Security Engineer

Security Engineer

Full-Time 63000 - 77000 £ / year (est.) Home office (partial)
S

At a Glance

  • Tasks: Own cloud and product security, run pen tests, and embed security in engineering workflows.
  • Company: Join StackOne, a fast-growing AI integration startup backed by top investors.
  • Benefits: Enjoy share options, private health insurance, and a generous holiday allowance.
  • Other info: Flexible hybrid working, diverse team, and excellent career growth opportunities.
  • Why this job: Make a real impact on security in a cutting-edge tech environment.
  • Qualifications: 3+ years in security engineering with strong coding skills in TypeScript, Python, or Go.

The predicted salary is between 63000 - 77000 £ per year.

About StackOne: StackOne is the AI Integration Gateway for SaaS products and AI Agents. Backed by GV and Workday Ventures ($24M raised), we help builders of SaaS platforms and AI Agents orchestrate hundreds of scalable, accurate, and enterprise-grade integrations. Our platform combines 25,000 pre-mapped actions on 200 connectors, an AI-powered integration development toolkit, plus security by design: a real‑time architecture, managed authentication and permissions, and end‑to‑end observability. Join us on our fast trajectory to build the future of agentic integrations.

About the role: We’re looking for a Security Engineer to be a key hire on our Engineering team and own our cloud and product security posture as we scale. You’ll work across our AWS and Cloudflare estate, harden our secure SDLC, run pen testing efforts end‑to‑end, and threat‑model the features powering our connectors, OAuth flows, and agent execution paths. It’s a hands‑on, DevSecOps‑heavy role: you write code, ship tooling, and embed security into how engineers work every day. You’ll report directly to the CTO and have broad scope across the platform (from CI/CD pipelines to multi‑tenant APIs to incident response on authentication flows).

Responsibilities:

  • Own the secure SDLC: drive SAST, dependency scanning, secrets detection, and PR‑blocking standards across every repository.
  • Harden our AWS and Cloudflare estate: IAM, secrets, network segmentation, KMS, WAF, GuardDuty, and zero‑trust patterns.
  • Run pen testing end‑to‑end: scope and coordinate engagements with both AI‑driven scanners and human researchers, then drive findings through fix and retest.
  • Threat‑model product features before they ship, new Auth provider, expanded multi‑tenant APIs, connector executions, agent tool‑calling paths etc.
  • Build detection and response capability around credential and authentication flows, with observability that closes incidents fast.
  • Partner with engineering to raise the bar day‑to‑day: architecture reviews, written standards, and security embedded in code review.
  • Use LLMs and agents to accelerate security workflows (triage, code review, evidence gathering) with guardrails you trust and help secure and monitor the (code/application/device) fleet.
  • Support compliance work where it intersects security engineering: SOC 2, ISO 27001, customer security reviews, and pen test responses.

What we’re looking for:

  • 3+ years in security engineering with hands‑on AWS security: IAM, KMS, networking, secrets, GuardDuty / Security Hub.
  • Strong coding ability in TypeScript or Python or Go comfortable shipping production code, not just configs and scripts.
  • Application security fluency: OWASP Top 10, threat modeling, and code‑level reviews on real systems.
  • Experience securing a B2B SaaS multi‑tenant production environment.
  • Comfort owning end‑to‑end work: scope, ship, measure. You don’t wait for a queue.
  • Clear communication with engineers, product, and non‑technical stakeholders.
  • Bias toward automating security checks instead of running manual checklists.
  • (Preferred) IaC fluency in AWS CDK or Terraform, comfortable reviewing infrastructure code for security misconfigs and writing custom scanning rules.
  • (Preferred) Experience with Aikido, Drata, Cloudflare Workers, or pen testing in a compliance‑mature environment.

Our Stack:

  • Cloud & infra: AWS (ECS, RDS, Lambda, KMS, GuardDuty, Security Hub, Inspector), Cloudflare (Workers, WAF, Zero Trust)
  • IaC: AWS CDK, Terraform
  • Security tooling: Aikido (SAST, DAST, container scanning, pen testing), 1Password, GitHub (org‑level enforcement, Advanced Security)
  • Compliance & ops: Drata, Iru, EasyLlama
  • Observability & IR: Datadog, Sentry, Logfire, Incident.io
  • Languages: TypeScript (Node.js), Python

Benefits:

  • Meaningful share options (EMI) - share in the company’s success as we grow
  • 25 days holiday + 1 additional day per year of tenure
  • Private health insurance - including dental & optical
  • £15/day lunch budget when working from our London office, up to £120/month
  • £1,000 for your home office set up + £500/year top‑up
  • Annual team offsite to sunny spots (last ones were in Spain and Portugal)
  • Join one of Europe’s fastest-growing startups
  • Work with a veteran team of ex‑employees of Google, Microsoft, Oracle, Coinbase, JP Morgan and more
  • Health, fitness and gift card discounts
  • Cycle2Work and Electric Cars scheme
  • Hybrid working friendly - typically 2 days/week in our London office. We’re open to discussing flexible arrangements—please share any preferences in your application

We believe diversity drives innovation. We encourage individuals from all backgrounds to apply. As an equal‑opportunity employer, we celebrate diversity and are committed to creating an inclusive environment for all employees.

Security Engineer employer: StackOne Technologies Limited

StackOne is an exceptional employer, offering a dynamic work environment where innovation thrives and employees are empowered to shape the future of AI integrations. With competitive benefits such as meaningful share options, private health insurance, and a generous holiday allowance, alongside opportunities for professional growth and collaboration with a talented team from top tech companies, StackOne fosters a culture of inclusivity and flexibility in its London office. Join us to be part of a fast-growing startup that values diversity and encourages every employee to contribute to our success.

S

Contact Details:

StackOne Technologies Limited Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Security Engineer

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including StackOne Technologies Limited, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through StackOne Technologies Limited

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at StackOne Technologies Limited. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Security Engineer

AWS Security
Cloudflare Security
Secure SDLC
Penetration Testing
Threat Modelling
TypeScript
Python

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at StackOne Technologies Limited insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to StackOne Technologies Limited that you’re committed to staying ahead in the game.

How to prepare for a job interview at StackOne Technologies Limited

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at StackOne Technologies Limited to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at StackOne Technologies Limited.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.