At a Glance
- Tasks: Design and implement secure platform capabilities to enhance developer experience.
- Company: Join Motorway, the UK's fastest-growing used car marketplace with an award-winning platform.
- Benefits: Competitive salary, mentorship, and opportunities for professional growth.
- Other info: Be part of a dynamic team transforming the used car market.
- Why this job: Make a real impact on security practices in a rapidly evolving tech environment.
- Qualifications: Experience in platform engineering and knowledge of AWS cloud security best practices.
The predicted salary is between 36000 - 60000 £ per year.
About Motorway
Motorway is the UK's fastest-growing used car marketplace - our award winning, online-only platform connects private car sellers with over 7,500 verified dealers nationwide, who compete to offer the best price. Founded in 2017, our technology makes the process refreshingly easy, earning us an 'Excellent' Trustpilot rating with over 70,000 reviews. We're not just building a platform; we're changing how people sell cars. Backed by leading investors like Index Ventures and ICONIQ Growth, and following a successful $190 million funding round, we're on a mission to transform the used car market.
About the role
Motorway is rapidly growing its technology team and business, and we are looking for a Developer Experience Security Engineer to help enable a secure, scalable, and frictionless developer experience across Motorway. We have recently built and rolled out a new container platform on top of AWS Fargate, and are currently enhancing our observability, reliability, and developer-focused tooling. We will continue to build and evolve secure, standardised platform capabilities that reduce cognitive load and help teams ship faster with confidence. This role will act as a bridge between the Developer Experience team and Security Operations team, ensuring security strategy is embedded into platform abstractions, tooling, and defaults.
As a Security Developer Experience Security Engineer, you will ensure that security is built into how engineers build, deploy, and operate software, making the secure path the easiest path. The role will involve:
- Design, implement, and maintain secure-by-default platform capabilities (e.g. IAM patterns, network primitives, secrets management, runtime protections, encryption) that are easy for product teams to adopt.
- Build automated security checks, guardrails, and visibility that continuously assess risk and reduce the need for manual security audits.
- Collaborate with engineering to embed secure software development practices into CI/CD pipelines, templates, and shared tooling (Shift left and Secure by design principles).
- Reduce manual work (toil) for the technology and Security Operations Team using automation (e.g. scripting, workflows, tooling).
- Ensure platform-level security telemetry, logging, and monitoring are consistent, high-quality, and provided as a standard capability for all teams.
- Define and implement platform-wide security use cases (e.g. SIEM detections, alerts, and signals) that scale across teams without bespoke configuration.
- Work as part of a virtual SOC with the Security Operations Team to support in security incident response.
- Stay up-to-date with the latest security trends and best practices.
- Enable secure engineering practices through documentation, examples, platform defaults, and targeted training where appropriate.
- Help translate security policies and standards into practical, enforceable platform patterns and guardrails.
Requirements
We encourage you to apply, even if you might not meet all the requirements. You'll be directly reporting to an Engineering Manager, who will help mentor and guide you in your career.
- Proven experience as a Platform engineer, Developer Experience engineer, or similar role focused on enabling other engineers.
- Proven experience working with Containers and serverless with Infrastructure as code.
- Good knowledge of AWS cloud security best practices and tooling.
- Technical knowledge of best practice security for networks, systems, web applications, APIs and databases.
- Good understanding of secure software development practices.
- Familiarity with security tools and technologies, such as SIEM, IDS/IPS, WAF and vulnerability scanners.
- Knowledge of common adversarial Tactics, Techniques and Procedures (Mitre Att&ck TTPs).
- Knowledge of security standards and frameworks (e.g. ISO27001, NIST CSF) is beneficial.
- Relevant security certifications (e.g. GCLD, Security+, AWS/GCP Security Certifications) are a plus.
- Excellent problem-solving and analytical skills.
- Strong communication and collaboration abilities.
Senior Developer Experience Security Engineer in London employer: Motorway Online Ltd
Contact Detail:
Motorway Online Ltd Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Developer Experience Security Engineer in London
✨Tip Number 1
Network like a pro! Attend tech meetups, webinars, or conferences related to developer experience and security. It's a great way to meet people in the industry and get your name out there.
✨Tip Number 2
Show off your skills! Create a portfolio showcasing your projects, especially those involving AWS, containers, or security practices. This gives potential employers a taste of what you can do.
✨Tip Number 3
Don’t just apply anywhere; focus on companies that align with your values and interests, like Motorway. Use our website to apply directly, as it shows you're genuinely interested in being part of our mission.
✨Tip Number 4
Prepare for interviews by brushing up on common security scenarios and best practices. Be ready to discuss how you can help embed security into the developer experience at Motorway.
We think you need these skills to ace Senior Developer Experience Security Engineer in London
Some tips for your application 🫡
Tailor Your CV: Make sure your CV reflects the skills and experiences that align with the role of a Developer Experience Security Engineer. Highlight your experience with AWS, containers, and security best practices to show us you’re the right fit!
Craft a Compelling Cover Letter: Use your cover letter to tell us why you’re passionate about security and developer experience. Share specific examples of how you've implemented secure practices in past roles, and let your personality shine through!
Showcase Your Projects: If you’ve worked on relevant projects, whether personal or professional, don’t hesitate to include them. We love seeing practical applications of your skills, especially those that demonstrate your ability to enhance security in development.
Apply Through Our Website: We encourage you to apply directly through our website for the best chance of getting noticed. It’s the easiest way for us to keep track of your application and ensure it reaches the right people!
How to prepare for a job interview at Motorway Online Ltd
✨Know Your Stuff
Make sure you brush up on your knowledge of AWS cloud security best practices and tooling. Familiarise yourself with the latest trends in security, especially around containers and serverless architectures. Being able to discuss these topics confidently will show that you're not just a candidate, but a potential asset to their team.
✨Showcase Your Experience
Prepare specific examples from your past roles where you've successfully implemented secure-by-default platform capabilities or automated security checks. Use the STAR method (Situation, Task, Action, Result) to structure your answers, making it easy for the interviewers to see how your experience aligns with their needs.
✨Collaboration is Key
Since this role involves working closely with both the Developer Experience team and Security Operations team, be ready to discuss how you've collaborated with cross-functional teams in the past. Highlight any experiences where you’ve helped bridge gaps between different departments to achieve a common goal.
✨Ask Smart Questions
Prepare thoughtful questions about Motorway's current security practices and future plans. This shows your genuine interest in the role and helps you gauge if the company’s culture and goals align with your own. For example, ask about their approach to embedding security into CI/CD pipelines or how they handle incident response.