, Azure, and Microsoft 365.
• Design and ensure security controls across areas such as identity, networking, compute, containers, storage, databases, encryption, secrets management, and backup and recovery.
• Review and critically assess cloud designs, threat models, Architecture Decision Records, and major changes.
• Lead the remediation efforts for identified control gaps.
• Provide support for AWS landing zones, account boundaries, access controls, permission models, and break-glass arrangements.
• Engineer and verify IAM, KMS, CloudTrail, Config, GuardDuty, Inspector, Security Hub, CloudWatch, and AWS Backup capabilities.
• Propel security enhancements across EC2, RDS, S3, ECS/Fargate, Lambda, ECR, and internet-facing services.
• Enhance security within Microsoft 365 E5, Azure, Defender, Intune, Azure Virtual Desktop, Purview, and SIEM capabilities.
• Integrate Secure-by-Design principles into projects through the Security and Technology Assurance Framework.
• Incorporate security into engineering workflows, CI/CD pipelines, and cloud deployment methodologies.
• Implement and refine SAST, SCA, secrets scanning, infrastructure-as-code, container, and application security testing.
• Collaborate with engineering teams on threat modeling, vulnerability remediation, dependency management, and release assurance.
• Ensure comprehensive, protected, and effectively monitored security telemetry.
• Lead technical assessments and risk-based remediation of complex vulnerabilities and misconfigurations.
• Respond to cloud security incidents, aiding in containment, investigation, recovery, and lessons learned.
• Collaborate with the 24/7 SOC, digital forensics, and incident response partners.
• Translate frameworks such as ISO/IEC 27001, Cyber Essentials Plus, DSPT, NCSC, and UK GDPR into technical controls and evidence.
• Maintain security engineering documentation for audits, control testing, risk treatment, and ongoing improvement.
• Provide security assurance for new systems, suppliers, and significant changes.
• Contribute to security standards, hardening guidelines, runbooks, architecture documentation, and control reporting.
• Offer technical leadership, mentorship, and constructive feedback across Cyber, Platform, Engineering, and Digital Workplace teams.
• Lead technical investigations and initiatives aimed at improving security.
• Communicate recommendations effectively to both technical and non-technical stakeholders.
• Independently manage priorities, escalate risks early, and maintain clear technical and assurance documentation.
• Report directly to the Director of Cyber Security and Resilience.
• Applicants must be residents of the UK.
• Extensive hands-on experience in cloud or platform security, including the design, implementation, and operation of production security controls.
• Strong background in AWS security engineering, encompassing multi-account governance, IAM, logging, threat detection, vulnerability management, encryption, network controls, and workload hardening.
• Proven experience in securing cloud-native applications, APIs, containers, and CI/CD pipelines.
• Deep understanding of DevSecOps and shared-responsibility models.
• Experience in building or reviewing infrastructure as code and security automation using Terraform, CloudFormation, Python, PowerShell, AWS CLI, or equivalent tools.
• Proven experience in security monitoring, investigation, and incident response using SIEM, cloud-native telemetry, and relevant query languages.
• Solid knowledge of network security, encryption, key and secrets management, resilience, vulnerability management, and secure configuration.
• Experience in translating security risk, policy, and compliance requirements into appropriate technical controls and auditable evidence.
• Experience in providing technical leadership, mentoring, or developing capabilities within security or engineering teams.
• Strong comprehension of security governance, risk management, and security controls in complex technology environments.
• Desirable: Practical experience with Microsoft Entra ID and Microsoft cloud security, including Conditional Access, MFA, PIM, RBAC, and Defender capabilities.
• Desirable: Experience in healthcare, regulated digital services, or environments handling sensitive or special category data.
• Desirable: Knowledge of ISO/IEC 27001, Cyber Essentials Plus, DSPT, NCSC CAF, NCSC Cloud Security Principles, NIST CSF, and UK GDPR.
• Desirable: Familiarity with Datadog, Cloudflare, Rapid7, GitHub security capabilities, CSPM/CNAPP platforms, or managed SOC services.
• Desirable: Experience in penetration testing, red teaming, threat modeling, MITRE ATT&CK mapping, or cloud forensic investigation.
• Desirable: Understanding of service management, change control, supplier assurance, business continuity, and disaster recovery.
• Degree or equivalent practical experience in cyber security, computer science, cloud engineering, or a related field.
• Relevant professional certifications are welcomed as supporting evidence but do not replace current, hands-on technical capabilities.
• Strong skills in communication, influencing, analytical thinking, and collaboration.
• Ability to work independently, manage competing priorities, and remain composed during incidents.
• Integrity, sound judgment, accountability, and a commitment to knowledge sharing and continuous improvement.
• £1000 working from home allowance.
• Health Cash Plan.
• Well Hub Subscription.
• Employee Assistance Programme.
• Annual Volunteering Day.
• Enhanced Sickness and Family Leave pay.
• Length of Service Bonus.
• Work from Home allowance.
• Pension options.
• Flexible remote full-time role.
• Reasonable adjustments during recruitment, including additional time, assistive technology, or alternative formats.
Viatris
Dragonfli Group
Motive
OCCU | Oregon Community Credit Union
Get handpicked remote jobs straight to your inbox weekly.