At a Glance
- Tasks: Design and implement next-gen cloud security architecture while enhancing internal SOC capabilities.
- Company: Dynamic startup focused on innovative security solutions and collaborative culture.
- Benefits: Equity ownership, hybrid work, generous holiday, paid volunteering days, and wellness budget.
- Other info: Opportunity for career growth with a supportive team and exciting challenges.
- Why this job: Join a fast-paced environment and make a real impact on cloud security.
- Qualifications: Strong background in DevSecOps, cloud security, and Python development.
The predicted salary is between 70000 - 90000 £ per year.
About the role
You won't be sitting in an ivory tower throwing policies over the fence. You will be embedded directly within our Platform team in a true DevSecOps capacity. Operating as a highly technical individual contributor, you will bridge the gap between product-led engineering and Corporate IT. You will play a hands-on role in challenging the security architecture of production and corporate IT infrastructure. In your first 6-12 months, you will design and implement our next-generation cloud security architecture across AWS and GCP, while helping to build and mature our internal SOC capabilities, including detection and response. You will take ownership of Microsoft Sentinel, enhancing our SIEM/SOAR capabilities, and strengthen identity and access management through improved and automated RBAC across AWS, Microsoft Entra, and internal systems. You will also drive a shift-left approach to security by embedding controls into GitLab CI/CD pipelines, including scanning, IaC reviews, and automated policy enforcement across the SDLC.
Our technology stack:
- Cloud & Compute: AWS, ECS Fargate, Aurora, Lambda, GCP
- Data Lake: S3, DMS, Glue
- Security & Identity: Microsoft Defender (XDR), Microsoft Sentinel (SIEM/SOAR), Defender for Cloud (CSPM), Microsoft 365, Entra, Intune
- Cloud Security Tooling: GuardDuty, Security Hub, Inspector, Security Command Center
- Code & IaC: Python, Java, GitLab, AWS CDK, Terraform/CDK-TF
- Observability & Incident Management: AMP, Incident.io
Who you are
You are a security professional by trade, but a hacker by design. You have a strong track record in DevSecOps and cloud security engineering, with hands-on experience elevating the security posture of other organisations. You are a strong Python developer. You know how to script automation, interact with APIs, and build security tooling from scratch. You possess a rock-solid understanding of network security fundamentals and how they apply to modern, distributed cloud architectures. You are comfortable owning both the build and run aspects of security - designing systems and responding to incidents. You thrive in the dynamic, ambiguous, and fast-paced environment of a high-growth startup. You know how to balance rigorous security with engineering velocity.
What you'll be doing
- Actively contribute infrastructure-as-Code (AWS CDK, Terraform) for security risks prior to deployment
- Implement best practice network security across AWS and GCP (IAM, VPCs, encryption, logging, monitoring)
- Embed zero-trust policies across the estate
- Actively challenge the security standards of production applications and infrastructure
- Embed security controls into CI/CD pipelines (SAST, dependency scanning, container security)
- Partner with engineering teams on secure architecture and deployment patterns
- Support secure SDLC practices and pre-deployment security reviews
What we offer
- Everyone owns a piece of the company - equity
- Hybrid with 3 days a week in the office
- 25 days' holiday a year, plus 8 bank holidays
- 2 paid volunteering days per year
- One month paid sabbatical after 4 years
- Employee loan
- Free gym membership
- Team wellness budget to be active together - set up a yoga class, a tennis lesson or go bouldering
Senior Security Engineer employer: Abound
Contact Detail:
Abound Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Security Engineer
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the industry. Attend meetups, webinars, or even local tech events. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those related to cloud security and DevSecOps. This gives potential employers a taste of what you can do and sets you apart from the crowd.
✨Tip Number 3
Prepare for interviews by practising common technical questions and scenarios. Think about how you would tackle security challenges in a real-world setting. We want to see your problem-solving skills in action!
✨Tip Number 4
Don't forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you're genuinely interested in joining our team and contributing to our mission.
We think you need these skills to ace Senior Security Engineer
Some tips for your application 🫡
Show Your Technical Skills: Make sure to highlight your hands-on experience with cloud security and DevSecOps in your application. We want to see how you've tackled security challenges in the past, so don’t hold back on those technical details!
Tailor Your Application: Take a moment to customise your CV and cover letter for this role. Use the job description as a guide and align your experiences with what we’re looking for. It shows us you’re genuinely interested and have done your homework!
Be Yourself: We love authenticity! Don’t be afraid to let your personality shine through in your application. Share your passion for security and any unique projects or experiences that set you apart from the crowd.
Apply Through Our Website: For the best chance of getting noticed, make sure to apply directly through our website. It’s the easiest way for us to keep track of your application and ensures it lands in the right hands!
How to prepare for a job interview at Abound
✨Know Your Tech Stack
Familiarise yourself with the specific technologies mentioned in the job description, like AWS, GCP, and Microsoft Sentinel. Be ready to discuss your hands-on experience with these tools and how you've used them to enhance security in previous roles.
✨Showcase Your DevSecOps Mindset
Prepare examples that demonstrate your ability to integrate security into the development process. Talk about how you've successfully embedded security controls into CI/CD pipelines and the impact it had on the overall security posture of your previous projects.
✨Be Ready for Technical Challenges
Expect technical questions or scenarios that test your problem-solving skills in real-time. Brush up on your Python scripting and be prepared to discuss how you would automate security processes or respond to incidents using your coding skills.
✨Emphasise Collaboration
Highlight your experience working closely with engineering teams. Discuss how you've partnered with them to implement secure architecture and deployment patterns, showcasing your ability to balance security needs with engineering velocity.