Security Engineer - London - Cloudsmith

    Cloudsmith
    Cloudsmith London

    23 hours ago

    £55,000 - £100,000 (GBP) per year *
    Description

    Security · NI/GB/ROI Security Engineer (AppSec) TL;DR: We're seeking a passionate and technically sophisticated security engineer to lead, architect, and integrate security into every aspect of our platform. You like making things but also breaking things and preventing others from doing the same.About Cloudsmith Cloudsmith is transforming how organizations handle software artifacts and secure their supply chains. As a fully managed multi-tenant Software as a Service (SaaS) built on AWS, our mission is to enable organizations to tackle scale and complexity through best-in-class artifact management and to secure software by default. Our vision is to become the software supply chain itself, powering the future of software delivery.We are the world's most potent artifact management platform, built by developers for developers. Our platform supports over 30 formats spanning languages, containers, and operating systems, with enterprise-grade features, including vulnerability and security scanning, world-class policy management and enforcement, and web-scale to handle the Fortune 500. Organizations integrate Cloudsmith as critical infrastructure into their development, deployment, and distribution pipelines, trusting us to protect and accelerate, no matter the scale.Backed by top-tier investors and on a trajectory toward IPO, we're building mission-critical infrastructure that powers software delivery for organizations worldwide. We operate at the cutting edge of cloud-native technology, tackling complex distributed systems challenges that directly impact millions of developers. Now is an exciting time to join us as we revolutionize how organizations deliver and secure software and help write the next chapter of our rocket-ship growth story.The Role As a Security Engineer (AppSec) reporting to the Head of Application Security, you'll be a key member of our growing security function, focusing on our product and platform security. This role combines hands-on security engineering with technical leadership, requiring someone to implement security controls and guide other engineers in secure development practices. You'll be the technical cornerstone of our product security initiatives, working to ensure our platform remains secure by design as we scale.

    Key Responsibilities Technical Security Leadership Enhance and expand security controls across our cloud-native infrastructure.Lead security architecture reviews and threat modeling sessions.Develop, evolve, and implement secure coding standards and practices.Extend our security automation tooling and strengthen CI/CD pipeline security.Build upon our existing security testing frameworks and procedures.Application Security Implementation Perform security code reviews and penetration testing of our codebases.Implement security controls for our distributed systems (AWS-based).Design and implement secure container runtime environments.Build secure API endpoints and review API security architecture.Implement supply chain security controls and verification systems.Security Engineering & Architecture Enhance our security monitoring solutions using DataDog, AWS Security Hub, etc.Strengthen our secure deployment pipelines using CircleCI and GitHub Actions.Drive implementation of our secure artifact storage and processing systems.Design and implement additional customer and environment isolation controls.Develop security automation tools and frameworks and apply them.Partner with the Head of AppSec + CTO on security architecture decisions.Security Culture & Education Provide security guidance and mentorship to engineering teams.Develop and deliver security training materials.Create security documentation and guidelines.Participate in security incident response.Contribute to security policies and standards.Team Collaboration Work closely with the Head of AppSec + CTO to implement security strategies.Collaborate with engineering teams to embed security practices.Support security audit and compliance initiatives.Participate in security incident response as a technical lead (incl. red/blue team).Help evaluate and implement new security tools and technologies.Automate everything, write code (if you want to), and make proofs ('sploits).Required Experience, Qualities & Skills Technical Expertise 3+ years of security engineering experience or equivalent.Deep expertise in application security and secure software development.Experience with implementing SAST, DAST, and RASP (Runtime Security).Strong programming skills in Python, with familiarity in or similar.Extensive experience with: Cloud security (AWS-based, preferably).Web application security.API security (REST or GraphQL, etc.).Infrastructure as Code security.CI/CD pipeline security.Container security (Docker, OCI).Database security.

    Security Engineering Skills Experience building security tools and automation.Strong background in threat modeling and risk assessment.Expertise in penetration testing and vulnerability assessment.Knowledge of cryptography and secure communication protocols.Experience with security monitoring and incident response.Domain Knowledge Understanding of software supply chain security.Experience with artifact management systems.Knowledge of modern development practices and tools.Familiarity with compliance frameworks (ISO 27001, SOC2).Bonus Points Experience with: Data enclave implementations.Secure runtime environments (Firecracker, gVisor).Software Composition Analysis.Contributions to open-source security tools.Security-focused certifications (OSCP, CSSLP, etc.).Experience securing package management systems.

