At a Glance
- Tasks: Lead platform security practices and mentor teams in a cloud-first environment.
- Company: Join a leading tech firm focused on innovation and security.
- Benefits: Enjoy competitive salary, flexible working, and opportunities for professional growth.
- Other info: Collaborate in a fast-paced environment with excellent career advancement potential.
- Why this job: Make a real impact by shaping secure technology solutions in a dynamic team.
- Qualifications: 5+ years in DevOps/Platform Engineering with strong security knowledge.
The predicted salary is between 60000 - 80000 £ per year.
The Principal Platform Security Engineer is a senior leader within the London Platform Engineering Chapter. The role sets direction and leads by example in maturing platform security practices, guiding Innovation squads and Engineering Chapters toward cloud-first, secure by design outcomes.
Key Responsibilities
- Coach and mentor chapter members, supporting the Head of Platform Engineering with overall chapter management, especially regarding partner resources.
- Design, implement, and automate security controls and security testing within the SDLC.
- Lead application security practices to ensure secure design and build, coordinating between engineering and security teams.
- Apply Security as Code principles by providing training, creating reusable patterns, and establishing best practices for teams.
- Support the investigation and future implementation of agentic workflows and agents, ensuring solutions are secure by design and comply with Hiscox AI governance.
- Respond swiftly to new and emerging security threats and vulnerabilities, investigate suspected attacks, and manage security incidents, including post-incident reviews to identify root causes and implement preventative solutions.
- Produce clear, actionable security reporting for senior leadership.
- Act as the primary point of contact for security-related inquiries across London Market technology and change initiatives, coordinating with Group, other Business Units, and Cyber teams.
- Influence key architectural decisions early, balancing business requirements, budgets, security, and resilience.
- Partner with squads to move solutions from proof of concept (PoC) to a production-ready platform.
- Build and maintain secure Azure and GCP infrastructure across all environments using Azure DevOps Pipelines and Terraform.
- Oversee and coach squads on intra-day deployment mechanisms, advocating for cloud-informed improvements that enhance security, reliability, and delivery speed.
- Build and maintain monitoring and alerting at all levels (infrastructure, application, and data), ensuring actionable signals and secure operational practices.
Person Specification
- 5+ years' DevOps/Platform Engineering experience delivering solutions in Azure and/or GCP.
- Full stack application and infrastructure solution design with robust security controls, high availability, and operational resilience.
- Working knowledge of vulnerability and compliance management (scanning to remediation), patch management, endpoint protection/anti-malware, and access control management (e.g., IAM/PAM).
- Experience with threat modelling and risk assessment applied to cloud architectures and CI/CD pipelines to guide secure design and prioritise risk treatment.
- Experience with AppSec tooling, including CI/CD integration, noise reduction tuning, and triaging results with engineers.
- Strong leadership skills, educating teams and delegating responsibilities across chapters and Group IT teams.
- Proficiency in Terraform and platform solutions, with experience integrating GCP and Azure.
- Knowledge of cloud native, microservices, and containerised systems.
- A strong desire for continuous improvement and an Agile way of working.
- Ideal: knowledge of the insurance and London Market ecosystem; Lloyd's market experience.
- Hands-on software delivery experience, including platform engineering, build, release, and deployment engineering using modern DevOps practices.
- Experience delivering and operating technology in regulated environments, understanding controls, audit expectations, and evidence-based compliance.
- Clear communication of processes, patterns, and tooling to ensure quality, stability, performance, scalability, secure deployment, maintainability, and documentation.
- Broad awareness of major cloud providers and services, curious about evaluating and adopting capabilities that improve security, reliability, and cost efficiency.
- Proactive and improvement focused, challenging the status quo and driving automation and simplification where it adds value.
- Strong delivery focus, capable of prioritising effectively and delivering outcomes in a fast-paced environment with shifting demands.
- Ability to operate effectively in a small, high impact team while collaborating across a wider product/engineering organisation.
- Excellent communication and stakeholder management skills, able to influence at all levels and present complex topics clearly.
- Comfortable working in ambiguity and adapting quickly as priorities, technology, and threats evolve.
- Up to date knowledge of security practices, processes, and tooling, with judgement to apply emerging approaches pragmatically.
Principal Platform Security Engineer employer: Hiscox Underwriting Group Services Ltd (HUGS)
As a Principal Platform Security Engineer at our London office, you will join a dynamic and innovative team dedicated to enhancing platform security practices in a collaborative environment. We prioritise employee growth through mentorship and continuous learning opportunities, while offering a competitive benefits package that includes flexible working arrangements and a focus on work-life balance. Our culture fosters creativity and agility, empowering you to influence key architectural decisions and drive meaningful change in a fast-paced, technology-driven landscape.
Contact Details:
Hiscox Underwriting Group Services Ltd (HUGS) Recruitment Team