Cloud Security Engineer

Cloud Security Engineer

Full-Time 60000 - 75000 £ / year (est.) Home office (partial)
Blue Light Card

At a Glance

  • Tasks: Secure and evolve our cloud estate while tackling complex security challenges.
  • Company: Join Blue Light Card, a mission-driven company making heroes happy.
  • Benefits: Enjoy hybrid working, 25 days leave, medical insurance, and exclusive discounts.
  • Other info: Collaborative culture with great career growth and fun social events.
  • Why this job: Make a real impact in cloud security and work with cutting-edge technologies.
  • Qualifications: Experience as a Cloud Security Engineer with AWS and Cloudflare expertise.

The predicted salary is between 60000 - 75000 £ per year.

We have an exciting opportunity for a Cloud Security Engineer to join our Technology team and play a key role in how we secure and evolve our cloud estate. You'll report directly to the Director of Technology & Security. This is a hands-on role where you'll take the technical lead on securing our cloud and edge estate. You'll work closely with our platform and engineering squads, helping us continuously improve how we protect the infrastructure that sits behind our product. If you love solving complex security challenges and want your work to matter, this is a great time to join.

What You'll Do

  • Review and triage security findings, prioritise remediation, and work with engineering squads and third parties to continuously improve our cloud security position.
  • Own our Cloud Security Posture Management tooling day to day, tuning policies, driving remediation, and keeping our security position visible across the business.
  • Keep our AWS estate secure across IAM, network controls, encryption, logging, and workload protection, partnering with platform engineering on guardrails, Service Control Policies, and secure landing zones.
  • Manage our Cloudflare edge as a security control, tuning WAF rules, overseeing rate limiting and bot management, and responding quickly as threats evolve.
  • Lead detection and response for cloud and edge incidents, develop detections in our SIEM, and produce post-incident reviews that help us learn and improve.
  • Develop and maintain our technical security standards across cloud, WAF, IAM, and logging, keeping us aligned with best practice and our regulatory obligations.
  • Support compliance across UK GDPR, PCI DSS, ISO 27001, NIST CSF, and Cyber Essentials Plus, contributing to risk assessments and implementing technical mitigations.
  • Champion security best practice across our engineering teams, helping squads build security in from the start.

What You'll Bring

  • Extensive experience as a Cloud Security Engineer, with the ability to operate independently and influence how security is done across a technology organisation.
  • Hands-on experience with AWS, Cloudflare, Tenable, and SIEM, with the depth to use these tools confidently day to day.
  • Proven experience working to frameworks including NIST CSF, ISO 27001, and Cyber Essentials Plus, with a practical understanding of what good compliance really looks like.
  • Familiarity with Cloud Security Maturity Frameworks and benchmarks such as CIS, and the ability to apply them to raise security standards in practice.
  • Experience leading or contributing to incident response, particularly for cloud and edge incidents such as credential stuffing, IAM compromise, and exposed assets.
  • Strong working knowledge of Cloudflare Enterprise, including WAF rule authoring, Bot Management, and log pipelines into SIEM.
  • A clear communication style and the ability to translate technical risk into plain language for non-technical stakeholders.
  • A collaborative approach, a strong track record of delivering results, and a genuine interest in how AI and automation can improve security operations.

Our Culture

Our mission is simple - make heroes happy. Our members are the real-life heroes who keep us all safe, cared for, and thriving. It's what gets us up in the morning and pushes us to go further, think bigger, and create something that truly matters. By focusing on their happiness, we create amazing experiences, deliver unrivalled discounts, innovative products, and world-class service. We don't just follow the usual path - we look for smarter, bolder ways to deliver real impact. We take ownership, move fast, and work shoulder to shoulder to build something special. We promote hybrid working, and value in-person collaboration so encourage time in our offices, where you can make the most of our fully stocked snack drawers - either the HQ in Leicestershire, or London, Holborn office. The frequency and office location will vary depending on the role and team. We aim to be flexible, but we aren't able to offer fully remote working. Blue Light Card is an equal opportunities employer. We believe that employing a diverse workforce is key to our success. We make recruiting decisions based on your experience and skills. In the event of a high number of applications, we'll prioritise candidates who meet both the essential and desirable criteria for the role.

