Security Engineer – Cloud Migration to AWS in Newcastle upon Tyne

Security Engineer – Cloud Migration to AWS in Newcastle upon Tyne

Newcastle upon Tyne Full-Time 63000 - 77000 £ / year (est.) Home office (partial)
Version 1

At a Glance

  • Tasks: Join a dynamic team to secure cloud migrations to AWS and automate security processes.
  • Company: Version 1, a leading tech partner with a strong focus on employee wellbeing.
  • Benefits: Enjoy flexible working, competitive pay, and a range of wellness initiatives.
  • Other info: Be part of an inclusive workplace that values diversity and personal growth.
  • Why this job: Make a real impact in cloud security while growing your skills in a supportive environment.
  • Qualifications: 4+ years in security engineering and hands-on AWS experience required.

The predicted salary is between 63000 - 77000 £ per year.

Version 1 has celebrated 30 years in business and continues to be trusted by global brands to deliver technology and transformation solutions that drive customer success. Our deep expertise enables our customers to navigate the rapidly evolving technology landscape. We foster strong partnerships with global technology leaders including Microsoft, AWS, Oracle, Red Hat, OutSystems, Snowflake, ensuring that our customers are provided with the highest quality solutions and services.

We are seeking a hands-on Security Engineer to embed within a large-scale cloud migration programme, moving workloads into AWS. You will be responsible for designing, automating, and enforcing security controls throughout the migration lifecycle — ensuring that every workload lands in AWS with a secure, compliant, and auditable posture. This is a technical, build-focused role combining cloud security architecture, infrastructure-as-code, and Python automation.

Key Responsibilities

  • Define and implement the security controls, guardrails, and landing zone baseline for workloads migrating to AWS.
  • Design and operate AWS-native security tooling across accounts and Organizations.
  • Build security automation in Python — remediation Lambdas, compliance-check scripts, event-driven response, and integrations with ticketing/SIEM systems.
  • Author, review, and maintain infrastructure-as-code (Terraform and/or CloudFormation) for security services, guardrails, IAM, networking, and encryption.
  • Integrate security into GitLab CI/CD pipelines — SAST, IaC scanning, secrets detection, dependency/container scanning, and policy-as-code gates.
  • Assess the security posture of workloads before, during, and after migration; identify and remediate misconfigurations and vulnerabilities.
  • Design secure network segmentation and connectivity between source environments and AWS (Direct Connect / VPN, Transit Gateway, security groups, NACLs).
  • Implement IAM least-privilege models, identity federation, and secrets management for migrated workloads.
  • Define encryption standards (at rest and in transit) using KMS, ACM, and TLS policy.
  • Support compliance and audit requirements (e.g. CIS Benchmarks, NIST, ISO 27001, SOC 2, PCI-DSS as applicable) and produce evidence.
  • Partner with migration, platform, and application teams to unblock security issues without slowing delivery.
  • Contribute to incident detection and response runbooks for the AWS environment.

Qualifications Required Technical Skills

  • AWS Security Tooling
  • AWS Security Hub – aggregated findings, standards, and posture management
  • Amazon GuardDuty – threat detection
  • AWS Config – configuration compliance and drift detection, custom/conformance rules
  • AWS IAM / IAM Identity Center – least-privilege roles, policies, permission boundaries, federation
  • AWS KMS & ACM – encryption key management and certificates
  • AWS WAF & Shield – application and DDoS protection
  • Amazon Inspector – vulnerability scanning for EC2/ECR/Lambda
  • AWS CloudTrail – audit logging and monitoring
  • AWS Organizations & Service Control Policies (SCPs) – multi-account guardrails
  • AWS Secrets Manager / Systems Manager Parameter Store – secrets handling
  • Amazon Macie – sensitive data discovery (desirable)
  • AWS Control Tower / Landing Zone – governed account provisioning

Automation & Infrastructure-as-Code

  • Python – security automation, boto3, Lambda functions, remediation scripts, custom Config rules
  • Terraform – modules for security services, guardrails, IAM, networking
  • CloudFormation – templates and (desirable) StackSets across accounts
  • Familiarity with policy-as-code (e.g. OPA/Conftest, cfn-guard, Checkov, tfsec) is a strong plus

CI/CD & Version Control

  • GitLab – repositories, merge requests, and GitLab CI/CD pipeline development
  • Integrating security scanning into pipelines: SAST, DAST, IaC scanning, secrets scanning, SCA, container image scanning
  • Git branching, code review, and shift-left security practices

Migration & Infrastructure

  • Workload discovery and assessment ahead of migration
  • AWS migration tooling (Application Migration Service / MGN, DMS, Migration Hub) – desirable
  • Hybrid networking: Direct Connect, VPN, Transit Gateway, VPC design, security groups, NACLs
  • Operating system security hardening (Linux and/or Windows)

Required Experience & Qualifications

  • 4+ years in security engineering, cloud security, or infrastructure security (adjust to seniority).
  • Demonstrable hands-on experience securing production AWS environments.
  • Proven experience delivering or securing a cloud migration programme.
  • Strong scripting/automation ability in Python.
  • Experience with IaC (Terraform and/or CloudFormation) in a production setting.
  • Comfortable working in a GitLab-based DevSecOps workflow.
  • Solid understanding of security frameworks and compliance standards.

Version 1 is an equal opportunities employer. We are committed to building a diverse, inclusive and respectful workplace where everyone feels valued and able to thrive. We welcome applications from people of all backgrounds, identities and lived experiences, and we value the different perspectives people bring.

Security Engineer – Cloud Migration to AWS in Newcastle upon Tyne employer: Version 1

Version 1 is an exceptional employer that prioritises the well-being and professional growth of its employees. With a strong focus on fostering a collaborative work culture, this role offers unique opportunities to engage with leading Private Sector organisations in the UK & Ireland, driving meaningful impact while enjoying competitive salaries, bonuses, and comprehensive benefits. Join us to be part of a dynamic team that values innovation and personal development.

Version 1

Contact Details:

Version 1 Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Security Engineer – Cloud Migration to AWS in Newcastle upon Tyne

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Version 1, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Version 1

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Version 1. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Security Engineer – Cloud Migration to AWS in Newcastle upon Tyne

AWS Security Tooling
Python Automation
Infrastructure-as-Code (Terraform, CloudFormation)
GitLab CI/CD
Security Frameworks and Compliance Standards
IAM Management
Network Security Design

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Version 1 insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Version 1 that you’re committed to staying ahead in the game.

How to prepare for a job interview at Version 1

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Version 1 to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Version 1.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.