At a Glance
- Tasks: Secure our multi-cloud SaaS platform and tackle exciting challenges in cloud security.
- Company: Join Finova, the UK's largest financial services tech provider, driving innovation in lending.
- Benefits: Enjoy hybrid working, private medical insurance, flexible holidays, and family-friendly policies.
- Other info: Diverse and inclusive workplace with excellent career growth opportunities.
- Why this job: Make a real impact in fintech while working with cutting-edge cloud technologies.
- Qualifications: 4-6 years in cloud security with hands-on experience in AWS, Azure, or GCP.
The predicted salary is between 60000 - 80000 £ per year.
Finova is the UK’s largest financial services technology provider, supporting one in every five mortgages nationwide. Our agile, cloud-native solutions enable over 60 banks, building societies, specialist lenders, equity release providers and a network of 2,400+ brokers to stay ahead in a competitive market. Built on open architecture and backed by deep industry expertise, our platform is designed to scale. Each year, we process over £50 billion in loans, manage nearly £50 billion in savings, and support the digital servicing of more than 650,000 UK borrower accounts. Be part of a team that’s driving innovation, enabling growth and shaping the future of UK lending.
We’re looking for a Cloud Security Engineer to own the security posture of our multi-cloud SaaS fintech platform across AWS, Azure, and GCP. This is a hands-on, hybrid role. You’ll review Terraform pull requests, tune CSPM rules, and trace misconfigured storage buckets across multiple accounts to close gaps by day’s end.
Must-Have Experience
- Professional Experience: 4–6 years in cloud security, security engineering, or security-focused platform engineering, with hands-on production experience in regulated environments.
- Multi-Cloud Mastery: Hands-on experience securing at least two of AWS, Azure, and GCP in production, and working familiarity with all three.
- Infrastructure-as-Code: Deep experience with IaC security, primarily utilizing Terraform, plus at least one of Bicep, ARM, CloudFormation, or Pulumi, alongside their associated policy-as-code tooling.
- Cloud-Native Security Services: Practical knowledge of tools like Defender for Cloud, AWS Security Hub / GuardDuty / Macie / Inspector, and GCP Security Command Center / Chronicle.
- Container Security: Practical experience with Kubernetes security and container supply-chain security.
- Guardrails as Code: Experience defining and operating cloud guardrails as code.
- Network & Core Security: Solid understanding of cloud network security patterns and secrets management.
- SecOps & Multi-Tenancy: Familiarity with cloud detection engineering and an understanding of how cloud-layer choices dictate real SaaS tenant isolation.
- Consultative Delivery: Experience working as a delivery engineer or consultant for a vendor or consultancy.
- Communication: Clear communicator capable of explaining a cloud risk to various stakeholders.
Nice-to-Have Experience
- Experience working within fintech, payments, banking, or insurance environments.
- Hands-on experience securing AI/ML cloud infrastructure.
- Experience with CNAPP / CIEM platforms.
- Familiarity with eBPF-based runtime security tooling.
- Experience with FedRAMP, ISO 27001, or other formal compliance regimes.
- Relevant industry certifications.
- Strong scripting skills for automation, custom tooling, and detection engineering.
- Background in offensive cloud security.
What will you be doing?
- Infrastructure-as-Code (IaC) Security & Shift-Left
- Network, Workload Security & Data Protection
- Detection, Response & Cloud SecOps
- AI & ML Infrastructure Security
- Compliance, Evidence & Enablement
What We Offer
- Multi-Cloud Posture & CSPM
- Tooling & Baselines: Own and tune CSPM tooling across AWS, Azure, and GCP.
- Remediation & Inventory: Partner with platform teams to fix underlying misconfiguration patterns.
- Pipeline Integration: Embed security scanners into IaC pipelines.
- Guardrails & Design: Define production-grade guardrails as code.
- Network & Edge: Design secure multi-cloud architectures.
- Containers & Serverless: Harden Kubernetes, container supply chains, and serverless workloads.
- Data & Secrets: Enforce cross-cloud encryption and hardened secrets infrastructure.
- Standards: Establish cryptographic baselines and implement continuous discovery controls.
- Detection Engineering: Build and tune detections using cloud audit logs.
- Incident Response: Own the cloud IR lifecycle.
- Asset Hardening: Define the cloud security model for AI/ML pipelines.
- Isolation & Standards: Design strict multi-tenant isolation.
- Continuous Compliance: Automate continuous evidence collection.
- Engineering Enablement: Provide clear standards and deep cloud expertise.
Hybrid working: Work in a hybrid way that suits you.
Private medical insurance: Comprehensive health cover.
Life assurance & income protection: We provide life assurance and income protection.
Family friendly policies: Our enhanced family-friendly policy goes beyond maternity and paternity leave.
Work from anywhere: With approval, Finova employees can work abroad for up to 4 weeks each year.
Flexible holiday package: Enjoy 25 days paid holiday allowance, plus all public holidays.
We value diversity and are committed to creating an inclusive environment for all employees.
Cloud Security Engineer in Salford employer: finova
Finova is an exceptional employer, offering a dynamic work culture that fosters innovation and collaboration in the heart of Manchester. With a strong commitment to employee well-being, we provide comprehensive benefits including private medical insurance, flexible holiday packages, and family-friendly policies, all while supporting your professional growth in the rapidly evolving fintech landscape. Join us to be part of a team that values diversity and empowers you to shape the future of UK lending through cutting-edge cloud security solutions.
StudySmarter Expert Advice🤫
We think this is how you could land Cloud Security Engineer in Salford
✨Tip Number 1
Network like a pro! Reach out to folks in the industry on LinkedIn or at local meetups. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repo showcasing your cloud security projects. This gives potential employers a taste of what you can do and sets you apart from the crowd.
✨Tip Number 3
Prepare for interviews by practising common questions and scenarios related to cloud security. We recommend doing mock interviews with friends or using online platforms to boost your confidence.
✨Tip Number 4
Apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you’re genuinely interested in joining our team at Finova.
We think you need these skills to ace Cloud Security Engineer in Salford
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Cloud Security Engineer role. Highlight your experience with AWS, Azure, and GCP, and don’t forget to mention any hands-on projects you've worked on that relate to cloud security.
Showcase Your Skills:In your application, be sure to showcase your skills in Infrastructure-as-Code and any relevant tools like Terraform. We want to see how you’ve applied these skills in real-world scenarios, so give us some juicy examples!
Be Clear and Concise:When writing your cover letter or application, keep it clear and concise. Use straightforward language to explain your experience and how it aligns with our needs. Remember, we appreciate clarity just as much as technical expertise!
Apply Through Our Website:Don’t forget to apply through our website! It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it’s super easy to do!
How to prepare for a job interview at finova
✨Know Your Cloud Security Inside Out
Make sure you brush up on your knowledge of cloud security principles, especially around AWS, Azure, and GCP. Be ready to discuss specific tools like Defender for Cloud or AWS Security Hub, and how you've used them in past roles.
✨Showcase Your IaC Skills
Since this role involves Infrastructure-as-Code, be prepared to talk about your experience with Terraform and other IaC tools. Bring examples of how you've implemented security measures in your code and any challenges you faced.
✨Communicate Clearly
You’ll need to explain complex security concepts to various stakeholders. Practice articulating your thoughts clearly and concisely, adjusting your technical depth based on your audience—whether it’s a developer or a CFO.
✨Prepare for Scenario-Based Questions
Expect questions that assess your problem-solving skills in real-world scenarios. Think of examples where you’ve identified and remediated security vulnerabilities, and be ready to walk through your thought process step-by-step.