Closing Gap

Senior Cloud Security/DevSecOps Engineer – UK

London, Greater LondonFull-time
£45,000 - £80,000 annually
About the Job
We are looking for a Senior Cloud Security / DevSecOps Engineer to join a growing technology team and help build secure, reliable and scalable cloud environments.

The role combines cloud security, DevSecOps, infrastructure and automation. You will work closely with Engineering, DevOps and Platform teams to embed security into infrastructure, applications and deployment processes.

Key Responsibilities:
  • Design and implement security controls across AWS and/or Azure.
  • Secure cloud infrastructure, networking, identities and data.
  • Manage and improve IAM, access controls and least-privilege policies.
  • Secure Kubernetes and containerised production environments.
  • Build security controls into CI/CD pipelines.
  • Integrate automated security testing into development and deployment workflows.
  • Secure Infrastructure as Code using Terraform.
  • Monitor cloud environments and identify security risks and misconfigurations.
  • Investigate and respond to cloud security incidents.
  • Manage vulnerabilities and drive remediation through to completion.
  • Implement secure networking and Zero Trust principles.
  • Automate security processes using Python, Bash or similar.
  • Work closely with engineering teams to improve secure development practices.
  • Support security, compliance and cloud governance initiatives.

What We’re Looking For:
  • 5+ years of experience in Cloud Security, DevSecOps, Security Engineering, Platform Engineering or related roles.
  • Strong hands-on AWS and/or Azure experience.
  • Strong cloud security and infrastructure knowledge.
  • Solid Terraform / Infrastructure as Code experience.
  • Experience securing Kubernetes and Docker environments.
  • Strong IAM and cloud networking experience.
  • Strong CI/CD experience.
  • Experience integrating security into CI/CD pipelines.
  • Experience with vulnerability management and remediation.
  • Good understanding of secrets management.
  • Strong scripting skills in Python, Bash, PowerShell or similar.
  • Understanding of Zero Trust and least-privilege principles.
  • Strong production troubleshooting and incident response experience.
  • Comfortable working closely with Engineering, Platform and DevOps teams.

Desirable:
  • AWS Security Hub, GuardDuty, CloudTrail or AWS Config.
  • Microsoft Defender for Cloud.
  • Wiz, Prisma Cloud or similar CSPM tools.
  • Snyk, Trivy or similar security scanning tools.
  • Vault or other secrets-management platforms.
  • OPA / Gatekeeper or policy-as-code.
  • SIEM and security monitoring platforms.
  • SOC 2, ISO 27001 or Cyber Essentials Plus.
  • Experience in regulated industries.

Important:
This is a hands-on technical security role.

Candidates whose experience is mainly limited to GRC, compliance, audits, policy documentation or vulnerability reporting without strong cloud and infrastructure experience may not be suitable.

We are looking for someone who has actually built, secured, automated and operated production cloud environments.

If you have strong cloud infrastructure experience combined with security and DevSecOps expertise, we would be interested in hearing from you.