Security Lead

LocalStack

Indiana

Hybrid

GBP 60,000 - 85,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Fully remote
Competitive salary
Annual company retreat
Extra company-wide holidays
Inclusive workplace culture

Job summary

A growing tech startup in the UK is seeking a Security Engineer to ensure a robust security posture across products and lead vendor risk assessments. This role requires 7+ years of experience in security engineering, a background in DevSecOps, and the ability to document complex subjects clearly. Benefits include fully remote work and a competitive salary.

Qualifications

  • 7+ years in security engineering or compliance role.
  • Experience leading vendor risk assessments and building compliance frameworks.
  • Strong background in API design and DevSecOps.

Responsibilities

  • Ensure robust security posture of our product.
  • Lead initiatives for incident monitoring and vulnerability management.
  • Define and implement security auditing procedures.

Skills

Threat modeling
Vulnerability management
Incident monitoring
Intrusion detection
Documentation skills
Risk-based decision-making

Education

Expert knowledge of cloud security
Good knowledge of SOC 2, ISO 27001, GDPR

Tools

AWS
Linux/Unix OS hardening tools

Job description

Overview

We are a fast-growing Series A startup building cutting-edge technology to revolutionize cloud development processes and support highly efficient dev&test feedback loops. LocalStack provides a high-fidelity emulator and local cloud development platform. Our mission is to empower developers to rapidly build and test their cloud applications, allowing for a more enjoyable dev experience, and saving valuable time and resources. LocalStack is headquartered in Zurich/Switzerland, with a main engineering office in Vienna/Austria and remote team members from the US, FR, UK, CA, ES, and many more countries. We have a large open-source community (57k+ GitHub stars), 100k+ active users, and 290M+ downloads to date.


This is the right opportunity for a person with 7+ years in a security engineering or security compliance role, experience leading vendor risk assessments and building compliance frameworks from the ground up, a strong background in API design and build, as well as a strong background in DevSecOps, incident response, and pragmatic, risk-driven security leadership.


We are looking for a candidate who can contribute to our globally distributed team and join us in shaping the future of cloud development.



Responsibilities


  • Ensure robust security posture of our product, across the various components (in particular, the LocalStack emulators, the LocalStack Cloud platform, as well as our data warehouse)

  • Lead initiatives for incident monitoring, intrusion detection, and vulnerability management

  • Define and implement regular security auditing procedures across systems and access controls

  • Deliver a sustainable, scalable process for vendor risk assessments and other security-related initiatives (e.g., via tooling, delegation, or automation) including completing and submitting vendor risk assessments to support our sales process

  • Ensure secure configurations and permission models, while collaborating with the engineering teams

  • Identify gaps between claimed and actual compliance and propose/lead corrective actions

  • Own documentation of security controls, configurations, and policies

  • Engage with internal stakeholders to evaluate different security threats and attack vectors

  • Generate and distribute internal audit and compliance reports at regular intervals



Experience and qualifications


  • Expert knowledge of threat modelling, vulnerability management, and tools like intrusion detection, network security, or Linux/Unix OS hardening

  • Practical experience with cloud security (AWS preferred)

  • Good knowledge of common standards (e.g., SOC 2, ISO 27001, GDPR)

  • Strong documentation skills and ability to make complex topics accessible to non-experts

  • Good understanding of US and EU security and compliance expectations

  • Prior engineering experience strongly preferred (even if no longer coding daily)

  • Proactive, pragmatic, and capable of risk-based decision-making



Values we hold at LocalStack


  • care: we create with compassion. We prioritize empathy and understanding in every interaction. By genuinely caring for our team, customers, and community, we create an environment where people thrive and impactful work flourishes.

  • ownership: we own the outcome. We take responsibility for our work and are passionate about its impact. We foster autonomy, inspire ambition, encourage ownership, and empower everyone to unlock their potential and make an impact.

  • openness: we build trust together. We build trust through open communication and honest feedback. By sharing ideas and embracing diverse perspectives, we create stronger, more connected teams that work toward shared goals.

  • courage: we dare to innovate. We embrace bold challenges and take calculated risks to move the needle. We step outside our comfort zones, experiment fearlessly, and turn setbacks into springboards for growth.

  • excellence: we chase the extraordinary. We push boundaries and deliver results that go beyond the ordinary, constantly raising the bar and delivering exceptional value.



Benefits


  • Fully remote

  • Competitive salary

  • Annual company retreat

  • 2 extra company-wide holidays

  • Friendly and inclusive workplace culture (community guilds and online company events)



To apply, follow the LI application process or apply on our career page. Please include a short motivation outlining why you are the perfect candidate for this role. If your profile matches, we will be in touch to organize the next steps within 2 weeks.


Note: due to a high volume of candidates, we cannot offer personalized feedback to every candidate.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior DevOps Engineer
Senior DevOps Engineer

LocalStack • Greater London

Remote
GBP 90,000 - 140,000
Fully remote
Competitive salary
Annual company retreat
+3
Senior Software Engineer (Systems Engineering)
Senior Software Engineer (Systems Engineering)

LocalStack • City Of London

On-site
GBP 60,000 - 80,000
Fully remote
Competitive salary
Professional development opportunities
+2
Senior DevOps Engineer
Senior DevOps Engineer

LocalStack • United Kingdom

Remote
GBP 89,000 - 133,000
Director of Platform Engineering
Director of Platform Engineering

LocalStack • United Kingdom

On-site
GBP 85,000 - 120,000
Fully remote
Competitive salary
Annual company retreat
+2
Senior Cloud Infrastructure Engineer (cloud sandboxes)
Senior Cloud Infrastructure Engineer (cloud sandboxes)

LocalStack • Greater London

On-site
GBP 36,000 - 67,000
Fully remote
Competitive salary
Annual retreat
+2
Senior Product Engineer (GCP)
Senior Product Engineer (GCP)

LocalStack • Greater London

Remote
GBP 36,000 - 67,000
Fully remote
Annual company retreat
2 extra company-wide holidays
+1
Information Security Governance Specialist
Information Security Governance Specialist

Frontify • Greater London

On-site
GBP 90,000 - 140,000
Private health benefits
Pension scheme
25 days annual leave
+4
Lead Security Engineer
Lead Security Engineer

Eeze • Greater London

On-site
GBP 80,000 - 100,000
26 days paid holiday
Hybrid Working
Pension and Life Assurance
+2
Senior Security Operations Engineer New London
Senior Security Operations Engineer New London

Risk Ledger • Greater London

On-site
GBP 90,000 - 135,000
EMI equity
Healthcare AXA
Hybrid working policy
+3
Security Engineer
Security Engineer

StackOne Technologies Limited • Greater London

On-site
GBP 70,000 - 90,000
Meaningful share options
25 days holiday + additional days per year
Private health insurance
+6