Senior Principal, Cloud Engineering

Forterro

United Kingdom

Hybrid

GBP 120,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Forterro seeks a Senior DevSecOps Engineer to close the operational gap between security tooling, platform automation and CloudOps execution across a multi-product AWS SaaS estate. This hands-on role works within Cloud Platform to implement controls via infrastructure-as-code, GitOps workflows, CI/CD pipelines and runbooks.

You will own cloud workload protection, vulnerability and patch management automation, network perimeter controls, container and serverless security, and deployment health

Qualifications

  • 5+ years hands-on experience in DevSecOps, Cloud Security Engineering, Platform Engineering or senior cloud engineering roles.
  • Proficient with infrastructure-as-code, GitOps and CI/CD tooling.
  • Strong knowledge of AWS security architecture and services.

Responsibilities

  • Design, implement and maintain AWS security controls across IAM, networking, encryption, logging, account governance and guardrails.
  • Implement and maintain AWS-native security services and governance patterns.
  • Harden AWS accounts, services and workloads against CIS Benchmarks and Forterro baselines.
  • Translate security requirements into infrastructure-as-code, policy-as-code and reusable automation modules.
  • Own the reliable deployment, configuration and operational health of security tooling across cloud and workload environments.
  • Ensure CrowdStrike Falcon endpoint and cloud workload protection is deployed and reporting correctly.
  • Ensure Tenable scanning coverage is complete with remediation workflows and evidence reporting.
  • Operate and improve ManageEngine-based patch tooling and workflows.
  • Troubleshoot failed security-tool deployments and configuration drift across IAM, networking, Kubernetes, host agents, APIs, CI/CD and platform automation.

Skills

DevSecOps
Cloud security
GitOps
CI/CD
Kubernetes
AWS
SRE

Education

AWS Certified Security – Specialty
CKS / CISSP / CCSP / GIAC
Terraform Associate

Tools

CrowdStrike
Tenable
ManageEngine
Fortinet
Cloudflare
AWS security services

Job description

Senior Principal, Cloud Engineering

Department: Cloud Platform

Employment Type: Permanent

Location: Royaume-Uni, Remote


Description

Forterro is seeking a Senior DevSecOps Engineer to close the operational gap between Security tooling requirements, Platform automation and CloudOps execution across a multi-product AWS SaaS estate. This is a hands‑on engineering role responsible for making security controls deployable, repeatable, measurable and operationally reliable.
The role is a dedicated for Security function but embedded within the Cloud Platform / Platform Engineering team so that it has the practical authority to implement controls through infrastructure‑as‑code, GitOps workflows, CI/CD pipelines and operational runbooks. Security will define risk, policy and control intent; Platform will provide automation patterns; CloudOps will maintain and patch operational systems; this role owns the bridge between those teams and ensures security tooling and configuration are successfully implemented and handed over.
You will take hands‑on ownership of cloud workload protection, vulnerability and patch management automation, network perimeter controls, container and serverless security, and deployment health for security tooling such as CrowdStrike, Tenable, ManageEngine, Fortinet, Cloudflare and AWS‑native security services. The role must close the gap by turning security requirements into working automation, verified configuration and clear operational acceptance criteria.


Responsibilities
  • Design, implement and maintain AWS security controls across IAM, networking, encryption, logging, account governance and guardrails.
  • Implement and maintain AWS‑native security services and governance patterns, including AWS Organizations, Control Tower, Service Control Policies, IAM Access Analyzer, Security Hub, GuardDuty, Inspector, Config, CloudTrail, KMS and centralised logging where applicable.
  • Harden AWS accounts, services and workloads against CIS Benchmarks and Forterro security baselines, including documented exception and waiver processes for product‑specific differences.
  • Translate security requirements into infrastructure‑as‑code, policy‑as‑code and reusable automation modules that can be deployed consistently across multiple products and environments.
  • Own the reliable deployment, configuration and operational health of security tooling across cloud and workload environments.
  • Ensure CrowdStrike Falcon endpoint and cloud workload protection is deployed, healthy, version‑compliant and reporting correctly, including failed agent deployment remediation and coverage reporting.
  • Ensure Tenable scanning coverage is complete and reliable across cloud assets, with remediation workflows, exception handling and evidence reporting agreed with the Security team.
  • Operate and improve ManageEngine‑based patch tooling and workflows, ensuring patch automation, compliance reporting, failure handling and maintenance windows are clear and repeatable.
  • Troubleshoot failed security‑tool deployments and configuration drift across IAM, networking, Kubernetes, host agents, APIs, CI/CD and platform automation.
  • Operationalise vulnerability and patch management processes across the AWS estate, ensuring scan coverage, triage, remediation ownership and closure tracking are measurable.
  • Define, automate and report patch SLAs based on severity, asset criticality and business impact, including exception handling, rollback evidence and stakeholder communication.
  • Work with Security to prioritise risk and with CloudOps/Product teams to execute remediation safely through approved change‑control processes.
  • Create dashboards and reports for patch compliance, vulnerability ageing, failed deployments, risk acceptance and remediation trends.
  • Implement, maintain and audit Fortinet firewall controls, including rule sets, segmentation, VPNs, policy reviews and configuration validation under change control.
  • Manage and validate Cloudflare services including WAF, DNS, CDN, DDoS protection and Zero Trust / access policies, using configuration‑as‑code where practical.
  • Partner with Security on policy intent while ensuring configuration is implemented accurately, tested and operationally supportable.
  • Secure and harden Kubernetes clusters, including Amazon EKS, RBAC, network policies, admission controls, secrets management, runtime controls and image provenance.
  • Integrate container image scanning, registry scanning, software composition analysis, secrets scanning and SBOM generation into CI/CD and runtime processes.
  • Establish and enforce baseline configurations and CIS Kubernetes Benchmark compliance using policy‑as‑code tooling such as OPA/Gatekeeper or Kyverno where appropriate.
  • Secure AWS Lambda and event‑driven serverless services through least‑privilege execution roles, dependency and code scanning, runtime monitoring, event‑source control and API Gateway/WAF guardrails.
  • Implement and maintain infrastructure‑as‑code and automation using Terraform, Crossplane, CloudFormation where required, Ansible, Helm, Python, Bash/PowerShell and YAML.
  • Integrate security controls into GitLab CI/CD and GitOps workflows such as ArgoCD, including SAST, SCA, secrets scanning, IaC scanning, container scanning, policy gates and exception workflows.
  • Automate routine security operations including scanning, patch orchestration, configuration drift detection, evidence gathering and compliance reporting.
  • Convert repeatable runbooks into idempotent automation and reusable deployment patterns that CloudOps and product teams can consume safely.
  • Create clear runbooks, operational acceptance criteria, handover packs, service documentation, diagrams and support guidance for CloudOps and product teams.
  • Define and maintain a practical RACI for security tooling deployment and operation, reducing ambiguity between Security, Platform, CloudOps and product teams.
  • Participate in incident response and post‑incident reviews where security tooling, control failures, vulnerability exposure or patch failures are involved.
  • Mentor engineers on secure practices and support continuous improvement across Platform Engineering, CloudOps and product delivery teams.
  • Evaluate new security technologies and products, produce evaluation reports, and recommend improvements aligned to business risk and SaaS platform strategy.