    Cultural Values We're Looking For Technical Mastery: Demonstrate deep security expertise and engineering craftsmanship.Security Innovation: Drive automated, cloud-native security solutions to excellence.Knowledge Champion: Share security expertise openly and mentor engineering teams.Pragmatic Builder: Deliver practical security solutions with customer needs in mind.Continuous Growth: Actively expand security knowledge and embrace sustainable practices.Impact & Opportunity This role offers the chance to enhance security in a platform already trusted by organizations worldwide for software supply chain security. You'll join an ISO 27001-certified organization and work with cutting-edge technologies, implementing security controls that protect critical infrastructure. From startups to Fortune 500 customers, your work will directly impact how organizations secure their software supply chains while helping us maintain our position as the most trusted name in artifact management.Benefits, Location & Work Environment Note: You must be based in Ireland or the United Kingdom and have the right to work independently without requiring sponsorship.Headlines A remote-first position based in Ireland or the United Kingdom.A competitive compensation package, including equity.With comprehensive health, dental, and vision insurance.Plus, generous annual leave and flexible working policies to suit your lifestyle.Including a professional development budget for conferences and training.In a dynamic, innovative, trust-centric, and supportive work environment.With the opportunity to shape a fast-growing Series A startup (and beyond).Regular (monthly-ish) travel may be required for team meetings.Regular (quarterly-ish) travel may also be required for events and customers.Health and Wellness Regardless of your location, we deeply care about our staff's and their families' health and wellness; a sustainable pace is essential. In addition to generous annual leave (PTO), we offer parental leave and health benefits to cover you and your dependents up to 100%. We also offer flexible, family-friendly working policies.

    Personal Growth You will have an enormous opportunity to learn new skills alongside your colleagues, and your continued professional development is essential to us because it's important to you. We will support you with budgets for equipment, training, books, conferences, travel, and certifications. The more powerful you become, the better for all of us.Hybrid / Remote First Cloudsmith is headquartered in Belfast, Northern Ireland, and we use our H.Q. regularly for activities like team planning, meets and greets, and sometimes other group activities (like games). We also hold all-hands offsites in Belfast (or otherwise) thrice yearly, with guest speakers and team activities. Most Cloudsmithers work remotely, close and far, so we rely on our online collaboration tools; Slack is how we work.About Equal Opportunity Cloudsmith is an equal-opportunity employer proud to nurture a diverse workplace that welcomes applications from individuals of all races, genders, and ethnic groups. We do not discriminate on age, religion, sexual orientation, citizenship status, military service, or health conditions. We will not tolerate discrimination of any kind within our workforce.

    The Final Word We're seeking someone with deep technical security expertise and a passion for building secure systems. You'll be working at the intersection of cloud infrastructure, artifact management, and supply chain security, helping to develop a platform that organizations trust with their most critical assets. If you're excited about security engineering and want to have a lasting impact on the software industry, we want to hear from you.Department Security Role Application Security Locations NI/GB/ROI Employment type Full-time Contact Lee Skillen Chief Technology Officer (CTO) – Engineering Colleagues Lee Skillen Chief Technology Officer (CTO) About Cloudsmith Founded in 2018 Co-workers 80+ (and growing) Security · NI/GB/ROI Security Engineer (AppSec) Already working at Cloudsmith? Let's recruit together and find your next colleague.

    #J-18808-Ljbffr

    * This salary range is an estimation made by beBee
  • Work in company

    AI Security Engineer- security engineering/ cloud security

    Only for registered members

    AI Security Engineer- security engineering/ cloud security London This is a new and exclusive opportunity for a AI Security Engineer to focus on security engineering/ cloud security for this award winning STEM Business Role details Title: AI Security Engineer Focus of the role: s ...

    London £75,000 - £95,000 (GBP)

    1 week ago

  • Work in company

    Security Engineer

    Only for registered members

    +4 years of experience in high-growth cloud-native SaaS environments. · Design Security controls and tooling from the ground up. Collaborate with engineering teams to raise the security bar. · Run threat hunts and respond to security incidents in real time. ...

