At a Glance
- Tasks: Build scalable security controls through code and automation in a hands-on role.
- Company: Join Shieldpay, a forward-thinking company prioritising security as an engineering challenge.
- Benefits: Enjoy flexible working hours, hybrid options, and a commitment to work-life balance.
- Why this job: Make a real impact by securing innovative projects and automating threat detection.
- Qualifications: Strong Computer Science background with scripting skills and cloud experience.
- Other info: Equal opportunities employer with excellent training and career growth prospects.
The predicted salary is between 36000 - 60000 £ per year.
We are seeking a hands-on Security Engineer to build scalable controls through code and automation. We treat security as an engineering challenge—focusing on IaC, reliable guardrails, and making "secure by default" easy for our teams. We need a builder. This role is for a technical engineer who views security as an engineering problem to be solved with code, not a set of documents to be filed.
Responsibilities:
- Instead of manually reviewing logs, you will be writing the scripts that automate threat detection.
- Working within AWS and GCP to ensure our infrastructure is secure by design using Pulumi, CDK, or Terraform.
- Building and maintaining the CI/CD security gates that allow our dev teams to move fast without breaking things.
- Getting hands-on with vulnerability scanning, occasional internal "red-teaming," and incident response when things get interesting.
What we are looking for in you:
- A solid background in Computer Science. You understand how systems talk to each other, how memory works, and why the "cloud" is just someone else's computer.
- Automation First - you are proficient in at least one scripting language (Python, Go, JavaScript) and hate doing the same task manually twice.
- You have spent significant time in AWS or GCP. You know your way around IAM, VPCs, and serverless environments.
- You understand CI/CD using GitHub Actions and how to bake security into the deployment process.
- You have configured and managed Cloudflare, CloudFront and AWS WAF and know how to defend against common web threats at the perimeter.
The 'nice to haves':
- We do not necessarily expect you to arrive with a CISSP or a deep love for ISO. If you bring the engineering muscle, we will train you on Governance, Risk and Compliance.
- Previous experience in Penetration Testing or CTF competitions.
- Exposure to Incident Response (knowing what to do when the alarm goes off).
- Experience securing event-driven serverless workloads.
Our Promise: Shieldpay is an equal opportunities employer. For Shieldpay, building a fair and transparent workforce begins with the recruitment process that does not discriminate on the grounds of gender, sexual orientation, pregnancy or maternity, gender reassignment, race, colour, nationality, ethnic or national origin, religion or belief, disability or age. We offer flexible working options, such as flexible hours and hybrid work, to support our employees' work-life balance.
Security Engineer in London employer: Shieldpay
Contact Detail:
Shieldpay Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Security Engineer in London
✨Tip Number 1
Network like a pro! Reach out to folks in the industry on LinkedIn or at meetups. A personal connection can often get your foot in the door faster than any application.
✨Tip Number 2
Show off your skills! Create a GitHub repo with projects that highlight your coding and automation abilities. This is your chance to demonstrate how you tackle security challenges through engineering.
✨Tip Number 3
Prepare for technical interviews by brushing up on your scripting languages and cloud knowledge. Be ready to discuss how you've automated processes or secured environments in past roles.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who take that extra step!
We think you need these skills to ace Security Engineer in London
Some tips for your application 🫡
Show Your Technical Skills: When writing your application, make sure to highlight your technical skills and experience. We want to see how you’ve tackled security challenges in the past, so don’t hold back on sharing specific examples of your work with code and automation.
Be Authentic: We’re looking for builders, not just checkbox tickers. Let your personality shine through in your application. Share your passion for security and how you view it as an engineering problem to be solved. This will help us get a sense of who you are beyond your CV.
Tailor Your Application: Make sure to tailor your application to our job description. Use the same language we use and address the specific responsibilities and skills we’re looking for. This shows us that you’ve done your homework and are genuinely interested in the role.
Apply Through Our Website: Don’t forget to apply through our website! It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it gives you a chance to explore more about what we do at StudySmarter.
How to prepare for a job interview at Shieldpay
✨Know Your Tech Inside Out
Make sure you’re well-versed in the technologies mentioned in the job description, like AWS, GCP, and scripting languages. Brush up on your knowledge of IAM, VPCs, and serverless environments, as these will likely come up during the interview.
✨Showcase Your Automation Skills
Prepare to discuss specific examples where you've automated tasks or built scalable security controls. Be ready to explain your thought process and the impact of your work, as this role is all about solving security challenges through code.
✨Demonstrate a Builder's Mindset
Emphasise your hands-on experience and how you view security as an engineering problem. Share stories that highlight your proactive approach to security, whether it’s through vulnerability scanning or incident response.
✨Be Ready for Technical Questions
Expect technical questions that test your understanding of CI/CD processes and how to integrate security into them. Prepare to discuss your experience with tools like GitHub Actions and how you’ve managed security gates in past projects.