Senior Cloud Security Engineer
Senior Cloud Security Engineer
Location: Remote/Hybrid (UK & Ireland)
Salary: c.£50,000 per annum (depending on experience)
Reports to: Director of Cyber Security
About the Role
We are seeking a highly skilled and hands-on Senior Cloud Security Engineer to lead cloud security governance, automation, and security engineering across a multi-cloud estate covering AWS, Azure, and Google Cloud Platform (GCP).
This is an exciting opportunity for someone who enjoys combining deep technical expertise with strategic security governance. You'll be responsible for designing secure cloud architectures, building automated security controls, and working closely with engineering teams, auditors, and enterprise customers to ensure cloud environments remain secure, compliant, and resilient.
If you're passionate about Infrastructure-as-Code, cloud security automation, and secure-by-design principles, we'd love to hear from you.
The Role
As a Senior Cloud Security Engineer, you will operate at the intersection of security engineering, governance, DevSecOps, and compliance. You will own security tooling, drive security improvements across multiple cloud platforms, and build the automation that makes security controls scalable and repeatable.
You'll play a key role in supporting regulatory compliance frameworks, customer assurance activities, vulnerability management programmes, and cloud security operations.
Key ResponsibilitiesCloud Security & Governance
- Lead cloud security governance across AWS, Azure, and GCP.
- Design and implement secure-by-design cloud architectures and security guardrails.
- Drive remediation of cloud security findings, vulnerabilities, and compliance gaps.
- Define and maintain tagging, IAM, privileged access, and governance standards.
Security Automation & Engineering
- Build and maintain security automation using:
- Terraform
- GitLab CI/CD
- AWS Lambda
- Azure Functions
- Logic Apps
- Python
- PowerShell
- Develop Infrastructure-as-Code security controls and governance frameworks.
- Automate security remediation and compliance validation processes.
Security Operations & Tooling
- Own and manage key security platforms including:
- Microsoft Defender for Cloud
- AWS Security Hub
- AWS GuardDuty
- AWS Inspector
- Qualys
- Snyk
- SonarQube
- DRATA
- GitLab
- Bitwarden
- Support threat detection, incident investigations, cloud security reviews, and vulnerability management activities.
Identity & Access Management
- Design and maintain least-privilege access models.
- Manage AWS IAM, IAM Identity Center, Azure Entra ID, RBAC, PIM, service accounts, and break-glass access processes.
- Support access life cycle management and privileged access governance.
Compliance & Customer Assurance
- Support compliance initiatives including:
- ISO 27001
- SOC 2
- Cyber Essentials Plus
- Secure by Design
- Assist with audits, evidence collection, risk remediation, and customer security assessments.
- Work directly with enterprise clients to support secure integrations, connectivity, key management, and compliance requirements.
What We're Looking ForEssential Experience
- Proven experience leading cloud security initiatives across AWS, Azure, and GCP.
- Strong hands-on expertise with Terraform and CI/CD pipelines for security automation.
- Experience operating cloud-native security tooling such as Defender for Cloud, Security Hub, GuardDuty, Inspector, Qualys, and Snyk.
- Strong understanding of Identity and Access Management, including AWS IAM, Azure Entra ID, RBAC, PIM, and privileged access controls.
- Experience developing automation using Python and/or PowerShell.
- Working knowledge of ISO 27001, SOC 2, Cyber Essentials Plus, or similar compliance frameworks.
- Experience working directly with customers, auditors, suppliers, and security assessors.
- Excellent communication skills with the ability to translate technical risks into business-focused recommendations.
Desirable
- Experience supporting regulated or financial services environments.
- Background in DevSecOps and Infrastructure-as-Code security practices.
- Experience implementing Secure by Design principles.
- Relevant cloud or cybersecurity certifications (AWS, Azure, GCP, ISC2, ISACA, or equivalent).
Core Technology Stack
AWS Microsoft Azure Google Cloud Platform (GCP) Terraform GitLab CI/CD AWS Organizations AWS IAM Identity Center Azure Entra ID Azure PIM Azure Policy Microsoft Defender for Cloud AWS Security Hub GuardDuty Inspector Qualys Snyk SonarQube DRATA Bitwarden AWS Lambda Azure Functions Logic Apps PowerShell Python DevSecOps IAM Vulnerability Management ISO 27001 SOC 2 Cyber Essentials Plus Secure by Design
Security Clearance Requirements
This role requires eligibility for Security Clearance. Applicants must be NATO or Irish nationals, meet the relevant residency and nationality requirements, and be willing to undergo security vetting as a condition of employment.