Skills, Knowledge & Expertise
  • 5+ years of hands‑on experience in DevSecOps, Cloud Security Engineering, Platform Engineering, SRE or senior cloud engineering roles.
  • Strong working knowledge of AWS security architecture and services, including IAM, networking, encryption, logging, Organizations/SCPs, Security Hub, GuardDuty, Inspector, Config, CloudTrail and KMS.
  • Practical experience deploying, configuring or operating security tools such as CrowdStrike, Tenable, ManageEngine, Fortinet firewalls and Cloudflare.
  • Strong experience with infrastructure‑as‑code, GitOps and CI/CD tooling such as Terraform, CloudFormation, Ansible, Helm, ArgoCD, GitLab CI/CD and Git.
  • Proficiency with scripting and automation using Python, Bash, PowerShell and YAML.
  • Experience securing Kubernetes/EKS, container platforms and serverless workloads, including RBAC, network policies, admission controls, image scanning, secrets management and runtime monitoring.
  • Solid grasp of vulnerability management, patch management, risk‑based remediation, change control, SLAs and compliance evidence.
  • Hands‑on ability to troubleshoot failed automation, configuration drift and deployment failures across cloud, network, endpoint, Kubernetes and CI/CD layers.
  • Experience operating in a multi‑team, multi‑product SaaS or enterprise cloud environment.
  • Excellent communication, stakeholder management and ownership mindset, with the ability to reduce ambiguity between Security, Platform, CloudOps and product teams.
  • Relevant certifications such as AWS Certified Security - Specialty, Certified Kubernetes Security Specialist (CKS), CISSP, CCSP, GIAC, Terraform Associate or equivalent experience.
  • Experience with SIEM/SOAR platforms, security incident response and threat‑informed remediation.
  • Familiarity with compliance frameworks such as ISO 27001, SOC 2, NIST and CIS.
  • Experience implementing policy‑as‑code
  • Experience in SaaS platform standardisation, shared services, mergers/acquisitions integration or multi‑account AWS governance.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cloud Security Engineer
Cloud Security Engineer

The French Sourcer • Greater London

Hybrid
GBP 70,000 - 110,000
Private health cover
Pension contribution
Equity plan
+1
Cloud Platform Security Engineer Software engineering London
Cloud Platform Security Engineer Software engineering London

Checkout Ltd • Greater London

Hybrid
GBP 75,000 - 100,000
Flexible working hours
Opportunities for growth and development
Security Platform Engineering Manager
Security Platform Engineering Manager

ISS • Greater London

Hybrid
GBP 84,000 - 100,000
Car allowance
Bupa health insurance
Matched pension contributions
Senior Cloud Security Analyst
Senior Cloud Security Analyst

MCS Group • Belfast City District

On-site
GBP 70,000 - 90,000
Senior DevSecOps Architect – Cloud Security & Automation
Senior DevSecOps Architect – Cloud Security & Automation

Forterro • United Kingdom

Hybrid
GBP 120,000 - 170,000
Senior Security Engineer
Senior Security Engineer

Intropic • Greater London

Hybrid
GBP 110,000 - 150,000
AWS Security & Cloud Platform Consultant
AWS Security & Cloud Platform Consultant

Kryptos Technologies limited • Greater London

On-site
GBP 111,000 - 221,000
Lead Engineer
Lead Engineer

Queen Square Recruitment • Sheffield

On-site
GBP 85,000 - 125,000
Senior Security Engineer
Senior Security Engineer

Sanderson • Greater London

On-site
GBP 70,000 - 90,000
Senior Security Consultant (Platform Security Engineer) - Permanent
Senior Security Consultant (Platform Security Engineer) - Permanent

RiverSafe • Greater London

Hybrid
GBP 90,000 - 140,000