At a Glance
- Tasks: Design and implement secure platform capabilities to enhance developer experience.
- Company: Join Motorway, the UK's fastest-growing used car marketplace with an award-winning platform.
- Benefits: Competitive salary, mentorship, and opportunities for professional growth.
- Other info: Be part of a dynamic team transforming the used car market.
- Why this job: Make a real impact on security practices in a rapidly evolving tech environment.
- Qualifications: Experience in platform engineering, AWS security, and secure software development.
The predicted salary is between 36000 - 60000 £ per year.
About Motorway
Motorway is the UK's fastest-growing used car marketplace - our award winning, online-only platform connects private car sellers with over 7,500 verified dealers nationwide, who compete to offer the best price. Founded in 2017, our technology makes the process refreshingly easy, earning us an 'Excellent' Trustpilot rating with over 70,000 reviews. We're not just building a platform; we're changing how people sell cars. Backed by leading investors like Index Ventures and ICONIQ Growth, and following a successful $190 million funding round, we're on a mission to transform the used car market.
About the role
Motorway is rapidly growing its technology team and business, and we are looking for a Developer Experience Security Engineer to help enable a secure, scalable, and frictionless developer experience across Motorway. We have recently built and rolled out a new container platform on top of AWS Fargate, and are currently enhancing our observability, reliability, and developer-focused tooling. We will continue to build and evolve secure, standardised platform capabilities that reduce cognitive load and help teams ship faster with confidence. This role will act as a bridge between the Developer Experience team and Security Operations team, ensuring security strategy is embedded into platform abstractions, tooling, and defaults.
As a Security Developer Experience Security Engineer, you will ensure that security is built into how engineers build, deploy, and operate software, making the secure path the easiest path. The role will involve:
- Design, implement, and maintain secure-by-default platform capabilities (e.g. IAM patterns, network primitives, secrets management, runtime protections, encryption) that are easy for product teams to adopt.
- Build automated security checks, guardrails, and visibility that continuously assess risk and reduce the need for manual security audits.
- Collaborate with engineering to embed secure software development practices into CI/CD pipelines, templates, and shared tooling (Shift left and Secure by design principles).
- Reduce manual work (toil) for the technology and Security Operations Team using automation (e.g. scripting, workflows, tooling).
- Ensure platform-level security telemetry, logging, and monitoring are consistent, high-quality, and provided as a standard capability for all teams.
- Define and implement platform-wide security use cases (e.g. SIEM detections, alerts, and signals) that scale across teams without bespoke configuration.
- Work as part of a virtual SOC with the Security Operations Team to support in security incident response.
- Stay up-to-date with the latest security trends and best practices.
- Enable secure engineering practices through documentation, examples, platform defaults, and targeted training where appropriate.
- Help translate security policies and standards into practical, enforceable platform patterns and guardrails.
Requirements
We encourage you to apply, even if you might not meet all the requirements. You'll be directly reporting to an Engineering Manager, who will help mentor and guide you in your career.
- Proven experience as a Platform engineer, Developer Experience engineer, or similar role focused on enabling other engineers.
- Proven experience working with Containers and serverless with Infrastructure as code.
- Good knowledge of AWS cloud security best practices and tooling.
- Technical knowledge of best practice security for networks, systems, web applications, APIs and databases.
- Good understanding of secure software development practices.
- Familiarity with security tools and technologies, such as SIEM, IDS/IPS, WAF and vulnerability scanners.
- Knowledge of common adversarial Tactics, Techniques and Procedures (Mitre Att&ck TTPs).
- Knowledge of security standards and frameworks (e.g. ISO27001, NIST CSF) is beneficial.
- Relevant security certifications (e.g. GCLD, Security+, AWS/GCP Security Certifications) are a plus.
- Excellent problem-solving and analytical skills.
- Strong communication and collaboration abilities.
Senior Developer Experience Security Engineer employer: Motorway Online Ltd
Contact Detail:
Motorway Online Ltd Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Developer Experience Security Engineer
✨Tip Number 1
Network, network, network! Get out there and connect with folks in the industry. Attend meetups, webinars, or even online forums. The more people you know, the better your chances of landing that dream job.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects and contributions. This is your chance to demonstrate what you can do, especially in areas like secure software development and cloud security.
✨Tip Number 3
Prepare for interviews by brushing up on common technical questions and scenarios related to developer experience and security. Practice explaining your thought process clearly, as communication is key in collaborative environments.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive about their job search!
We think you need these skills to ace Senior Developer Experience Security Engineer
Some tips for your application 🫡
Tailor Your CV: Make sure your CV reflects the skills and experiences that align with the Developer Experience Security Engineer role. Highlight your experience with AWS, containers, and security best practices to show us you’re the right fit!
Craft a Compelling Cover Letter: Use your cover letter to tell us why you’re passionate about security and developer experience. Share specific examples of how you've implemented secure practices in past roles to grab our attention!
Showcase Your Projects: If you’ve worked on relevant projects, don’t hesitate to include them! Whether it’s a personal project or something from your previous job, we love seeing practical applications of your skills.
Apply Through Our Website: We encourage you to apply directly through our website for a smoother application process. It helps us keep track of your application and ensures you don’t miss any important updates!
How to prepare for a job interview at Motorway Online Ltd
✨Know Your Stuff
Make sure you brush up on your knowledge of AWS cloud security best practices and tooling. Familiarise yourself with the latest trends in security, especially around containers and serverless architectures. Being able to discuss these topics confidently will show that you're not just a candidate, but a potential asset to their team.
✨Showcase Your Experience
Prepare specific examples from your past roles where you've successfully implemented secure-by-default platform capabilities or automated security checks. Use the STAR method (Situation, Task, Action, Result) to structure your answers, making it easy for the interviewers to see how your experience aligns with their needs.
✨Collaboration is Key
Since this role involves working closely with both the Developer Experience team and Security Operations team, be ready to discuss how you've collaborated with cross-functional teams in the past. Highlight any experiences where you’ve helped bridge gaps between different departments to achieve a common goal.
✨Ask Smart Questions
Prepare thoughtful questions about Motorway's current security practices and future plans. This shows your genuine interest in the role and helps you gauge if the company’s culture and goals align with your own. For example, ask about their approach to embedding security into CI/CD pipelines or how they handle incident response.