What We Offer

  • Hybrid working and flexible hours.
  • EV charging and free parking onsite at HQ.
  • 25 days annual leave plus an additional day off for your birthday, and a buy and sell holiday scheme of up to 5 days.
  • A company bonus scheme.
  • Your own Blue Light Card and exclusive access to thousands of discounts.
  • Generous funded BUPA medical insurance covering pre-existing conditions.
  • Auto-enrolment pension scheme via salary sacrifice, with employer NI savings reinvested into pensions.
  • Enhanced parental leave and absence leave.
  • Healthcare cashback plan.
  • Employee assistance programme (including mental health support) and mental health first aiders.
  • Great social events e.g., festive party, summer party, team socials, sports matches.
  • Regular company-wide recognition events e.g. monthly Light's Up and annual Shine awards.
  • Relaxed dress code and modern office space (games area, chill-out areas, book club, free drinks/snacks).
  • Onsite gym at HQ (including access to free HIIT & stretch classes).
  • Strong learning and development culture and personal growth fund.

Cloud Security Engineer employer: Blue Light Card

At Blue Light Card, we pride ourselves on being an exceptional employer that values the happiness and well-being of our team members. With a strong focus on hybrid working, generous benefits including 25 days annual leave plus your birthday off, and a vibrant work culture that encourages collaboration and personal growth, we create an environment where you can thrive both professionally and personally. Join us in making a real impact while enjoying perks like onsite gym access, mental health support, and exclusive discounts, all within our modern offices in Leicestershire or London.

Blue Light Card

Contact Details:

Blue Light Card Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Cloud Security Engineer

Tip Number 1

Network like a pro! Reach out to current employees on LinkedIn or attend industry events. A friendly chat can sometimes lead to job opportunities that aren't even advertised.

Tip Number 2

Show off your skills in real-time! Consider setting up a GitHub repository or a personal project that showcases your cloud security expertise. This gives you something tangible to discuss during interviews.

Tip Number 3

Prepare for the technical interview by brushing up on your AWS and Cloudflare knowledge. Be ready to tackle scenario-based questions that test your problem-solving skills in cloud security.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our team.

We think you need these skills to ace Cloud Security Engineer

Cloud Security Engineering
AWS
Cloudflare
Tenable
SIEM
NIST CSF
ISO 27001

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Cloud Security Engineer role. Highlight your hands-on experience with AWS, Cloudflare, and SIEM, and don’t forget to mention any frameworks you’ve worked with like NIST CSF or ISO 27001.

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you’re passionate about cloud security and how your skills can help us improve our security posture. Keep it engaging and relevant to the job description.

Showcase Your Problem-Solving Skills:In your application, give examples of complex security challenges you've tackled in the past. We love seeing how you approach problems and what solutions you’ve implemented, especially in cloud environments.

Apply Through Our Website:We encourage you to apply through our website for the best chance of getting noticed. It’s super easy, and you’ll be able to see all the details about the role and our amazing culture!

How to prepare for a job interview at Blue Light Card

Know Your Cloud Security Tools

Make sure you’re well-versed in the tools mentioned in the job description, like AWS, Cloudflare, and SIEM. Be ready to discuss your hands-on experience with these platforms and how you've used them to tackle security challenges in the past.

Understand Compliance Frameworks

Familiarise yourself with compliance frameworks such as NIST CSF, ISO 27001, and Cyber Essentials Plus. Prepare to explain how you've applied these standards in previous roles and how they relate to the responsibilities of the position you're applying for.

Showcase Your Incident Response Skills

Be prepared to share specific examples of incidents you've managed, particularly in cloud and edge environments. Highlight your approach to detection, response, and post-incident reviews, as this will demonstrate your ability to lead in critical situations.

Communicate Clearly and Collaboratively

Practice explaining complex technical concepts in simple terms. This is crucial for translating technical risks to non-technical stakeholders. Also, emphasise your collaborative approach and how you’ve worked with engineering teams to embed security best practices.