At a Glance
- Tasks: Design and maintain robust security for multi-cloud environments, focusing on GCP and Azure.
- Company: Join a leading tech firm dedicated to cloud security innovation.
- Benefits: Attractive salary, flexible working options, and opportunities for professional growth.
- Why this job: Be a key player in shaping cloud security and making a real impact.
- Qualifications: 5+ years in cloud security with expertise in GCP or Azure; programming skills a plus.
- Other info: Dynamic team environment with excellent career advancement opportunities.
The predicted salary is between 36000 - 60000 £ per year.
We are seeking a highly skilled Sr. Cloud Security Engineer to join our Security Operations and Engineering team. In this role, you will be a key player in designing, implementing, and maintaining a robust security posture across our multi‑cloud environment. While your primary expertise should lie in Google Cloud Platform (GCP) or Microsoft Azure, you will also leverage your experience in Amazon Web Services (AWS) to ensure consistent security standards across our entire infrastructure. You will be instrumental in automating security controls, conducting deep‑dive architectural reviews, and managing our Cloud Security Posture Management (CSPM) lifecycle.
What You'll Do
- Cloud Security Architecture & Design: Lead and participate in security reviews for new product features and infrastructure changes. Provide actionable recommendations to engineering teams to ensure "secure by design" principles.
- Posture Management (CSPM): Own the end‑to‑end CSPM process. This includes configuring tools, monitoring for misconfigurations, prioritising risks, and working with stakeholders to remediate security gaps across GCP, Azure, and AWS.
- Security Automation: Utilise basic programming and scripting skills (e.g., Python, Go, or Bash) to automate repetitive security tasks, incident response playbooks, and compliance checks.
- Infrastructure as Code (IaC) Security: Integrate security scanning into CI/CD pipelines (Terraform, Pulumi, or Bicep) to catch vulnerabilities before they reach production and also write IaC code for security related infrastructure.
- Identity & Access Management (IAM): Design and enforce least‑privilege access models across multi‑cloud environments, managing service accounts, roles, and identity federation.
- Incident Response Support: Act as a subject matter expert during cloud‑related security incidents, providing technical analysis and forensic support.
What We're Looking For
- Deep Cloud Expertise: 5+ years of experience in cloud security, with extensive, hands‑on experience in either GCP (Security Command Center, IAM, VPC Service Controls) or Azure (Microsoft Defender for Cloud, Azure Policy, Sentinel).
- Multi‑Cloud Proficiency: Strong working knowledge of AWS security services (GuardDuty, IAM, Security Hub, Config).
- CSPM Experience: Proven track record of managing Cloud Security Posture Management tools (e.g., Wiz, Orca, Prisma Cloud, or native cloud tools) to reduce the attack surface.
- Programming Skills: Ability to write scripts or small applications in Python, Go, or PowerShell to interact with Cloud APIs, automate workflows, and maintain security related IaC code.
- Security Reviews: Experience performing threat modelling and security architecture reviews for complex, distributed systems.
- Relevant certifications such as Google Professional Cloud Security Engineer, Microsoft Certified: Azure Security Engineer Associate (AZ‑500), or AWS Certified Security - Specialty would be great plus.
- Experience with container security (Kubernetes/GKE/AKS/EKS).
- Familiarity with compliance frameworks such as PCI DSS, SOC2, ISO 27001, or NIST.
- Excellent communication skills with the ability to translate complex security risks into business context for non‑technical stakeholders.
Sr. Cloud Security Engineer in London employer: Navan
Contact Detail:
Navan Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Sr. Cloud Security Engineer in London
✨Tip Number 1
Network like a pro! Attend industry meetups, webinars, or conferences related to cloud security. It's a great way to meet potential employers and get your name out there.
✨Tip Number 2
Show off your skills! Create a portfolio showcasing your cloud security projects, scripts, or any automation you've done. This gives you a tangible way to demonstrate your expertise beyond just words.
✨Tip Number 3
Don’t just apply; engage! When you find a job on our website that excites you, reach out to someone in the company on LinkedIn. A friendly message can make you stand out from the crowd.
✨Tip Number 4
Prepare for interviews by brushing up on common cloud security scenarios. Think about how you'd handle specific incidents or design secure architectures. Practice makes perfect!
We think you need these skills to ace Sr. Cloud Security Engineer in London
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights your cloud security experience, especially with GCP, Azure, and AWS. We want to see how your skills align with the role, so don’t be shy about showcasing relevant projects or achievements!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you’re passionate about cloud security and how your background makes you a perfect fit for our team. Keep it engaging and personal – we love to see your personality!
Show Off Your Technical Skills: Don’t forget to mention your programming skills and any experience with automation or security tools. We’re looking for someone who can hit the ground running, so highlight any relevant projects or scripts you’ve worked on.
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows you’re keen on joining our awesome team!
How to prepare for a job interview at Navan
✨Know Your Cloud Security Stuff
Make sure you brush up on your knowledge of GCP, Azure, and AWS security services. Be ready to discuss specific tools like Security Command Center or Microsoft Defender for Cloud, and how you've used them in past roles. This will show that you're not just familiar with the platforms but have hands-on experience.
✨Showcase Your Automation Skills
Prepare to talk about how you've automated security tasks in previous jobs. Whether it's using Python, Go, or Bash, be ready to share examples of scripts or applications you've written. This will demonstrate your ability to streamline processes and improve security posture.
✨Understand CSPM Inside Out
Since you'll be owning the CSPM process, make sure you can explain how you've managed tools like Wiz or Prisma Cloud. Discuss how you've monitored for misconfigurations and prioritised risks in the past. This will highlight your expertise in maintaining a secure cloud environment.
✨Communicate Like a Pro
You’ll need to translate complex security concepts into business language, so practice explaining your past projects to someone without a technical background. This will help you demonstrate your excellent communication skills, which are crucial for working with non-technical stakeholders.