What You’ll Do
- You will own and evolve the security posture of our cloud‑native data platform, focusing on protecting data in containerised Python services on AWS.
- You will partner with Data Engineering and Data Science teams to deliver secure‑by‑default DevOps, DataOps, MLOps and AIOps workloads, creating guardrails, automation and observability that scale.
- You will help shape a medium‑term path to support Azure, ensuring security controls, IaC patterns and CI/CD pipelines are portable across clouds.
- Design and implement security controls for containerised Python applications across build, deploy and runtime (image hardening, least privilege, network policies, secrets management, vulnerability management).
- Embed security into CI/CD by building automated checks (SAST, dependency scanning, IaC scanning, container scanning) and enforcing policy‑as‑code.
- Secure our AWS footprint using Infrastructure as Code: IAM design, account/environment separation, encryption standards, private networking and service control guardrails.
- Own database security across our data stores (Postgres/Redshift), including access models, row/column‑level controls, encryption, key management, auditing, patching and backup/restore security.
- Implement end‑to‑end data protection controls: encryption in transit/at rest, data classification, tokenisation/masking and secure data sharing patterns for analytics and ML.
- Build security observability: centralised logging, security monitoring, alerting and incident runbooks for cloud, containers and data platforms.
- Enable secure MLOps/DataOps practices: protect model artefacts, feature/data pipelines, support secure compute for training/inference and guide teams on secure coding and threat modelling.
- Create practical security standards and documentation, mentor engineers and partner with stakeholders to balance risk, delivery speed and operational reliability.
- Build cloud‑agnostic security patterns to support a potential move to Azure (e.g., mapping IAM to Entra ID, KMS to Key Vault, container services to AKS).
What You’ll Bring
- Significant experience in DevSecOps/SRE/Platform Engineering roles, taking ownership of security outcomes for cloud‑native systems in production.
- Strong hands‑on AWS experience (identity, networking, encryption and logging primitives) and an interest to extend controls to Azure over time.
- Deep knowledge of containers and orchestration (Docker, Kubernetes/EKS or ECS), secure configuration, runtime hardening and network isolation.
- Proficiency with Infrastructure as Code (Terraform/CloudFormation) and CI/CD, implementing policy‑as‑code and security automation.
- Strong Python skills and familiarity with secure software engineering practices for backend services.
- Strong SQL fundamentals and proven experience securing relational databases (Postgres) and analytical warehouses (Redshift), including auditing and access control design.
- Experience with secrets management and key management (AWS Secrets Manager/SSM, KMS, and understanding of Azure Key Vault), and designing rotation and break‑glass processes.
- Hands‑on experience with security tooling and practices such as SAST, SCA, container vulnerability scanning, IaC scanning and runtime detection integrated into developer workflows.
- Experience operating production platforms: monitoring/alerting, incident response, post‑incident reviews and designing for resilience.
- Knowledge of data governance and security concepts (data classification, retention, privacy‑by‑design) and how to implement them in cloud‑native architectures.
- Strong problem‑solving and systems‑thinking skills, assessing risk, prioritising remediation and delivering improvements iteratively.
- Comfortable partnering with Data Engineering and Data Science teams, translating security requirements into pragmatic controls without blocking delivery.
- Strong documentation and communication skills, influencing stakeholders and raising security maturity of engineering teams.
- Experience defining standards and mentoring others (security champion models, enablement sessions, self‑service improvements).
- Bonus: experience securing data/ML platforms (SageMaker, Databricks, feature stores, model registries) and understanding of MLOps/AIOps operational patterns.
Tech Stack
AWS (ECS/EKS, IAM, VPC, KMS, S3, CloudWatch/CloudTrail, Lambda, Redshift, SageMaker); Azure (AKS, Key Vault, Entra ID, Databricks); Containers & orchestration (Docker, Kubernetes); Databases (Postgres, Redshift); Infrastructure & delivery (Terraform/CloudFormation, CI/CD pipelines, Git workflows); Security & observability (secrets management, vulnerability scanning, policy‑as‑code, central logging/monitoring).
Equality of Opportunity
We want to create an equality of opportunity in a fair and supportive working environment where people feel included, accepted and allowed to flourish, and where mental health and well‑being are considered. We are committed to diversity, equity and inclusion in all aspects of employment.