Senior Cloud Security Engineer (Automation & Tooling) - Engine by Starling

Starling

Greater London

On-site

GBP 60,000 - 80,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

33 days holiday including public holidays
Annual leave increases with service
Private Medical Insurance
Paid volunteering time
Life insurance at 4x salary

Job summary

A leading financial technology company in Greater London seeks a Cloud Security Engineer to enhance their security infrastructure. The role involves automating compliance processes using Go, managing identity and infrastructure on AWS and GCP, and ensuring strong Kubernetes security. Ideal candidates will have software engineering backgrounds with expertise in cloud security. Enjoy 33 days of holiday and various employee benefits including private health insurance and volunteering time.

Qualifications

  • Experience managing AWS or GCP at scale using Terraform.
  • Knowledge of Kubernetes security from runtime to service mesh.
  • Familiarity with container signing tools such as Sigstore.

Responsibilities

  • Design and maintain custom security tooling in Go.
  • Write and peer-review Terraform for AWS and GCP.
  • Contribute to CI/CD by integrating security tools.

Skills

Software or infrastructure engineering background
Proficiency in Go or Python
Experience securing AWS or GCP
Understanding of Kubernetes security
Expert knowledge of cloud identity models
Strong understanding of network protocols

Tools

Terraform
Kubernetes

Job description

About Engineering at Engine by Starling - https://www.enginebystarling.com/

The Mission

This is a highly varied position where you will spearhead efforts to fortify both our infrastructure and application platforms. Your mission is to solve complex security problems through code, focusing on three core pillars:

  • Identity & Network Security: Engineering robust IAM controls and zero-trust network architectures. You will lead the way in refining edge-defense strategies and trust redirection to ensure every request is verified and encrypted
  • Unified Vulnerability Orchestration: Building a custom "single pane of glass" for security data. You will engineer API integrations between scanning engines, dependency trackers, and internal portals to create a seamless, automated vulnerability ecosystem
  • Compliance as Code: Bridging the gap between technical execution and regulatory requirements. You will build the automated systems that provide real-time evidence for frameworks like SOC 2, ISO 27001 & PCI ensuring we stay compliant without manual overhead
The Team

You will be a key member of our growing Security Engineering team, working at the intersection of our Infrastructure, Cross-Cutting, Information Security, and GRC teams. At Engine, we believe security should be at the heart of every technical process, not an afterthought. You won’t work in a silo; you’ll have close interaction with engineers across the business to deliver a platform that is resilient against evolving threats.

About You

We are primarily looking for experienced Cloud Security Engineers, but we are equally keen to talk to talented Software Engineers who possess strong programming skills and a genuine desire to apply their knowledge to security challenges.

Engine engineers are motivated by impact and high-quality delivery, regardless of their original tech stack. Whether you are a security specialist or a developer with a "security-first" mindset, your place within the team will be shaped by your individual strengths and interests.

What you’ll get to do?

You won’t be manually checking boxes. You will be building the systems that check them for you.

  • Security as Code: Design and maintain custom security tooling in Go to automate evidence collection for SOC2/ISO 27001 and remediation of security alerts
  • Infrastructure & IAM: Write and peer-review Terraform to manage identity and core infrastructure across AWS and GCP, ensuring the principle of least privilege is baked into the foundation and adhering to cloud security standards
  • Pipeline & Supply Chain: Contribute to maintaining the integrity of our software supply chain. You\'ll integrate SAST/DAST/SCA tools into our CI/CD pipelines (GitHub Actions/TeamCity) and manage container provenance
  • Cloud Native Defense: Engineer Kubernetes security solutions focusing on Cilium, RBAC, and network policies to protect our microservices
  • Identity & Trust (PKI): Build and maintain our Certificate Authority (CA) tooling and internal PKI infrastructure. You will be a trusted guardian of our cryptographic foundations, participating in Key Ceremonies to ensure the highest level of root-level security
  • Incident Response & Research: Support the Information Security team and participate in incident response and post-mortem activities
Requirements

