At a Glance
- Tasks: Secure our multi-cloud fintech platform and enhance cloud security practices.
- Company: Join Finova, the UK's largest financial services tech provider, driving innovation in lending.
- Benefits: Enjoy hybrid working, private medical insurance, flexible holidays, and gym discounts.
- Other info: Dynamic team culture with opportunities for growth and learning.
- Why this job: Make a real impact in cloud security while working with cutting-edge technology.
- Qualifications: 4-6 years in cloud security with hands-on experience in AWS, Azure, and GCP.
The predicted salary is between 60000 - 80000 £ per year.
Finova is the UK’s largest financial services technology provider, supporting one in every five mortgages nationwide. Our agile, cloud-native solutions enable over 60 banks, building societies, specialist lenders, equity release providers and a network of 2,400+ brokers to stay ahead in a competitive market. Built on open architecture and backed by deep industry expertise, our platform is designed to scale. Each year, we process over £50 billion in loans, manage nearly £50 billion in savings, and support the digital servicing of more than 650,000 UK borrower accounts. Be part of a team that’s driving innovation, enabling growth and shaping the future of UK lending.
About the Role
We’re looking for a Cloud Security Engineer to own the security posture of our multi-cloud SaaS fintech platform across AWS, Azure, and GCP. This is a hands‑on, hybrid role. You’ll find yourself reviewing a Terraform pull request before stand‑up, tuning CSPM rules at midday, and tracing a misconfigured storage bucket across three accounts before the end of the day.
About you
Must-Have Experience
- Professional Experience: 4–6 years in cloud security, security engineering, or security-focused platform engineering, with hands‑on production experience in regulated environments.
- Multi-Cloud Mastery: Hands‑on experience securing at least two of AWS, Azure, and GCP in production, and working familiarity with all three.
- Infrastructure-as-Code: Deep experience with IaC security, primarily utilizing Terraform, plus at least one of Bicep, ARM, CloudFormation, or Pulumi, alongside their associated policy-as-code tooling.
- Cloud-Native Security Services: Practical knowledge of tools like Defender for Cloud, AWS Security Hub / GuardDuty / Macie / Inspector, and GCP Security Command Center / Chronicle—including their failure modes, not just their marketing.
- Container Security: Practical experience with Kubernetes security (admission control, pod security, network policy, service mesh) and container supply‑chain security (image signing, SBOMs, SLSA).
- Guardrails as Code: Experience defining and operating cloud guardrails as code (AWS SCPs, Azure Policy, GCP Org Policies), including safe rollout strategies that avoid production disruption.
- Network & Core Security: Solid understanding of cloud network security patterns (VPC/VNet design, private connectivity, egress filtering, DNS security) and secrets management (KMS, Key Vault, Secrets Manager, HashiCorp Vault).
- SecOps & Multi-Tenancy: Familiarity with cloud detection engineering (CloudTrail, Activity/Audit Logs) and an understanding of how cloud-layer choices (account structure, networking, KMS keys, storage layout) dictate real SaaS tenant isolation.
- Consultative Delivery: Experience working as a delivery engineer or consultant for a vendor or consultancy.
- Communication: Clear communicator capable of explaining a cloud risk to a developer, a CFO, and an auditor—adjusting technical depth and language appropriately without compromising facts.
Nice-to-Have Experience
- Experience working within fintech, payments, banking, or insurance environments.
- Hands‑on experience securing AI/ML cloud infrastructure (training clusters, GPU workloads, vector databases, model registries).
- Experience with CNAPP / CIEM platforms (Wiz, Prisma Cloud, Orca, Microsoft Defender CNAPP, etc.) and an understanding of their trade‑offs.
- Familiarity with eBPF-based runtime security tooling (Falco, Tetragon, or commercial equivalents).
- Experience with FedRAMP, ISO 27001, or other formal compliance regimes beyond SOC 2 / PCI-DSS.
- Relevant industry certifications: AWS Security Specialty, AZ-500, GCP Professional Cloud Security Engineer, CCSP, CKS, or CISSP.
- Strong scripting skills (Python, PowerShell, Go) for automation, custom tooling, and detection engineering.
- Background in offensive cloud security, known cloud attack patterns, red team experience, or contributions to cloud security research.
What will you be doing?
- Multi-Cloud Posture & CSPM
- Tooling & Baselines: Own and tune CSPM tooling across AWS, Azure, and GCP to ensure continuous drift detection and accurate, prioritized findings aligned with CIS Benchmarks.
- Remediation & Inventory: Partner with platform teams to fix underlying misconfiguration patterns and template defaults; maintain a real‑time, accurate cloud asset inventory.
- Infrastructure-as-Code (IaC) Security & Shift-Left
- Pipeline Integration: Embed security scanners (Checkov, tfsec, KICS) into IaC pipelines and build secure‑by‑default, reusable infrastructure modules.
- Guardrails & Design: Define production‑grade guardrails as code (SCPs, Azure/GCP Policies) and partner early with developers/SREs to architect secure cloud environments.
- Network, Workload Security & Data Protection
- Network & Edge: Design secure multi‑cloud architectures utilizing private connectivity, segmentation, and edge protection (WAF, DDoS).
- Containers & Serverless: Harden Kubernetes, container supply chains, and serverless workloads from admission to runtime using policy engines, scanning, and strict event/permission controls.
- Data & Secrets: Enforce cross‑cloud encryption, key management (KMS/BYOK), and hardened secrets infrastructure (Vault) with automated rotation and access logging.
