At a Glance
- Tasks: Secure cloud environments and applications while collaborating with engineering teams.
- Company: Join a forward-thinking tech company focused on clean energy.
- Benefits: Competitive salary, hybrid work model, and opportunities for professional growth.
- Other info: Diverse and inclusive workplace that values every voice.
- Why this job: Make a real impact in cloud security and application development.
- Qualifications: Experience in cloud security and application security practices required.
The predicted salary is between 65000 - 65000 £ per year.
- Department: Technology
- Reports to: Global Head of Cyber Security
- About Segen
- Own and continuously improve Segen’s security posture across our Cloud environment, including configuration hardening, policy enforcement, and security architecture.
- Implement and manage cloud-native security controls using Microsoft Defender for Cloud, Azure Security Centre, and Azure Policy.
- Design and enforce Identity and Access Management (IAM) controls, including Privileged Identity Management (PIM), Conditional Access, and Entra ID (Azure AD) governance.
- Manage cloud network security including virtual network segmentation, NSGs, Private Endpoints, and Azure Firewall.
- Lead cloud security reviews for new infrastructure deployments, ensuring secure architecture patterns are followed (Zero Trust, least privilege, defence-in-depth).
- Monitor cloud environments for misconfigurations and security drift using CSPM tooling, remediating findings in collaboration with Dev Ops and infrastructure teams.
- Application & Development Security (App Sec)
- Champion and embed secure software development lifecycle (SSDLC) practices across engineering teams.
- Integrate and manage application security tooling within CI/CD pipelines, including SAST, DAST, SCA, and secrets scanning (e. g.
Checkmarx, Snyk, Git Hub Advanced Security, OWASP ZAP).
- Conduct and coordinate application security assessments, threat modelling sessions, and secure code reviews.
- Act as the primary security liaison for development and Dev Ops teams, providing hands-on guidance on secure coding standards (OWASP Top 10, SANS CWE).
- Manage the responsible disclosure and triage process for application vulnerabilities identified through internal testing or third-party penetration tests.
- Develop and maintain application security standards, policies, and developer-facing guidance documentation.
- Dev Sec Ops & Security Automation
- Build and maintain security automation pipelines to enforce policy-as-code, infrastructure-as-code (Ia C) scanning, and automated compliance checks.
- Implement and manage secrets management solutions (e. g. Azure Key Vault) and ensure secure handling of credentials and API keys across development environments.
- Develop scripted tooling and automation using Power Shell, Python, or similar to improve detection, response, and security operational efficiency.
- Collaborate with Dev Ops on container security, including image scanning, Kubernetes security posture, and runtime protection.
- Vulnerability Management & Threat Intelligence
- Own the application and cloud vulnerability management programme, including tooling, triage, SLA tracking, and remediation coordination.
- Integrate threat intelligence feeds to contextualise cloud and application risk, informing prioritisation and defensive improvements.
- Manage and track findings from penetration tests through to resolution.
- Compliance & Risk
- Support cloud and application compliance requirements including ISO 27001, Cyber Essentials/Plus, UK GDPR, and PCI DSS where applicable.
- Contribute to security risk assessments for new cloud services, third‑party integrations, and application deployments.
- Maintain security documentation, evidence packs, and control mappings for internal and external audit purposes.
- Collaboration & Stakeholder Engagement
- Work closely with software engineers, architects, and Dev Ops teams as a trusted security partner – not a gatekeeper.
- Deliver security awareness and training for development teams, covering secure coding practices and common vulnerabilities.
- Produce clear risk-based reporting on cloud and application security posture for the Head of Cyber Security and senior stakeholders.
- Technical Competencies
- Required Skills
- Hands‑on experience securing Microsoft Azure environments, including Defender for Cloud, Azure Policy, Entra ID, Key Vault, and network security controls.
- Practical experience implementing application security tooling within CI/CD pipelines (SAST, DAST, SCA, secrets scanning).
- Strong understanding of the OWASP Top 10 and common application vulnerabilities (injection, broken auth, IDOR, XSS, etc.).
- Experience with Infrastructure‑as‑Code security scanning (e. g. Checkov, tfsec, or similar) and Ia C platforms such as Terraform or Bicep.
- Working knowledge of container security concepts (Docker, Kubernetes, image hardening, runtime security).
- Proficiency in at least one scripting or programming language (Python, Power Shell, Bash, or similar) for security automation.
- Familiarity with Zero Trust architecture principles and their application in cloud and application contexts.
- Understanding of OAuth 2.0, Open ID Connect, and API security best practices.
- Desired Skills
- Experience with Git Hub Advanced Security, Snyk, Checkmarx, Veracode, or equivalent App Sec platforms.
- Exposure to cloud-native SIEM/SOAR platforms such as Microsoft Sentinel for cloud and application threat detection.
- Familiarity with PCI DSS requirements as they relate to web applications and cloud‑hosted cardholder data environments.
- Experience working within an e‑commerce or digitally‑native business where application security is business‑critical.
- Knowledge of API gateway security, WAF configuration, and DDo S protection controls.
- Behavioural Competencies
- Engineer’s mindset – you build and automate rather than rely solely on policy and process.
- Excellent written and verbal communication skills, with the ability to clearly articulate application and cloud risks, recommendations and remediation plans into clear, actionable language for both technical and non-technical audiences.
- Collaborative and pragmatic – able to balance security rigour with development velocity.
- Self‑motivated and proactive, with a track record of taking ownership and driving improvements.
- Passion for security and a commitment to staying current with the evolving cloud and App Sec threat landscape.
- High level of personal integrity and sound ethical judgement.
Qualifications & Experience
- Hands‑on experience in a security engineering role with a clear focus on cloud and/or application security.
- Relevant certifications desirable, such as AZ‑500 (Azure Security Engineer), SC‑100/200, AWS Security Specialty, CSSLP, GWEB, or equivalent.
- Degree in Cyber Security, Computer Science, Software Engineering, or a related field is advantageous but not essential – demonstrable practical experience will be equally considered.
We welcome applications from candidates of all backgrounds, race, national or ethnic origin, colour, religion, age, sex, sexual orientation, gender identity or expression, marital status, family status, genetic characteristics, disability.
We are dedicated to creating equal opportunities for all, and we encourage candidates from underrepresented groups to apply.
Join us in shaping a workplace where diversity is celebrated, and everyone can thrive.
Join us and help shape the future of clean energy – one installation at a time.
#J-18808-Ljbffr
Security Engineer (Cloud & Application Security) employer: Segen Ltd
Segen Ltd is an exceptional employer located in the vibrant City of Westminster, offering a dynamic work culture that prioritises innovation and collaboration. With a strong commitment to employee growth, Segen provides ample opportunities for professional development alongside attractive benefits such as 25 days of holiday and an EV Car scheme. Join a forward-thinking team dedicated to making a positive impact in the renewable energy sector while enjoying a supportive and inclusive workplace.
StudySmarter Expert Advice🤫
We think this is how you could land Security Engineer (Cloud & Application Security)
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Segen Ltd, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Segen Ltd
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Segen Ltd. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Security Engineer (Cloud & Application Security)
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Segen Ltd insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Segen Ltd that you’re committed to staying ahead in the game.
How to prepare for a job interview at Segen Ltd
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Segen Ltd to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Segen Ltd.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.