Security Engineer in London

Security Engineer in London

London Full-Time 60000 - 80000 € / year (est.) Home office (partial)
StackOne

At a Glance

  • Tasks: Own cloud and product security, run pen tests, and threat-model features.
  • Company: Join StackOne, a fast-growing AI integration startup backed by top investors.
  • Benefits: Enjoy share options, private health insurance, and a generous holiday allowance.
  • Other info: Flexible hybrid working, diverse team, and excellent career growth opportunities.
  • Why this job: Make a real impact on security in a cutting-edge tech environment.
  • Qualifications: 3+ years in security engineering with AWS experience and strong coding skills.

The predicted salary is between 60000 - 80000 € per year.

About StackOne: StackOne is the AI Integration Gateway for SaaS products and AI Agents. Backed by GV and Workday Ventures ($24M raised), we help builders of SaaS platforms and AI Agents orchestrate hundreds of scalable, accurate, and enterprise-grade integrations. Our platform combines 25,000 pre-mapped actions on 200 connectors, an AI-powered integration development toolkit, plus security by design: a real-time architecture, managed authentication and permissions, and end-to-end observability. Join us on our fast trajectory to build the future of agentic integrations.

About the role: We’re looking for a Security Engineer to be a key hire on our Engineering team and own our cloud and product security posture as we scale. You’ll work across our AWS and Cloudflare estate, harden our secure SDLC, run pen testing efforts end-to-end, and threat-model the features powering our connectors, OAuth flows, and agent execution paths. It’s a hands-on, DevSecOps-heavy role: you write code, ship tooling, and embed security into how engineers work every day. You’ll report directly to the CTO and have broad scope across the platform (from CI/CD pipelines to multi-tenant APIs to incident response on authentication flows).

Responsibilities:

  • Own the secure SDLC: drive SAST, dependency scanning, secrets detection, and PR-blocking standards across every repository.
  • Harden our AWS and Cloudflare estate: IAM, secrets, network segmentation, KMS, WAF, GuardDuty, and zero-trust patterns.
  • Run pen testing end-to-end: scope and coordinate engagements with both AI-driven scanners and human researchers, then drive findings through fix and retest.
  • Threat-model product features before they ship, new Auth provider, expanded multi-tenant APIs, connector executions, agent tool-calling paths etc.
  • Build detection and response capability around credential and authentication flows, with observability that closes incidents fast.
  • Partner with engineering to raise the bar day-to-day: architecture reviews, written standards, and security embedded in code review.
  • Use LLMs and agents to accelerate security workflows (triage, code review, evidence gathering) with guardrails you trust and help secure and monitor the (code/application/device) fleet.
  • Support compliance work where it intersects security engineering: SOC 2, ISO 27001, customer security reviews, and pen test responses.

What we’re looking for:

  • 3+ years in security engineering with hands-on AWS security: IAM, KMS, networking, secrets, GuardDuty / Security Hub.
  • Strong coding ability in TypeScript or Python or Go comfortable shipping production code, not just configs and scripts.
  • Application security fluency: OWASP Top 10, threat modeling, and code-level reviews on real systems.
  • Experience securing a B2B SaaS multi-tenant production environment.
  • Comfort owning end-to-end work: scope, ship, measure. You don’t wait for a queue.
  • Clear communication with engineers, product, and non-technical stakeholders.
  • Bias toward automating security checks instead of running manual checklists.
  • (Preferred) IaC fluency in AWS CDK or Terraform, comfortable reviewing infrastructure code for security misconfigs and writing custom scanning rules.
  • (Preferred) Experience with Aikido, Drata, Cloudflare Workers, or pen testing in a compliance-mature environment.

