At a Glance
- Tasks: Design and maintain security automation for cloud environments, focusing on Microsoft Azure.
- Company: Join Atreides, a forward-thinking tech company prioritising security in the cloud.
- Benefits: Enjoy competitive salary, health insurance, flexible hours, and hybrid work options.
- Other info: Dynamic team environment with opportunities for professional growth and development.
- Why this job: Make a real impact by securing innovative cloud solutions and enhancing digital safety.
- Qualifications: 3+ years in security engineering with strong Azure experience and incident response skills.
The predicted salary is between 60000 - 80000 ÂŁ per year.
Location: Remote (25% Weekly on-site – Within England)
Security Clearance Requirement: Eligible to obtain and maintain an active UK security clearance
Position Overview: Atreides are seeking a motivated and proactive Cloud Security Engineer with a strong focus on Microsoft Azure security to join our growing team. This role is ideal for a security engineer or SecOps professional who understands the critical importance of maintaining a highly secure environment and is eager to work across cloud, endpoint, and infrastructure domains. While the primary focus will be Azure security engineering, experience with hardware and traditional infrastructure security will be considered a strong plus.
Responsibilities
- Security Engineering & Automation: Design, build, and maintain security automation and tooling to enforce controls and simplify compliance. Build and manage identity & access management controls across cloud platforms and applications. Write and review Infrastructure-as-Code (Bicep/Terraform) for secure cloud configuration. Implement preventative and detective controls in Azure; automate remediation of alerts. Secure CI/CD pipelines, integrating results from SAST/DAST/SCA tools and ensuring supply chain integrity. Engineer solutions for Kubernetes security, focusing on RBAC, network policies, and runtime protection.
- Detection, Monitoring & Incident Response: Perform triage, containment, eradication, and recovery activities as part of incident response, ensuring threats are effectively mitigated. Develop and optimise security detections (Sentinel, KQL, YARA). Manage log sources, ingestion pipelines, and monitoring infrastructure. Conduct threat hunting and analysis to identify emerging risks. Lead and contribute to incident investigations, including post-mortem analysis and remediation actions.
- Vulnerability & Risk Management: Identify, track, and remediate vulnerabilities across cloud, endpoint, and infrastructure. Implement controls from security assessments, audits, and architecture reviews. Support third-party risk assessments and vendor due diligence.
- Governance, Documentation & Projects: Maintain documentation of security standards, runbooks, and procedures. Participate in security-related projects and lead implementation of new security solutions.
Required Qualifications
- 3+ years in security engineering or security operations, ideally in cloud-first environments.
- Strong understanding of cloud security architecture with hands‑on experience securing cloud infrastructure and services.
- Hands‑on experience with the Azure security stack, including Microsoft Defender for Cloud (recommendations, alerts, Secure Score), Azure Policy, and related security tooling.
- Proficiency with SIEM platforms (Azure Sentinel preferred), developing detections and alerts, tuning rules, and investigating incidents.
- Proven incident response capability including triage, investigation, containment, eradication, and recovery.
- Practical experience integrating security into software and system development lifecycles.
- Experience with endpoint security solutions and MDM/EMM tools.
- Experience securing containerised environments (Kubernetes) and CI/CD pipelines.
- Proficiency in scripting and automation (PowerShell, Python, KQL, Bicep).
- Strong understanding of network security – protocols, firewalls, IDS/IPS, WAFs, and infrastructure hardening.
- Familiarity with incident response frameworks (NIST, SANS).
- Experience configuring and using cloud-native security logging, monitoring, and detection services.
- In-depth knowledge of security principles, attack vectors (OWASP Top 10, MITRE ATT&CK), and the threat landscape.
Desired Qualifications
- Azure Security Engineer AZ-500
- Security Operations Analyst SC-200
- Identity and Access Administrator SC-300
- GIAC Certified Forensic Analyst
- GIAC Certified Incident Handler
Compensation And Benefits
- Competitive salary
- Comprehensive health, dental, and vision insurance plans
- Flexible hybrid work environment
- Additional benefits like flexible hours, work travel opportunities, competitive vacation time and parental leave
Eligibility
You must have the right to work in the United Kingdom. Please note that we do not provide visa sponsorship.
Security Clearance
This position requires the successful candidate to be eligible to obtain and maintain an active UK security clearance. While meeting all of these criteria would be ideal, we understand that some candidates may meet most, but not all. If you're passionate, curious and ready to “work smart and get things done,” we’d love to hear from you.
Cloud Security Engineer (UK) employer: Atreides
Contact Detail:
Atreides Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Cloud Security Engineer (UK)
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with potential colleagues on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those related to Azure security. This gives you a chance to demonstrate your expertise beyond just a CV.
✨Tip Number 3
Prepare for interviews by brushing up on common questions and scenarios specific to cloud security. Practice articulating your thought process when tackling security challenges, as this will show your problem-solving skills.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our team at Atreides.
We think you need these skills to ace Cloud Security Engineer (UK)
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Cloud Security Engineer role. Highlight your experience with Azure security and any relevant projects you've worked on. We want to see how your skills match what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about cloud security and how your background makes you a great fit for our team. Keep it engaging and personal – we love to see your personality!
Showcase Your Skills: Don’t forget to showcase your technical skills, especially in scripting and automation. Mention any tools or frameworks you’ve used, like PowerShell or Terraform. We’re keen to see how you can contribute to our security engineering efforts!
Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. It’s super easy, and you’ll be able to keep track of your application status. Plus, we love seeing applications come directly from our site!
How to prepare for a job interview at Atreides
✨Know Your Azure Security Inside Out
Make sure you brush up on your knowledge of the Azure security stack, including Microsoft Defender for Cloud and Azure Policy. Be ready to discuss how you've implemented security measures in past roles, as this will show your hands-on experience.
✨Showcase Your Incident Response Skills
Prepare to share specific examples of how you've handled incident response in the past. Highlight your ability to triage, investigate, and recover from security incidents, as this is crucial for the role.
✨Demonstrate Your Automation Expertise
Since automation is key in this role, be ready to talk about your experience with scripting and automation tools like PowerShell or Python. Discuss any Infrastructure-as-Code projects you've worked on, especially using Bicep or Terraform.
✨Familiarise Yourself with Security Frameworks
Understand the incident response frameworks like NIST and SANS, and be prepared to discuss how you've applied these in your work. This will show that you have a solid grasp of security principles and best practices.