- Standards: Establish cryptographic baselines and implement continuous discovery controls to detect public exposure and sensitive data leaks.
- Detection, Response & Cloud SecOps
- Detection Engineering: Build and tune detections using cloud audit logs and runtime telemetry integrated directly with the SIEM.
- Incident Response: Own the cloud IR lifecycle—from writing runbooks and running live tablestops to leading active containment, eviction, and root‑cause analysis.
- AI & ML Infrastructure Security
- Asset Hardening: Define the cloud security model for AI/ML pipelines, inventorying assets and hardening GPU/compute paths.
- Isolation & Standards: Design strict multi-tenant isolation for training data and embeddings while translating emerging AI frameworks (NIST AI RMF) into engineering standards.
- Compliance, Evidence & Enablement
- Continuous Compliance: Automate continuous evidence collection for SOC 2 Type II and PCI‑DSS to streamline audits and customer reviews.
- Engineering Enablement: Provide clear standards, office hours, and deep cloud expertise (e.g., IMDS, SSRF mitigation) to help engineering teams safely self‑serve.
What We Offer
- Hybrid working: Work in a hybrid way that suits you. Our model is primarily office-based, with flexibility to work remotely as needed.
- Private medical insurance: Comprehensive health cover, with the option to add your family to your plan.
- Life assurance & income protection: We provide life assurance and income protection to give you peace of mind for the future.
- Family friendly policies: Our enhanced family‑friendly policy goes beyond maternity and paternity leave.
- Work from anywhere: With approval, Finova employees can work abroad for up to 4 weeks each year.
- Flexible holiday package: Enjoy 25 days paid holiday allowance, plus all public holidays.
- Company pension scheme: With salary exchange, you save on tax and can build a secure future.
- Employee assistance programme: Access to a 24/7 confidential counselling helpline.
- Electric car scheme: Get a brand‑new electric vehicle with salary sacrifice as a benefit.
- Health cash plan: Provides reimbursement for everyday healthcare costs.
- Gym discounts: Achieve your fitness goals for less with GymFlex.
- Perks that matter: Fully stocked pantry of fresh fruit and snacks and weekly socials and events.
Equal Opportunity Statement
We value diversity and are committed to creating an inclusive environment for all employees. If you’re passionate about this role but don’t meet all the criteria, please reach out, we’d love to discuss how your skills and experiences align with our needs.
Cloud Security Engineer in Salford employer: Finova Technologies Private Limited
Finova is an exceptional employer, offering a dynamic work culture that prioritises innovation and employee well-being. With a hybrid working model, comprehensive health benefits, and a commitment to professional growth, employees are empowered to thrive both personally and professionally. Located in Manchester, the company fosters a collaborative environment where team members can contribute to shaping the future of UK lending while enjoying unique perks like flexible holiday options and an electric car scheme.
Contact Details:
Finova Technologies Private Limited Recruitment Team
StudySmarter Expert Advice🤫
We think this is how you could land Cloud Security Engineer in Salford
✨Tip Number 1
Network like a pro! Get on LinkedIn and connect with folks in the fintech and cloud security space. Join relevant groups, participate in discussions, and don’t be shy to reach out for informational chats. You never know who might have the inside scoop on job openings!
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your cloud security projects, especially those involving AWS, Azure, and GCP. This gives potential employers a tangible look at what you can do and sets you apart from the crowd.
✨Tip Number 3
Prepare for interviews by brushing up on common cloud security scenarios. Be ready to discuss how you’d handle specific challenges, like misconfigured storage buckets or CSPM tuning. Practice explaining complex concepts in simple terms—this will impress interviewers!
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our team at Finova. Let’s get you that Cloud Security Engineer role!
We think you need these skills to ace Cloud Security Engineer in Salford
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Cloud Security Engineer role. Highlight your experience with AWS, Azure, and GCP, and don’t forget to mention any relevant certifications. We want to see how your skills align with what we’re looking for!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you’re passionate about cloud security and how your background makes you a great fit for our team. Keep it concise but impactful – we love a good story!
Showcase Your Projects:If you’ve worked on any cool projects related to cloud security, make sure to mention them! Whether it’s securing a multi-cloud environment or implementing IaC security, we want to hear about your hands-on experience.
Apply Through Our Website:We encourage you to apply through our website for the best chance of getting noticed. It’s super easy, and you’ll be able to keep track of your application status. Plus, we love seeing applications come directly from our site!
How to prepare for a job interview at Finova Technologies Private Limited
✨Know Your Cloud Security Inside Out
Make sure you brush up on your knowledge of AWS, Azure, and GCP. Be ready to discuss specific security tools and practices you've used in each environment. This role demands hands-on experience, so be prepared to share examples of how you've secured cloud infrastructures.
✨Showcase Your IaC Skills
Since Infrastructure-as-Code is a big part of this role, come armed with examples of how you've implemented security in IaC pipelines. Talk about the tools you've used, like Terraform or Checkov, and how you've integrated security checks into your workflows.
✨Communicate Clearly and Confidently
You’ll need to explain complex security concepts to various stakeholders. Practice articulating your thoughts clearly, adjusting your technical depth based on your audience. This will show that you can bridge the gap between technical and non-technical team members.
✨Prepare for Scenario-Based Questions
Expect to face scenario-based questions that test your problem-solving skills in real-world situations. Think through potential misconfigurations or security incidents and how you would address them. This will demonstrate your practical knowledge and readiness for the role.