Senior Cloud Security Engineer (Automation & Tooling) - Engine by Starling in London
Senior Cloud Security Engineer (Automation & Tooling) - Engine by Starling

Senior Cloud Security Engineer (Automation & Tooling) - Engine by Starling in London

London Full-Time 48000 - 72000 £ / year (est.) No home office possible
S

At a Glance

  • Tasks: Build secure systems and automate defences for our core banking platform.
  • Company: Join Engine by Starling, where security is a top priority.
  • Benefits: Enjoy 33 days holiday, private medical insurance, and wellness perks.
  • Why this job: Make a real impact in cloud security while working with cutting-edge tech.
  • Qualifications: Experience in cloud security or strong programming skills in Go or Python.
  • Other info: Collaborative team environment with opportunities for growth and innovation.

The predicted salary is between 48000 - 72000 £ per year.

About Engineering at Engine by Starling - At Engine by Starling, we don’t do "checkbox security". We treat security as a first-class engineering discipline. As a Cloud Security Engineer, you will be a hands-on builder responsible for the security architecture of our multi-tenant core banking platform. You’ll spend your days writing code, automating defenses, and ensuring our infrastructure that spans across AWS and GCP is secure by design and compliant by default.

The Mission: This is a highly varied position where you will spearhead efforts to fortify both our infrastructure and application platforms. Your mission is to solve complex security problems through code, focusing on three core pillars:

  • Identity & Network Security: Engineering robust IAM controls and zero-trust network architectures. You will lead the way in refining edge-defense strategies and trust redirection to ensure every request is verified and encrypted.
  • Unified Vulnerability Orchestration: Building a custom "single pane of glass" for security data. You will engineer API integrations between scanning engines, dependency trackers, and internal portals to create a seamless, automated vulnerability ecosystem.
  • Compliance as Code: Bridging the gap between technical execution and regulatory requirements. You will build the automated systems that provide real-time evidence for frameworks like SOC 2, ISO 27001 & PCI ensuring we stay compliant without manual overhead.

The Team: You will be a key member of our growing Security Engineering team, working at the intersection of our Infrastructure, Cross-Cutting, Information Security, and GRC teams. At Engine, we believe security should be at the heart of every technical process, not an afterthought. You won’t work in a silo; you’ll have close interaction with engineers across the business to deliver a platform that is resilient against evolving threats.

About You: We are primarily looking for experienced Cloud Security Engineers, but we are equally keen to talk to talented Software Engineers who possess strong programming skills and a genuine desire to apply their knowledge to security challenges. Engine engineers are motivated by impact and high-quality delivery, regardless of their original tech stack. Whether you are a security specialist or a developer with a "security-first" mindset, your place within the team will be shaped by your individual strengths and interests.

What you’ll get to do? You won’t be manually checking boxes. You will be building the systems that check them for you.

  • Security as Code: Design and maintain custom security tooling in Go to automate evidence collection for SOC2/ISO 27001 and remediation of security alerts.
  • Infrastructure & IAM: Write and peer-review Terraform to manage identity and core infrastructure across AWS and GCP, ensuring the principle of least privilege is baked into the foundation and adhering to cloud security standards.
  • Pipeline & Supply Chain: Contribute to maintaining the integrity of our software supply chain. You’ll integrate SAST/DAST/SCA tools into our CI/CD pipelines (GitHub Actions/TeamCity) and manage container provenance.
  • Cloud Native Defense: Engineer Kubernetes security solutions focusing on Cilium, RBAC, and network policies to protect our microservices.
  • Identity & Trust (PKI): Build and maintain our Certificate Authority (CA) tooling and internal PKI infrastructure. You will be a trusted guardian of our cryptographic foundations, participating in Key Ceremonies to ensure the highest level of root-level security.
  • Incident Response & Research: Support the Information Security team and participate in incident response and post-mortem activities.

Requirements: What skills are essential:

  • The Builder Mindset: You have a background in software or infrastructure engineering. You find manual work a personal affront and prefer to solve problems through code.
  • Polyglot-ish: You are proficient in Go (our preference) or Python.
  • Cloud Native: You have deep, practical experience securing AWS or GCP and have managed them at scale using Terraform.
  • Container Expert: You understand the nuances of Kubernetes security - from the runtime to the service mesh.
  • Identity Mastery: Expert knowledge of cloud identity models.
  • Networking: Strong understanding of network protocols.

