Cloud Security Engineer
Secures AWS cloud environments and production systems by designing controls, building detection and automation capabilities, and leading incident response. The role requires hands-on cloud security, programming, infrastructure-as-code, and investigation experience.
About the job
Responsibilities
- Design and implement secure cloud architectures across AWS environments.
- Build and maintain protective and detective controls that improve threat visibility across cloud environments.
- Develop detection engineering capabilities to identify attacker behavior and reduce time to detection and response.
- Lead cloud security investigations and incident response activities with engineering teams.
- Participate in a shared on-call rotation and coordinate containment, remediation, and recovery during security incidents.
- Build automation to improve the scalability, reliability, and effectiveness of security controls.
- Partner with infrastructure teams to embed security into cloud platforms, infrastructure-as-code workflows, and engineering practices.
- Develop and improve cloud security standards, guidance, and best practices.
- Drive security initiatives from problem definition through implementation and measurable outcomes.
- Assess emerging threats to cloud environments and evolve defensive capabilities.
- Help shape an AI-first approach to security, including AI-assisted detection, automated investigations, continuous monitoring, and emerging defensive capabilities.
- Support secure adoption of AI-assisted software development tools and engineering workflows.
Requirements
- Proven experience in cloud security, security engineering, detection engineering, or a closely related field.
- Strong experience securing and operating production AWS environments.
- Deep understanding of cloud security principles, modern attack techniques, and security best practices.
- Experience building or operating detection, monitoring, or threat detection capabilities.
- Hands-on experience investigating security incidents, leading technical investigations, and driving remediation.
- Experience implementing security controls across cloud platforms and production environments.
- Strong programming skills and experience building automation, tooling, or operational workflows.
- Experience with infrastructure-as-code practices and modern cloud-native technologies.
- Comfortable using modern AI-assisted development tools.
- Ability to communicate security concepts clearly and collaborate effectively with engineering teams.
- Pragmatic approach to balancing security, customer impact, and engineering velocity.
Nice-to-haves
- Experience building detection engineering, threat hunting, or security operations capabilities at scale.
- Experience with cloud-native security platforms, CNAPP technologies, or large-scale cloud security monitoring.
- Experience applying AI to detection, response, threat analysis, or security operations workflows.
- Familiarity with AWS networking, identity, and cloud security patterns.
- Experience working across large-scale SaaS environments and high-growth companies.
Compensation and Benefits
- Competitive salary and equity in a fast-growing start-up.
- Weekday lunch, snacks, and a fully stocked kitchen.
- Regular compensation reviews.
- Unlimited access to Claude Code and other AI tools.
- Pension scheme with matching up to 4%.
- Life assurance and comprehensive health and dental insurance for employees and dependents.
- Flexible paid time off.
- Paid maternity leave and six weeks of paternity leave.
- Cycle-to-Work Scheme and secure bike storage.
- MacBooks as standard, with Windows available for certain roles.
- Hybrid working with employees expected to work from the office at least three days per week.
Skills
AWS, Cloud Security, Detection Engineering, Incident Response, Threat Hunting, Infrastructure As Code, Cloud-Native Technologies, Security Monitoring, Security Controls, Python, Ai-Assisted Development Tools, Cnapp, Aws Networking, Aws Iam, Automation
Similar jobs
Security Engineering jobsBuild and scale application security for an enterprise AI platform through threat modeling, secure architecture, automated controls, code review, penetration testing, and AI/ML threat research. Requires 4+ years of application security experience and proficiency in at least two programming languages.
Investigates high-risk accounts and leads incident response for fraud and product-abuse events, using behavioral analysis and threat intelligence to identify root causes and improve detection. Requires 3+ years of incident response and fraud-data analysis experience, plus strong Python and SQL skills.
Investigates and leads response to high-risk fraud and product-abuse incidents, analyzes threat patterns, and drives root-cause and prevention improvements. Requires 3+ years of incident response and fraud-oriented data analysis, plus Python, SQL, and security investigation expertise.
Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.
The Threat Intelligence Specialist investigates identity fraud and threat actors, conducts pivot-based OSINT, and collaborates with law enforcement agencies across EMEA. The role requires at least three years of relevant analytical experience, strong communication skills, and the ability to work autonomously across time zones.