Principal Platform Security Engineer

Hiscox AG

York and North Yorkshire

Hybrid

GBP 47,000 - 87,000

Full time

7 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Hiscox is seeking a Permanent Principal Platform Security Engineer for the London Market, with responsibility across Platform, DevOps, and SRE domains in a cloud-first environment. The role welcomes senior engineers based in York, Lisbon, or London and emphasizes continuous improvement and secure-by-design delivery across cloud and on‑prem platforms.

The role requires proven hands-on software delivery experience, strong collaboration with security teams, and the ability to guide multiple squads

Qualifications

  • 5+ years of DevOps or Platform Engineering experience delivering solutions in Azure and/or GCP.
  • Full-stack application and infrastructure solution design experience, with robust security controls, high availability, and operational resilience.
  • Working knowledge of vulnerability and compliance management, patch management, endpoint protection or anti-malware, and access control management, including driving findings to closure.
  • Working knowledge of threat modelling and risk assessment applied to cloud architectures and CI/CD pipelines.
  • Experience with AppSec tooling, including CI/CD integration, tuning to reduce noise, and triaging results with engineers.
  • Strong leadership skills, including the ability to educate others and delegate responsibilities across chapters and teams.

Responsibilities

  • We coach and mentor chapter members and support the Head of Platform Engineering with overall chapter management, particularly across partner resources.
  • We design, implement, and automate security controls and security testing within the SDLC.
  • We lead application security practices, ensuring secure design and build, and coordinate effectively between engineering and security teams.
  • We apply Security-as-Code principles by providing training, creating reusable patterns, and establishing best practices for teams.
  • We support the investigation and future implementation of agentic workflows and agents, ensuring proposed solutions are secure by design and comply with our AI governance.
  • We respond swiftly to new and emerging security threats and vulnerabilities, investigate suspected attacks, and help manage security incidents, including post‑incident reviews.

Skills

Azure
GCP
CI/CD
DevOps
Security
Cloud
Microservices
IAM

Tools

Terraform

Job description

Salary: £47,000 - 87,000 per year

Requirements
  • 5+ years of DevOps or Platform Engineering experience delivering solutions in Azure and/or GCP.
  • Full-stack application and infrastructure solution design experience, with robust security controls, high availability, and operational resilience.
  • Working knowledge of vulnerability and compliance management, patch management, endpoint protection or anti-malware, and access control management, including driving findings to closure.
  • Working knowledge of threat modelling and risk assessment applied to cloud architectures and CI/CD pipelines.
  • Experience with AppSec tooling, including CI/CD integration, tuning to reduce noise, and triaging results with engineers.
  • Strong leadership skills, including the ability to educate others and delegate responsibilities across chapters and teams.
  • Experience with Terraform and platform solutions.
  • Experience working on solutions with integrations between GCP and Azure.
  • Knowledge of cloud native, microservices, and containerised systems.
  • Strong desire for continuous improvement and an Agile way of working.
  • Knowledge of the insurance and London Market ecosystem is ideally beneficial; Lloyds market experience is particularly valuable.
  • Proven hands‑on software delivery experience, including platform engineering and/or build, release, and deployment engineering using modern DevOps practices.
  • Experience delivering and operating technology in regulated environments, with an understanding of controls, audit expectations, and evidence-based compliance.
  • Ability to clearly explain processes, patterns, and tooling used to ensure quality, stability, performance, scalability, secure deployment, maintainability, and documentation.
  • Broad awareness of major cloud providers and services, with curiosity to evaluate and adopt capabilities that improve security, reliability, and cost efficiency.
  • Proactive, improvement-focused mindset with the ability to challenge the status quo and drive automation and simplification.
  • Strong delivery focus, able to prioritise effectively and deliver outcomes in a fast‑paced environment with shifting demands.
  • Ability to operate effectively in a small, high‑impact team while collaborating across a wider product and engineering organisation.
  • Excellent communication and stakeholder‑management skills, able to influence at all levels and present complex topics clearly.
  • Comfortable working in ambiguity and adapting quickly as priorities, technology, and threats evolve.
  • Up‑to‑date knowledge of security practices, processes, and tooling, with the judgement to apply emerging approaches pragmatically.
Responsibilities
  • We coach and mentor chapter members and support the Head of Platform Engineering with overall chapter management, particularly across partner resources.
  • We design, implement, and automate security controls and security testing within the SDLC.
  • We lead application security practices, ensuring secure design and build, and coordinate effectively between engineering and security teams.
  • We apply Security-as-Code principles by providing training, creating reusable patterns, and establishing best practices for teams.
  • We support the investigation and future implementation of agentic workflows and agents, ensuring proposed solutions are secure by design and comply with our AI governance.
  • We respond swiftly to new and emerging security threats and vulnerabilities, investigate suspected attacks, and help manage security incidents, including post‑incident reviews.
  • We produce clear, actionable security reporting for senior leadership.
  • We act as the primary point of contact for security‑related inquiries across London Market technology and change initiatives, coordinating with Group, other Business Units, and Cyber teams.
  • We influence key architectural decisions early, balancing business requirements, budgets, security, and resilience.
  • We partner with squads to take solutions from proof of concept through to a production‑ready platform.
  • We build and maintain secure Azure and GCP infrastructure across all environments using Azure DevOps Pipelines and Terraform.
  • We oversee and coach squads on intra‑day deployment mechanisms, advocating for cloud‑informed improvements that increase security, reliability, and delivery speed.
  • We build and maintain monitoring and alerting at all levels, ensuring actionable signals and secure operational practices.
  • We guide multiple Innovation squads and Engineering Chapters, driving cloud‑first adoption and championing secure‑by‑design initiatives.
  • We strengthen our platform security posture through visible leadership and help embed modern DevOps and security ways of working.
  • We may take on people leadership responsibilities, including day‑to‑day management of third‑party security engineers and partner resources.
Technologies
  • AI
  • Azure
  • CI/CD
  • Cloud
  • DevOps
  • GCP
  • Support
  • Security
  • Terraform
  • microservices
  • Embedded
  • IAM
More