What skills are desirable:

  • Experience with Cilium networking or advanced K8s hardening (CKS/CKA).
  • Deep knowledge of cryptography management and hardware security modules.
  • Familiarity with container signing (Sigstore/Cosign) and image provenance.
  • Cloud-native security certifications (AWS Security Specialist / GCP Professional).
  • Experience working with CSA CCM.

Benefits: 33 days holiday (including public holidays, which you can take when it works best for you). An extra day’s holiday for your birthday. Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off. 16 hours paid volunteering time a year. Salary sacrifice, company enhanced pension scheme. Life insurance at 4x your salary & group income protection. Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton. Generous family-friendly policies. Incentives refer a friend scheme. Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks. Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing.

Senior Cloud Security Engineer (Automation & Tooling) - Engine by Starling in London employer: Starling

At Engine by Starling, we pride ourselves on fostering a dynamic and inclusive work culture where security is treated as a core engineering discipline. As a Senior Cloud Security Engineer, you will enjoy a wealth of benefits including 33 days of holiday, a generous pension scheme, and private medical insurance, all while working in a collaborative environment that encourages personal growth and innovation. Our commitment to employee well-being and professional development makes us an exceptional employer for those looking to make a meaningful impact in the tech industry.
S

Contact Detail:

Starling Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Senior Cloud Security Engineer (Automation & Tooling) - Engine by Starling in London

✨Tip Number 1

Network like a pro! Reach out to folks in the industry, attend meetups, and connect with current employees at Engine by Starling. A friendly chat can sometimes lead to opportunities that aren’t even advertised.

✨Tip Number 2

Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those related to cloud security and automation. This gives potential employers a taste of what you can do beyond just a CV.

✨Tip Number 3

Prepare for technical interviews by brushing up on your coding skills and understanding cloud security principles. Practice common interview questions and scenarios that relate to the role of a Cloud Security Engineer.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining the team at Engine by Starling.

We think you need these skills to ace Senior Cloud Security Engineer (Automation & Tooling) - Engine by Starling in London

Cloud Security Engineering
Automation
Infrastructure as Code (Terraform)
AWS Security
GCP Security
Kubernetes Security
Programming in Go
Identity and Access Management (IAM)
Network Security
Incident Response
Vulnerability Management
Cryptography Management
CI/CD Integration
Container Security
Compliance as Code

Some tips for your application 🫡

Show Your Passion for Security: When you're writing your application, let us see your enthusiasm for security! Share specific examples of how you've tackled security challenges in the past and why you believe security should be a first-class engineering discipline.

Tailor Your Application: Make sure to customise your application to highlight your relevant skills and experiences. We want to see how your background in software or infrastructure engineering aligns with our mission at Engine by Starling.

Be Clear and Concise: Keep your application straightforward and to the point. Use clear language to describe your experiences and avoid jargon unless it's necessary. We appreciate clarity as much as we appreciate technical expertise!

Apply Through Our Website: Don't forget to submit your application through our website! It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it makes the whole process smoother for everyone involved.

How to prepare for a job interview at Starling

✨Know Your Tech Stack

Make sure you’re well-versed in the technologies mentioned in the job description, especially Go and Terraform. Brush up on your knowledge of AWS and GCP security practices, as well as Kubernetes security nuances. Being able to discuss these confidently will show that you’re ready to hit the ground running.

✨Demonstrate Your Builder Mindset

Prepare examples of how you've solved complex problems through code in previous roles. Highlight any automation projects you've worked on, especially those related to security. This will help illustrate your proactive approach and ability to think like a builder, which is crucial for this role.

✨Understand Compliance as Code

Familiarise yourself with frameworks like SOC 2 and ISO 27001. Be ready to discuss how you’ve implemented compliance measures in past projects, particularly through automation. Showing that you can bridge technical execution with regulatory requirements will set you apart from other candidates.

✨Engage with the Team's Mission

Research Engine by Starling’s approach to security and be prepared to discuss how you can contribute to their mission of integrating security into every technical process. Show enthusiasm for collaboration and how you can work across teams to enhance security architecture.

Senior Cloud Security Engineer (Automation & Tooling) - Engine by Starling in London
Starling
Location: London

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

S
  • Senior Cloud Security Engineer (Automation & Tooling) - Engine by Starling in London

    London
    Full-Time
    48000 - 72000 £ / year (est.)
  • S

    Starling

    250-500
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>