What skills are essential:

  • The Builder Mindset: You have a background in software or infrastructure engineering. You find manual work a personal affront and prefer to solve problems through code
  • Polyglot-ish: You are proficient in Go (our preference) or Python
  • Cloud Native: You have deep, practical experience securing AWS or GCP and have managed them at scale using Terraform
  • Container Expert: You understand the nuances of Kubernetes security - from the runtime to the service mesh
  • Identity Mastery: Expert knowledge of cloud identity models
  • Networking: Strong understanding of network protocols.
  • What skills are desirable: Experience with Cilium networking or advanced K8s hardening (CKS/CKA)
  • Deep knowledge of cryptography management and hardware security modules
  • Familiarity with container signing (Sigstore/Cosign) and image provenance
  • Cloud-native security certifications (AWS Security Specialist / GCP Professional)
  • Experience working with CSA CCM
Benefits
  • 33 days holiday (including public holidays, which you can take when it works best for you)
  • An extra day\'s holiday for your birthday
  • Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off
  • 16 hours paid volunteering time a year
  • Salary sacrifice, company enhanced pension scheme
  • Life insurance at 4x your salary & group income protection
  • Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton
  • Generous family-friendly policies
  • Incentives refer a friend scheme
  • Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks
  • Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cloud Security Engineer (GCP) - Engine by Starling
Senior Cloud Security Engineer (GCP) - Engine by Starling

Starling • City Of London

On-site
GBP 120,000 - 150,000
33 days holiday
Birthday leave
Pension scheme
+1
Senior Cloud Security Engineer (GCP) - Engine by Starling
Senior Cloud Security Engineer (GCP) - Engine by Starling

Engine by Starling • Greater London

On-site
GBP 100,000 - 150,000
33 days holiday
Private Medical Insurance
Cycle to Work
+1
Staff Cloud Security Engineer (GCP) - Engine by Starling
Staff Cloud Security Engineer (GCP) - Engine by Starling

Starling Bank • Greater London

On-site
GBP 90,000 - 130,000
33 days holiday
Birthday leave
Pension scheme
+2
Staff Cloud Security Engineer (GCP) - Engine by Starling
Staff Cloud Security Engineer (GCP) - Engine by Starling

Engine by Starling • Greater London

On-site
GBP 90,000 - 120,000
33 days holiday
Birthday day off
Pension scheme
+3
Senior Cloud Security Engineer (GCP) - Engine by Starling
Senior Cloud Security Engineer (GCP) - Engine by Starling

Starling • Greater London

On-site
GBP 90,000 - 150,000
Private Medical Insurance
Pension scheme
Life insurance
+5
Staff Cloud Security Engineer (GCP) - Engine by Starling
Staff Cloud Security Engineer (GCP) - Engine by Starling

Starling • Greater London

On-site
GBP 110,000 - 170,000
Private Medical Insurance
Pension scheme
Cycle to Work
Staff Cloud Security Engineer
Staff Cloud Security Engineer

Engine by Starling • Greater London

Hybrid
GBP 90,000 - 150,000
Principal Security Programme Manager & Technical Lead - Engine by Starling
Principal Security Programme Manager & Technical Lead - Engine by Starling

Engine By Starling Limited • Greater London

Hybrid
GBP 110,000 - 150,000
33 days holiday
Birthday day off
Pension scheme
+2
Senior Infrastructure Engineer (GCP) - Engine by Starling
Senior Infrastructure Engineer (GCP) - Engine by Starling

Starling Bank • Greater London

On-site
GBP 90,000 - 140,000
33 days holiday
Birthday holiday
Private Medical Insurance
+2
Senior Cloud Security Engineer (GCP) - Engine by Starling
Senior Cloud Security Engineer (GCP) - Engine by Starling

Starling Bank • Greater London

On-site
GBP 90,000 - 120,000