Security Engineer: Secure-by-Design Cloud & IAM

Surevine Limited

Greater London

Hybrid

GBP 65,000 - 90,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Surevine Limited is seeking a security-focused professional to own security across our corporate estate and collaborate with engineering teams on secure-by-design solutions. The role offers growth into customer-facing work and the chance to influence security posture early in product development.

You will engage with governance, risk management, and client assurance while supporting automated controls and security reviews across our AWS-hosted environments and SaaS stack.

Qualifications

  • 3-5 years experience in security, security risk, or a related technology role.
  • Working knowledge of ISO 27001, Cyber Essentials and comparable frameworks as a practitioner who has implemented controls, not only assessed them.
  • Some exposure to cloud and SaaS security; identity and access management, logging, configuration hardening etc. and an appetite to take that further.
  • Comfortable thinking about security risk end to end; spotting it, getting it owned by the right person, tracking what happens next, and reporting it honestly to people who will act on it.
  • Credible with engineers. You will be advising people who build secure systems for a living, so you need to be curious about how they work and specific about what you're asking for.
  • Comfortable facilitating a room; design workshops, threat modelling sessions, risk reviews
  • Able to explain security trade-offs to engineers, to executives and to customers, and to adjust the explanation for each
  • Security-conscious pragmatism. We need someone who can tell the difference between a risk worth stopping for and a risk worth documenting and moving past
  • Able to communicate effectively in a remote environment through written and verbal channels.

Responsibilities

  • Take ownership of security across our corporate estate — our SaaS applications, our identity provider, our endpoints and our AWS-hosted environments — driving the plan and getting stuck into the work alongside our InfraCare team
  • Make our ISO27001 and Cyber Essentials obligations business-as-usual; automated where it can be and evidenced as a by-product of how we work
  • Help us build the visibility we need: logging, monitoring and alerting good enough that we find out about problems ourselves rather than being told about them
  • Take part in security reviews and help our engineers run their own
  • Play a leading role when something goes wrong: running the process, knowing when to escape, and liaising with clients, internal teams and support partners
  • Advise our engineering teams on the security of what we build; contributing to design workshops, challenging assumptions early, and helping teams reach good security decisions without stalling delivery
  • Own our security risk picture and make it useful: understood by the board, owned by the people who can act on it, and reviewed often enough to mean something
  • Be the person who answers hard security questions from customers, prospects and their assurance teams — security questionnaires, supplier assessments, and the evidence behind our claims

Skills

Security risk
ISO 27001
Cyber Essentials
Cloud security
Threat modelling
Security architecture
Security reviews

Job description

Surevine Limited is seeking a security-focused professional to own security across our corporate estate and collaborate with engineering teams on secure-by-design solutions. The role offers growth into customer-facing work and the chance to influence security posture early in product development.

You will engage with governance, risk management, and client assurance while supporting automated controls and security reviews across our AWS-hosted environments and SaaS stack.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Surevine Limited • Greater London

Hybrid
GBP 65,000 - 90,000
Cloud Security Engineer - Azure | SIEM & Threat Defense
Cloud Security Engineer - Azure | SIEM & Threat Defense

Computershare • West of England

Hybrid
GBP 28,000 - 45,000
Flexible working
Hybrid role (Bristol/Edinburgh)
Health and wellbeing rewards
+3
Lead Security Engineer: Own Cloud & Incident Response
Lead Security Engineer: Own Cloud & Incident Response

Understanding Recruitment • Greater London

Hybrid
GBP 110,000 - 150,000
Hybrid working
London office access
Autonomy and ownership
+2
Security Infra Engineer: Build Secure, Resilient Cloud
Security Infra Engineer: Build Secure, Resilient Cloud

Surrey Satellite Technology • Guildford

On-site
GBP 33,000 - 73,000
Lead Security Architect — Cloud, Data & DevSecOps
Lead Security Architect — Cloud, Data & DevSecOps

Artificial • United Kingdom

On-site
GBP 110,000 - 140,000
Private medical insurance
Income protection
Company stock options
+2
Security-Focused Infrastructure Engineer (Cloud)
Security-Focused Infrastructure Engineer (Cloud)

IT Talent Solutions Ltd • England

On-site
GBP 50,000 - 75,000
Senior Secure Infrastructure Engineer: Cloud & DevSecOps
Senior Secure Infrastructure Engineer: Cloud & DevSecOps

Addition • Farnborough

On-site
GBP 65,000 - 90,000
Competitive pension contribution
Bonus scheme
Private medical cover
+2
Senior Security Engineer
Senior Security Engineer

Sanderson • Greater London

On-site
GBP 70,000 - 90,000
Secure Cloud Platform Engineer | DevSecOps & SRE
Secure Cloud Platform Engineer | DevSecOps & SRE

Envitia Group • Cheltenham, Greater London, Manchester

Hybrid
GBP 70,000 - 100,000
Annual Leave: 25 days + birthday off
Private Healthcare Coverage
Training & Skills Development
+6
Senior Security Engineer: IAM, Cloud Security & Automation
Senior Security Engineer: IAM, Cloud Security & Automation

SLAMcore • Greater London

Hybrid
GBP 90,000 - 150,000
Paid Time Off
Medical Insurance
Life Insurance
+2