Cloud Security Engineer
Summary
Improve and automate security controls for AWS cloud environments, enforce identity/access policies via Terraform, and harden Kubernetes deployments.
Secure a cloud platform used across multiple markets, without turning security into a barrier to engineering delivery.
Cloud Security Engineer - London
London, United Kingdom · Permanent · Hybrid
What you'd actually work on
- Reviewing and improving security controls across AWS cloud environments
- Implementing security requirements through Terraform and automated policies
- Managing identity, access controls, permissions, and privileged access
- Improving container and Kubernetes security across production environments
- Integrating security checks into CI/CD pipelines
- Identifying vulnerabilities across infrastructure, applications, and third-party dependencies
- Working with engineering teams to prioritise and remediate security findings
- Improving secrets management and encryption practices
- Monitoring cloud activity and investigating suspicious behaviour
- Supporting incident response and documenting corrective actions
- Contributing to threat modelling for new services and architecture changes
- Maintaining evidence and technical controls required for audits and compliance reviews
Where it gets technically interesting
- Managing access across multiple cloud accounts, environments, and engineering teams
- Securing Kubernetes without preventing teams from operating their services
- Detecting configuration drift in infrastructure managed through code
- Separating useful security signals from high volumes of automated findings
- Applying consistent controls without assuming every service has the same risk profile
- Supporting regulatory requirements across a platform that continues to change
- Automating repetitive security controls while retaining clear traceability
What we're looking for
- 4+ years of experience in cloud security, DevSecOps, infrastructure security, or a related role
- Strong knowledge of AWS, Azure, or GCP security services
- Experience with identity and access management
- Practical knowledge of Terraform or another infrastructure-as-code tool
- Experience securing containers and Kubernetes environments
- Understanding of cloud networking, encryption, secrets management, and logging
- Experience integrating security controls into CI/CD pipelines
- Knowledge of vulnerability management and incident response
- Familiarity with standards such as ISO 27001, SOC 2, or PCI DSS
- Ability to explain risks and remediation options to engineering teams
- Professional English
The company
A regulated financial technology company operating across the United Kingdom and Europe. The engineering organisation manages a cloud-native platform supporting high transaction volumes and sensitive customer data.
Private health cover, pension contribution, equity plan, and flexible working.
Languages: Professional or native English.
A search run by The French Sourcer, recruitment built for technical teams.