Security Engineer
stackone · London
Job description
About the role
We’re looking for a Security Engineer to be a key hire on our Engineering team and own our cloud and product security posture as we scale. You’ll work across our AWS and Cloudflare estate, harden our secure SDLC, run pen testing efforts end‑to‑end, and threat‑model the features powering our connectors, OAuth flows, and agent execution paths.
Key responsibilities
- Own the secure SDLC: drive SAST, dependency scanning, secrets detection, and PR‑blocking standards across every repository.
- Harden our AWS and Cloudflare estate: IAM, secrets, network segmentation, KMS, WAF, GuardDuty, and zero‑trust patterns.
- Run pen testing end‑to‑end: scope and coordinate engagements with AI‑driven scanners and human researchers, then drive findings through fix and retest.
- Threat‑model product features before they ship, including new Auth providers, multi‑tenant APIs, connector executions, and agent tool‑calling paths.
- Build detection and response capability around credential and authentication flows, with observability that closes incidents fast.
- Partner with engineering to raise the bar day‑to‑day: architecture reviews, written standards, and security embedded in code review.
- Use LLMs and agents to accelerate security workflows (triage, code review, evidence gathering) with trusted guardrails.
- Support compliance work intersecting security engineering: SOC 2, ISO 27001, customer security reviews, and pen‑test responses.
Required profile
- 3+ years in security engineering with hands‑on AWS security (IAM, KMS, GuardDuty, etc.).
- Strong coding ability in TypeScript, Python or Go and experience shipping production code.
- Application‑security fluency: OWASP Top 10, threat modeling, and code‑level reviews.
- Experience securing a B2B SaaS multi‑tenant production environment.
- Comfort owning end‑to‑end work from scope to delivery without waiting in a queue.
- Bias toward automating security checks rather than manual checklists.
Required skills
- AWS (IAM, KMS, GuardDuty, Security Hub, etc.)
- Cloudflare (Workers, WAF, Zero Trust)
- Infrastructure as Code: AWS CDK, Terraform
- Programming languages: TypeScript, Python, Go
- SAST/DAST tools (Aikido) and CI/CD pipelines
- OWASP Top 10, threat modeling, pen testing
- Compliance frameworks: SOC 2, ISO 27001
- GitHub Advanced Security, 1Password
What we offer
- Meaningful share options (EMI) and a fast‑growing startup environment.
- Hybrid working with flexible hours and at least two days per week in our London office.
- 25 days holiday plus an extra day per year of tenure.
- Private health insurance covering dental and optical.
- £15/day lunch budget in the office and up to £180/month.
- £1,000 home‑office setup allowance plus £500 yearly top‑up.
- Health, fitness and gift‑card discounts, Cycle2Work and electric‑car scheme.
- Annual team offsites in sunny locations.
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in the United Kingdom.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 13 hours ago
Expires 1 month from now
3 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
stackone
London