Salary: £47,000 - 87,000 per year
Requirements
- 5+ years of DevOps or Platform Engineering experience delivering solutions in Azure and/or GCP.
- Full-stack application and infrastructure solution design experience, with robust security controls, high availability, and operational resilience.
- Working knowledge of vulnerability and compliance management, patch management, endpoint protection or anti-malware, and access control management, including driving findings to closure.
- Working knowledge of threat modelling and risk assessment applied to cloud architectures and CI/CD pipelines.
- Experience with AppSec tooling, including CI/CD integration, tuning to reduce noise, and triaging results with engineers.
- Strong leadership skills, including the ability to educate others and delegate responsibilities across chapters and teams.
- Experience with Terraform and platform solutions.
- Experience working on solutions with integrations between GCP and Azure.
- Knowledge of cloud native, microservices, and containerised systems.
- Strong desire for continuous improvement and an Agile way of working.
- Knowledge of the insurance and London Market ecosystem is ideally beneficial; Lloyds market experience is particularly valuable.
- Proven hands‑on software delivery experience, including platform engineering and/or build, release, and deployment engineering using modern DevOps practices.
- Experience delivering and operating technology in regulated environments, with an understanding of controls, audit expectations, and evidence-based compliance.
- Ability to clearly explain processes, patterns, and tooling used to ensure quality, stability, performance, scalability, secure deployment, maintainability, and documentation.
- Broad awareness of major cloud providers and services, with curiosity to evaluate and adopt capabilities that improve security, reliability, and cost efficiency.
- Proactive, improvement-focused mindset with the ability to challenge the status quo and drive automation and simplification.
- Strong delivery focus, able to prioritise effectively and deliver outcomes in a fast‑paced environment with shifting demands.
- Ability to operate effectively in a small, high‑impact team while collaborating across a wider product and engineering organisation.
- Excellent communication and stakeholder‑management skills, able to influence at all levels and present complex topics clearly.
- Comfortable working in ambiguity and adapting quickly as priorities, technology, and threats evolve.
- Up‑to‑date knowledge of security practices, processes, and tooling, with the judgement to apply emerging approaches pragmatically.
Responsibilities
- We coach and mentor chapter members and support the Head of Platform Engineering with overall chapter management, particularly across partner resources.
- We design, implement, and automate security controls and security testing within the SDLC.
- We lead application security practices, ensuring secure design and build, and coordinate effectively between engineering and security teams.
- We apply Security-as-Code principles by providing training, creating reusable patterns, and establishing best practices for teams.
- We support the investigation and future implementation of agentic workflows and agents, ensuring proposed solutions are secure by design and comply with our AI governance.
- We respond swiftly to new and emerging security threats and vulnerabilities, investigate suspected attacks, and help manage security incidents, including post‑incident reviews.
- We produce clear, actionable security reporting for senior leadership.
- We act as the primary point of contact for security‑related inquiries across London Market technology and change initiatives, coordinating with Group, other Business Units, and Cyber teams.
- We influence key architectural decisions early, balancing business requirements, budgets, security, and resilience.
- We partner with squads to take solutions from proof of concept through to a production‑ready platform.
- We build and maintain secure Azure and GCP infrastructure across all environments using Azure DevOps Pipelines and Terraform.
- We oversee and coach squads on intra‑day deployment mechanisms, advocating for cloud‑informed improvements that increase security, reliability, and delivery speed.
- We build and maintain monitoring and alerting at all levels, ensuring actionable signals and secure operational practices.
- We guide multiple Innovation squads and Engineering Chapters, driving cloud‑first adoption and championing secure‑by‑design initiatives.
- We strengthen our platform security posture through visible leadership and help embed modern DevOps and security ways of working.
- We may take on people leadership responsibilities, including day‑to‑day management of third‑party security engineers and partner resources.
Technologies
- AI
- Azure
- CI/CD
- Cloud
- DevOps
- GCP
- Support
- Security
- Terraform
- microservices
- Embedded
- IAM
More
We are Hiscox, hiring for a Permanent Principal Platform Security Engineer for our London Market. This is a senior role within our London Platform Engineering Chapter, spanning Platform, DevOps, and Site Reliability Engineering, with a core focus on continuous improvement across our cloud and on-premises platforms. We offer the opportunity to make a real difference during a period of focused growth, working with amazing people in a unique culture that values diversity and inclusion. The role is based in York, Lisbon, or London and is full time.
last updated 36 week of 2026