At a Glance
- Tasks: Lead efforts to enhance security through innovative coding and automation.
- Company: Join Engine by Starling, a forward-thinking tech company prioritising security.
- Benefits: Enjoy 33 days holiday, private medical insurance, and flexible working options.
- Why this job: Make a real impact on security while working with cutting-edge technologies.
- Qualifications: Experience in cloud security or strong programming skills in Go or Python.
- Other info: Collaborative team environment with opportunities for personal and professional growth.
The predicted salary is between 60000 - 84000 £ per year.
This is a highly varied position where you will spearhead efforts to fortify both our infrastructure and application platforms. Your mission is to solve complex security problems through code, focusing on three core pillars:
- Identity & Network Security: Engineering robust IAM controls and zero-trust network architectures. You will lead the way in refining edge-defense strategies and trust redirection to ensure every request is verified and encrypted.
- Unified Vulnerability Orchestration: Building a custom "single pane of glass" for security data. You will engineer API integrations between scanning engines, dependency trackers, and internal portals to create a seamless, automated vulnerability ecosystem.
- Compliance as Code: Bridging the gap between technical execution and regulatory requirements. You will build the automated systems that provide real-time evidence for frameworks like SOC 2, ISO 27001 & PCI ensuring we stay compliant without manual overhead.
You will be a key member of our growing Security Engineering team, working at the intersection of our Infrastructure, Cross-Cutting, Information Security, and GRC teams. At Engine, we believe security should be at the heart of every technical process, not an afterthought. You won’t work in a silo; you’ll have close interaction with engineers across the business to deliver a platform that is resilient against evolving threats.
We are primarily looking for experienced Cloud Security Engineers, but we are equally keen to talk to talented Software Engineers who possess strong programming skills and a genuine desire to apply their knowledge to security challenges. Engine engineers are motivated by impact and high-quality delivery, regardless of their original tech stack. Whether you are a security specialist or a developer with a "security-first" mindset, your place within the team will be shaped by your individual strengths and interests.
What you’ll get to do?
- Security as Code: Design and maintain custom security tooling in Go to automate evidence collection for SOC2/ISO 27001 and remediation of security alerts.
- Infrastructure & IAM: Write and peer-review Terraform to manage identity and core infrastructure across AWS and GCP, ensuring the principle of least privilege is baked into the foundation and adhering to cloud security standards.
- Pipeline & Supply Chain: Contribute to maintaining the integrity of our software supply chain. You will integrate SAST/DAST/SCA tools into our CI/CD pipelines (GitHub Actions/TeamCity) and manage container provenance.
- Cloud Native Defense: Engineer Kubernetes security solutions focusing on Cilium, RBAC, and network policies to protect our microservices.
- Identity & Trust (PKI): Build and maintain our Certificate Authority (CA) tooling and internal PKI infrastructure. You will be a trusted guardian of our cryptographic foundations, participating in Key Ceremonies to ensure the highest level of root-level security.
- Incident Response & Research: Support the Information Security team and participate in incident response and post-mortem activities.
Requirements
What skills are essential:
- The Builder Mindset: You have a background in software or infrastructure engineering. You find manual work a personal affront and prefer to solve problems through code.
- Polyglot-ish: You are proficient in Go (our preference) or Python.
- Cloud Native: You have deep, practical experience securing AWS or GCP and have managed them at scale using Terraform.
- Container Expert: You understand the nuances of Kubernetes security - from the runtime to the service mesh.
- Identity Mastery: Expert knowledge of cloud identity models.
- Networking: Strong understanding of network protocols.
What skills are desirable:
- Experience with Cilium networking or advanced K8s hardening (CKS/CKA).
- Deep knowledge of cryptography management and hardware security modules.
- Familiarity with container signing (Sigstore/Cosign) and image provenance.
- Cloud-native security certifications (AWS Security Specialist / GCP Professional).
- Experience working with CSA CCM.
Benefits
- 33 days holiday (including public holidays, which you can take when it works best for you).
- An extra day’s holiday for your birthday.
- Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off.
- 16 hours paid volunteering time a year.
- Salary sacrifice, company enhanced pension scheme.
- Life insurance at 4x your salary & group income protection.
- Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton.
- Generous family-friendly policies.
- Incentives refer a friend scheme.
- Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks.
- Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing.
Senior Cloud Security Engineer (Automation & Tooling) - Engine by Starling in Cardiff employer: Starling
Contact Detail:
Starling Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Cloud Security Engineer (Automation & Tooling) - Engine by Starling in Cardiff
✨Tip Number 1
Network like a pro! Reach out to current employees at Engine by Starling on LinkedIn. A friendly chat can give you insider info and might just get your foot in the door.
✨Tip Number 2
Show off your skills! Prepare a portfolio or GitHub repo showcasing your projects, especially those related to cloud security and automation. This is your chance to shine and demonstrate your 'Builder Mindset'.
✨Tip Number 3
Ace the interview! Research common interview questions for Cloud Security Engineers and practice your answers. Be ready to discuss how you've tackled security challenges through code.
✨Tip Number 4
Apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you're genuinely interested in joining the team at Engine by Starling.
We think you need these skills to ace Senior Cloud Security Engineer (Automation & Tooling) - Engine by Starling in Cardiff
Some tips for your application 🫡
Tailor Your CV: Make sure your CV reflects the skills and experiences that align with the Senior Cloud Security Engineer role. Highlight your cloud security expertise, programming skills, and any relevant projects you've worked on. We want to see how you can contribute to our mission!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about security and how your background makes you a great fit for our team. Don’t forget to mention specific technologies or methodologies you’ve used that relate to the job description.
Showcase Your Problem-Solving Skills: In your application, give examples of how you've tackled complex security challenges in the past. We love candidates who have a builder mindset and prefer solving problems through code, so share those experiences that demonstrate your approach!
Apply Through Our Website: We encourage you to apply directly through our website for the best chance of getting noticed. It’s super easy, and you’ll be able to submit all your materials in one go. Plus, we love seeing applications come through our own channels!
How to prepare for a job interview at Starling
✨Know Your Tech Inside Out
Make sure you’re well-versed in the technologies mentioned in the job description, especially Go and Terraform. Brush up on your knowledge of AWS and GCP security practices, as well as Kubernetes security nuances. Being able to discuss these topics confidently will show that you're serious about the role.
✨Showcase Your Problem-Solving Skills
Prepare examples of how you've tackled complex security challenges in the past. Whether it’s automating compliance checks or enhancing IAM controls, be ready to explain your thought process and the impact of your solutions. This will demonstrate your builder mindset and ability to think critically.
✨Understand the Company’s Mission
Familiarise yourself with Engine by Starling's mission and values. Be prepared to discuss how your skills align with their goal of integrating security into every technical process. Showing that you understand their approach will help you stand out as a candidate who is genuinely interested in the role.
✨Ask Insightful Questions
Prepare thoughtful questions that reflect your understanding of the role and the company. Inquire about their current security challenges or how they envision the future of their security engineering team. This not only shows your enthusiasm but also helps you gauge if the company is the right fit for you.