Confidential — Financial Services
We are partnering with a leading financial services firm that is modernising its cloud footprint across AWS and Azure. As a mid‑senior Cloud Security Engineer you will join a high‑performing platform team, helping to embed security by design while supporting rapid delivery of new services.
Design, implement and maintain security controls across multi‑cloud (AWS & Azure) environments using Terraform IaC.
Integrate security testing and hardening steps into CI/CD pipelines (GitLab, Azure DevOps, Jenkins).
Collaborate with platform and development squads to translate security requirements into reusable, automated guardrails.
Conduct threat modelling, risk assessments and regular compliance reviews against regulatory standards (e.g., PCI‑DSS, ISO 27001).
Respond to security incidents, perform root‑cause analysis and drive remediation across cloud resources.
Maintain up‑to‑date security documentation, runbooks and configuration baselines.
Mentor junior engineers and champion a culture of security‑first thinking throughout the organisation.
5+ years of hands‑on experience securing AWS and Azure workloads.
Proficiency with Terraform (or other IaC tools) and a strong understanding of cloud‑native security services (e.g., IAM, Security Hub, Azure Sentinel).
Experience embedding security into CI/CD pipelines and familiar with tools such as Snyk, Checkov, or Trivy.
Solid knowledge of networking, encryption, identity & access management, and container security (EKS/ECS, AKS).
Eligibility for SC clearance (or ability to obtain it) – preferred.
Relevant certifications (e.g., AWS Security Specialty, Azure Security Engineer, CISSP, CISA) – desirable.
Excellent communication skills and a collaborative mindset for working with cross‑functional platform teams.
Competitive salary of £150,000 + performance bonus.
Hybrid working model – 2 days per week in our Bristol office, the rest remote.
Generous pension contribution, private medical and dental cover.
Professional development budget for certifications, conferences and training.
State‑of‑the‑art tech stack, flexible hardware allowance and access to a modern, collaborative workspace.