At a Glance
- Tasks: Design and implement security controls for AWS cloud and AI systems.
- Company: Join a leading tech firm focused on innovative cloud and AI security.
- Benefits: Competitive salary, flexible working hours, and opportunities for professional growth.
- Other info: Dynamic team environment with a focus on collaboration and continuous learning.
- Why this job: Make a real impact in securing cutting-edge AI technologies.
- Qualifications: Degree in Computer Science or equivalent experience; AWS certifications preferred.
The predicted salary is between 60000 - 80000 £ per year.
We are seeking an AWS Cloud & AI Security Engineer to design, implement, and operate security controls across AWS cloud platforms, AI/ML workloads, and Generative AI (GenAI) services. The role has a strong focus on threat detection and response, with particular emphasis on Amazon GuardDuty, Inspector and its integration into enterprise‑scale security operations. You will work closely with platform, MLOps, data science, and security teams to embed security‑by‑design, automate detection and response, and ensure AI systems are protected against evolving cloud and AI‑specific threats.
Accountabilities
- Secure AI/ML platforms using AWS SageMaker and Amazon Bedrock, covering notebooks, pipelines, endpoints, and inference workflows.
- Implement security controls for training and inference data isolation, protection of model artefacts/container images, and secure GenAI endpoints/RAG data sources.
- Monitor and respond to GuardDuty and CloudTrail findings related to IAM credential compromise, EC2/EKS threats, S3 access anomalies, and cryptomining.
- Integrate GuardDuty with Security Hub, CloudWatch, and SIEM platforms; tune findings and suppress false positives.
- Develop automated response playbooks using Lambda and Step Functions.
- Lead incident response activities, containment and root‑cause analysis.
- Contribute to threat modelling exercises for cloud, ML and GenAI architecture.
- Feed lessons learned back into detection rules and preventative controls.
- Support compliance with internal security baselines and external regulatory requirements.
- Define and enforce controls governing how context, prompts, tools, plugins and external data sources are exposed to AI models.
- Work with MLOps teams to ensure MCP implementations follow least‑privilege and data minimisation principles.
- Maintain awareness of emerging Gen AI attack vectors such as context/prompt injection and data leakage.
- Integrate AWS WAF with API Gateway to protect against common web and API‑specific attack patterns.
- Support alerting and investigation of suspicious API behaviour, including excessive token usage or unauthorised endpoint access.
Skills you’ll need to succeed
- Deep expertise in IAM, VPC security, encryption and network segmentation.
- Proven hands‑on experience with Amazon GuardDuty in production environments.
- Ability to tune and optimise GuardDuty to reduce noise and improve detection accuracy.
- Familiarity with SageMaker security constructs, Bedrock access controls and EKS runtime security.
- Experience working in automation‑driven, IaC‑based environments.
- Understanding of data protection, privacy and model lifecycle risks.
- Understanding of Model Context Protocols (MCPs) or equivalent patterns used in GenAI systems.
- Experience defining security controls for agent‑based or tool‑driven GenAI systems.
- Hands‑on experience securing Amazon API Gateway and familiarity with WAF protections.
- Experience integrating API Gateway with Lambda, SageMaker and Bedrock‑backed services.
- Experience with continuous vulnerability management using Amazon Inspector (EC2, ECR, Lambda).
- Ability to define standards for secure AI APIs, including GenAI, MCPs and agent‑based systems.
- Sound understanding of OAuth 2.0/OpenID Connect integrations and mTLS.
Leadership accountabilities
- Solution Focused Achiever – Deliver ambitious goals and cut through complexity to get to the right ethical solution.
- Change Agent – Identify, create and lead smooth business changes; adapt quickly to ambiguity.
- Team Coach – Coach and develop your people.
- Decision Making – Gather information, analyse scenarios and reach decisions.
Experience you’d be expected to have
- Degree in Computer Science/Engineering (or equivalent practical experience leading production cloud/ML platforms).
- AWS certifications strongly preferred – AWS Security Specialty.
- Strong understanding of API authentication, authorisation, throttling and abuse prevention.
- Familiarity with GenAI interaction standards, orchestration layers or AI gateways.
- Hands‑on delivery experience with Amazon Bedrock to run agentic apps safely and build observability around them.
Key decisions & Compliance
Compliance with all BT Group policies is mandatory for all employees. Policies are accessible via the Policy Portal and should be adhered to in‑line with Standards of Behaviour and “Being trusted: our code.”
Cyber & AI Security Engineer in London employer: 慨正橡扯
As a Cyber & AI Security Engineer at our London office, you will be part of a dynamic team that prioritises innovation and security in the rapidly evolving fields of cloud and AI technologies. We offer a collaborative work culture that encourages professional growth through continuous learning and development opportunities, alongside competitive benefits that support your well-being. Join us to make a meaningful impact while working in a vibrant city known for its tech advancements and diverse community.
StudySmarter Expert Advice🤫
We think this is how you could land Cyber & AI Security Engineer in London
✨Tip Number 1
Network, network, network! Get out there and connect with people in the industry. Attend meetups, webinars, or conferences related to Cyber and AI Security. You never know who might have a lead on your dream job!
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those involving AWS security tools like GuardDuty or SageMaker. This gives potential employers a taste of what you can do.
✨Tip Number 3
Don’t just apply blindly! Tailor your approach for each role. Research the company’s tech stack and mention how your experience aligns with their needs, especially around AI/ML security practices.
✨Tip Number 4
Use our website to apply! We’ve got loads of resources to help you through the application process. Plus, applying directly shows your interest and commitment to joining our team.
We think you need these skills to ace Cyber & AI Security Engineer in London
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Cyber & AI Security Engineer role. Highlight your experience with AWS, security controls, and any relevant projects that showcase your skills in threat detection and response.
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about AI security and how your background makes you a perfect fit for our team. Don’t forget to mention specific tools and technologies you’ve worked with.
Showcase Your Projects:If you've worked on any relevant projects, whether in a professional or personal capacity, make sure to include them. We love seeing practical examples of your skills, especially those involving AWS services and security measures.
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands and shows us you’re serious about joining the StudySmarter team!
How to prepare for a job interview at 慨正橡扯
✨Know Your AWS Security Tools
Familiarise yourself with Amazon GuardDuty, Inspector, and other AWS security tools mentioned in the job description. Be ready to discuss how you've used these tools in past roles, particularly in threat detection and response.
✨Showcase Your Automation Skills
Since the role involves automation-driven environments, prepare examples of how you've implemented automated security controls or incident response playbooks using AWS services like Lambda and Step Functions. Highlight any IaC experience you have.
✨Understand AI Security Challenges
Brush up on the specific security challenges related to AI/ML workloads and Generative AI. Be prepared to discuss how you would secure AI systems against evolving threats, including context/prompt injection and data leakage.
✨Demonstrate Team Collaboration
This role requires working closely with various teams. Prepare to share examples of how you've collaborated with platform, MLOps, or data science teams in the past to embed security-by-design principles into projects.