At a Glance
- Tasks: Design and enhance security for cloud environments, ensuring robust protection and compliance.
- Company: Join Avolution, a leading Enterprise Architecture Software company with a supportive culture.
- Benefits: Enjoy flexible working, 25 days leave, private medical insurance, and more perks.
- Why this job: Make a real impact in security while collaborating with global teams on innovative projects.
- Qualifications: 3+ years in Security Engineering with hands-on experience in Azure and AWS.
- Other info: Be part of a dynamic team with excellent career growth opportunities.
The predicted salary is between 48000 - 72000 £ per year.
ABOUT THE COMPANY
The best of all worlds: join Avolution, a highly regarded, worldwide, financially sound and growing 20-year-old Enterprise Architecture Software company. With offices in London, Sydney, Northern Virginia and Singapore, Avolution is established as an industry leader in its Gartner Magic Quadrant and other industry reports. Be part of a smart, friendly team, and use your skills and initiative to drive growth. Benefit from our culture which is described by employees as collegial, collaborative, flexible, and supportive.
Key Responsibilities
- Cloud & Infrastructure Security
- Design, manage, and enhance security configurations across Azure and AWS environments, including integration with Office 365.
- Implement and enforce best practices for identity and access management (IAM) in Azure AD (Entra ID) and AWS IAM.
- Monitor cloud workloads for vulnerabilities, misconfigurations, and threats using tools like Microsoft Defender.
- Collaborate with DevOps/Engineering teams to embed security controls into CI/CD pipelines and promote DevSecOps practices.
- Conduct security assessments, including assisting with penetration testing, risk evaluations, to identify and mitigate potential issues.
- Endpoint & Identity Security
- Enhance device posture, compliance, and management using Microsoft Intune and Defender for Endpoint.
- Develop and maintain robust conditional access, multi-factor authentication (MFA), and endpoint protection policies.
- Oversee secure identity lifecycle processes, enforcing least-privilege access and zero-trust principles.
- Security Operations
- Respond to security alerts, incidents, and vulnerabilities with timely investigations and remediation.
- Perform regular risk assessments, security reviews, internal audits.
- Manage and optimize security tools (e.g., SIEM, EDR, vulnerability scanners, Microsoft Defender suite).
- Lead incident response efforts and coordinate with cross-functional teams.
- Compliance & Governance
- Support ISO 27001:2022 recertification, continuous compliance activities, and internal audits.
- Prepare for and assist in achieving additional compliance certifications (e.g., SOC 2, GDPR) to support company growth.
- Develop, maintain, and improve security policies, procedures, and technical documentation.
- Track, report on, and remediate audit findings or compliance gaps.
- Collaboration & Culture
- Partner with global distributed teams across EMEA, AMER, and APAC regions.
- Educate internal teams on security best practices and foster a security-first culture through training and awareness programs.
Requirements
- 3+ years of experience in Security Engineering, Cloud Security, IT Operations, or similar roles.
- Hands-on expertise with Azure, AWS, Microsoft Intune, Defender suite, and Azure AD.
- Solid knowledge of cloud security standards (e.g., CIS Benchmarks, NIST, SOC 2).
- Experience with SIEM, EDR, vulnerability scanning, and security monitoring tools.
- Familiarity with ISO 27001 or other compliance frameworks.
- Understanding of network security concepts (e.g., VPN, firewalls, zero-trust architectures).
- Excellent communication skills and ability to thrive in a global, distributed environment.
Nice-to-Have
- Experience in a SaaS or fully cloud-native company.
- Automation and scripting skills (e.g., PowerShell, Python, Terraform).
- Knowledge of DevSecOps practices and tools.
- Relevant security certifications (e.g., Microsoft AZ-500, AWS Security Specialty, CCSP, CISSP, ISO 27001 Lead Implementer/Auditor).
- Experience with Microsoft 365 security configurations or data privacy regulations (e.g., GDPR).
Benefits
- Flexible working
- 25 days annual leave + bank holidays
- 1 day of birthday leave per year
- Private Medical Insurance which includes gym membership discounts and many other rewards
- Dental, Vision and Hearing insurance cover
- Pension Scheme
- Cycle to Work scheme
All applicants must have right to work in the United Kingdom. Avolution is an equal opportunities employer.
Principal Security Engineer in London employer: Avolution
Contact Detail:
Avolution Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Principal Security Engineer in London
✨Tip Number 1
Network like a pro! Reach out to current employees at Avolution on LinkedIn or other platforms. Ask them about their experiences and any tips they might have for landing a role there. Personal connections can make a huge difference!
✨Tip Number 2
Prepare for the interview by brushing up on your technical skills. Since this role involves cloud security and tools like Azure and AWS, make sure you can talk confidently about your hands-on experience and how you've tackled challenges in the past.
✨Tip Number 3
Show off your passion for security! During interviews, share examples of how you've implemented best practices or improved security measures in previous roles. This will demonstrate your commitment to fostering a security-first culture.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you're genuinely interested in being part of the Avolution team.
We think you need these skills to ace Principal Security Engineer in London
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Principal Security Engineer role. Highlight your experience with Azure, AWS, and security tools, and don’t forget to mention any relevant certifications. We want to see how your skills align with what we’re looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you’re passionate about security engineering and how you can contribute to our team at Avolution. Keep it concise but engaging – we love a good story!
Showcase Your Achievements: When detailing your experience, focus on your achievements rather than just responsibilities. Did you implement a security measure that reduced incidents? Share those successes! We appreciate candidates who can demonstrate their impact.
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows you’re keen on joining our awesome team!
How to prepare for a job interview at Avolution
✨Know Your Cloud Security Inside Out
Make sure you brush up on your knowledge of Azure and AWS security configurations. Be ready to discuss specific tools like Microsoft Defender and how you've used them in past roles. This will show that you're not just familiar with the concepts but have practical experience.
✨Showcase Your Collaboration Skills
Since Avolution values a collegial and collaborative culture, prepare examples of how you've worked with cross-functional teams. Highlight any experiences where you’ve embedded security practices into DevOps processes or educated teams on security best practices.
✨Be Ready for Technical Questions
Expect to dive deep into technical discussions about identity and access management, incident response, and compliance frameworks like ISO 27001. Practise articulating your thought process and problem-solving approach to demonstrate your expertise.
✨Demonstrate Your Passion for Security
Avolution is looking for someone who is proactive and passionate about security. Share your thoughts on current security trends, any relevant certifications you hold, and how you stay updated in the field. This will help convey your commitment to fostering a security-first culture.