We are Hiscox, hiring for a Permanent Principal Platform Security Engineer for our London Market. This is a senior role within our London Platform Engineering Chapter, spanning Platform, DevOps, and Site Reliability Engineering, with a core focus on continuous improvement across our cloud and on-premises platforms. We offer the opportunity to make a real difference during a period of focused growth, working with amazing people in a unique culture that values diversity and inclusion. The role is based in York, Lisbon, or London and is full time.

last updated 36 week of 2026

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Platform Security Engineer
Principal Platform Security Engineer

Hiscox • York and North Yorkshire

On-site
GBP 80,000 - 100,000
Cloud Platform Security Lead
Cloud Platform Security Lead

AXA Group • Tunbridge Wells

Hybrid
GBP 68,000 - 108,000
Principal Platform Security Engineer
Principal Platform Security Engineer

Hiscox SA • Greater London

Hybrid
GBP 80,000 - 100,000
Diversity and inclusion culture
Employee benefits for wellbeing
Lead Platform Security Engineer (Cloud & DevSecOps)
Lead Platform Security Engineer (Cloud & DevSecOps)

Hiscox SA • Greater London

Hybrid
GBP 80,000 - 100,000
Diversity and inclusion culture
Employee benefits for wellbeing
Senior Platform Security Engineer - Cloud & DevOps
Senior Platform Security Engineer - Cloud & DevOps

Hiscox AG • York and North Yorkshire

Hybrid
GBP 47,000 - 87,000
Senior Engineer
Senior Engineer

Back TO Work • City of Westminster

On-site
GBP 90,000 - 100,000
Platform Security & Compliance Lead | Southwest, London | Hybrid, Permanent
Platform Security & Compliance Lead | Southwest, London | Hybrid, Permanent

MRP-Global • Greater London

Hybrid
GBP 110,000 - 140,000
Principal Platform Engineer - Yeovil
Principal Platform Engineer - Yeovil

Hackajob Ltd • Yeovil

Hybrid
GBP 63,000 - 77,000
Pension scheme
Flexible hours
12 flexi-days per year
+4
Senior Platform Engineer Cheltenham
Senior Platform Engineer Cheltenham

CloudSecure Ltd. • Cheltenham

Hybrid
GBP 85,000 - 110,000
Competitive salary
Bonus and options scheme
Flexible working arrangements
+2
Senior Software Engineer
Senior Software Engineer

Hiscox AG • York and North Yorkshire

On-site
GBP 47,000 - 87,000