Our Stack:

  • Cloud & infra: AWS (ECS, RDS, Lambda, KMS, GuardDuty, Security Hub, Inspector), Cloudflare (Workers, WAF, Zero Trust)
  • IaC: AWS CDK, Terraform
  • Security tooling: Aikido (SAST, DAST, container scanning, pen testing), 1Password, GitHub (org-level enforcement, Advanced Security)
  • Compliance & ops: Drata, Iru, EasyLlama
  • Observability & IR: Datadog, Sentry, Logfire, Incident.io
  • Languages: TypeScript (Node.js), Python

Benefits:

  • Meaningful share options (EMI) - share in the company’s success as we grow
  • 25 days holiday + 1 additional day per year of tenure
  • Private health insurance - including dental & optical
  • £15/day lunch budget when working from our London office, up to £120/month
  • £1,000 for your home office set up + £500/year top-up
  • Annual team offsite to sunny spots (last ones were in Spain and Portugal ☀️)
  • Join one of Europe’s fastest-growing startups
  • Work with a veteran team of ex-employees of Google, Microsoft, Oracle, Coinbase, JP Morgan and more
  • Health, fitness and gift card discounts
  • Cycle2Work and Electric Cars scheme
  • Hybrid working friendly - typically 2 days/week in our London office. We’re open to discussing flexible arrangements—please share any preferences in your application
  • We believe diversity drives innovation. We encourage individuals from all backgrounds to apply. As an equal-opportunity employer, we celebrate diversity and are committed to creating an inclusive environment for all employees.

Security Engineer in London employer: StackOne

StackOne is an exceptional employer, offering a dynamic work environment where innovation thrives and employees are empowered to shape the future of AI integrations. With competitive benefits such as meaningful share options, generous holiday allowances, and a strong focus on employee well-being through private health insurance and a supportive hybrid working model, StackOne fosters a culture of collaboration and growth. Join a team of industry veterans in a fast-paced startup atmosphere that values diversity and encourages personal and professional development.

StackOne

Contact Detail:

StackOne Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Security Engineer in London

Tip Number 1

Network like a pro! Reach out to folks in the industry, attend meetups, and connect with current employees at StackOne. A friendly chat can sometimes lead to opportunities that aren’t even advertised!

Tip Number 2

Show off your skills! If you’ve got a GitHub or personal project showcasing your coding chops, make sure to highlight it during interviews. It’s a great way to demonstrate your hands-on experience in security engineering.

Tip Number 3

Prepare for technical interviews by brushing up on your knowledge of AWS security and coding in TypeScript or Python. Practice common security scenarios and be ready to discuss how you’d tackle them in real-world situations.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive about their job search!

We think you need these skills to ace Security Engineer in London

AWS Security
Cloudflare Security
Secure SDLC
Penetration Testing
Threat Modelling
TypeScript
Python

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience with AWS security and coding in TypeScript, Python, or Go. We want to see how your skills align with our needs!

Show Off Your Security Knowledge:Don’t forget to mention your familiarity with application security concepts like the OWASP Top 10 and threat modelling. This is key for us as we look for someone who can own our security posture.

Be Clear and Concise:When writing your application, keep it straightforward. We appreciate clear communication, especially when it comes to technical details. Make it easy for us to see your qualifications!

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you don’t miss out on any important updates from our team!

How to prepare for a job interview at StackOne

Know Your Security Fundamentals

Make sure you brush up on your security engineering basics, especially around AWS security, IAM, and KMS. Be ready to discuss how you've applied these concepts in real-world scenarios, as this will show your hands-on experience.

Showcase Your Coding Skills

Since the role requires strong coding abilities in TypeScript, Python, or Go, prepare to demonstrate your coding skills. Bring examples of production code you've shipped and be ready to explain your thought process behind it.

Understand the Company’s Tech Stack

Familiarise yourself with StackOne's tech stack, including AWS services and security tools like Aikido and GitHub Advanced Security. This knowledge will help you speak confidently about how you can contribute to their existing systems.

Prepare for Scenario-Based Questions

Expect scenario-based questions that assess your problem-solving skills in security contexts. Think through potential threats and how you would approach threat modelling or incident response, as this will highlight your proactive mindset.