    London

    1 month ago

  • Work in company

    Secure Engineer

    Only for registered members

    An opportunity has arisen for a Secure Engineer to join a growing Secure Engineering Project Team supporting Defence and highly secure government environments. · ...

    London

    1 month ago

  • Work in company

    Security Engineer

    Only for registered members

    We're seeking a hands-on Security Engineer to build scalable controls through code and automation.Treat security as an engineering challenge—focusing on IaC, reliable guardrails, and making “secure by default” easy for our teams. · ...

    London

    2 weeks ago

  • Work in company

    Security Engineer

    Only for registered members

    +We tackle the most complex problems in quantitative finance, by bringing scientific clarity to financial complexity. · +Embedding with product or platform teams to design and implement fixes for identified security issues · Learning unfamiliar systems and codebases quickly, cont ...

    London Full time

    1 month ago

  • Work in company

    Security Engineer

    Only for registered members

    I'm partnered with a highly technical research-driven investment firm to hire a Product Security Engineer to embed security directly into engineering and infrastructure teams. · This isn't a monitoring or alert-driven role.You'll be helping teams design and ship systems safely fr ...

    London

    2 weeks ago

  • Work in company

    Security Engineer

    Only for registered members

    This is an entry-level position and would suit a graduate with 1-3 years of commercial security experience who is looking for a move into a security engineering-focused role. · The ideal candidate will have a degree in technology and/or a cybersecurity-related subject and possess ...

    London

    1 month ago

  • Work in company

    Security Engineer

    Only for registered members

    Security Engineer (Azure) - Contract - London/Hybrid - £380 per day · Synergize Consulting are now hiring for a Security Engineer to work at a leading consultancy client of ours on a contract basis. · This is a hands-on engineer role, and the successful candidate will work as par ...

    London £55,000 - £100,000 (GBP) per year

    2 days ago

  • Work in company

    Security Engineer

    Only for registered members

    Security Engineer required for global insurance firm. · Design and implement Zero Trust controls across identity, devices, networks, applications, and data · Work with cloud, infrastructure, and application teams to embed security by design · ...

    London

    3 weeks ago

  • Work in company

    Security Engineer

    Only for registered members

    This regulated organization works with banks, insurers and pension providers to ensure that their customers are protected from losses. The team is expanding to support the needs of the business and their clients. · Delivering security engineering across MS Azure, including Sentin ...

    London

    1 month ago

  • Work in company

    Security Engineer

    Only for registered members

    Are you a skilled Service Engineer who has a solid understanding of high-end CCTV and Access Control? This role involves performing regular maintenance testing and troubleshooting of security systems to ensure optimal functionality. · ...

    London

    2 months ago

  • Work in company

    Security Engineer

    Only for registered members

    We are looking for an experienced engineer to join us in securing the most important engineering initiatives at Spotify. · You will be working in the product security engineering and consulting team. We're a distributed team supporting autonomous development teams with applicatio ...

    London Full time

    1 month ago

  • Work in company

    Security Engineer

    Only for registered members

    We are working with a well-established cyber security organisation delivering services into large-scale enterprise, defence and government environments. Due to continued growth, they are looking to appoint a Detection Engineer to strengthen their security monitoring and detection ...

    London £55,000 - £100,000 (GBP) per year

    1 week ago

  • Work in company

    Security Engineer

    Only for registered members

    We are seeking a Security Engineer specialising in Detection Engineering and Security Automation to design, build, and operate scalable detection and response capabilities across cloud and enterprise environments. · This role focuses on engineering high-fidelity detections and au ...

    London

    3 weeks ago

  • Work in company

    Security Engineer

    Only for registered members

    My client is looking for a hand's on Security Engineer with strong expertise in building and automating secure network infrastructure. · ...

    London

    1 month ago

  • Work in company

    Security Engineer

    Only for registered members

    About Agoda · At Agoda, we bridge the world through travel. Our story began in 2005, when two lifelong friends and entrepreneurs, driven by their passion for travel, launched Agoda to make it easier for everyone to explore the world. · Today, we are part of Booking Holdings [NASD ...

    London £55,000 - £100,000 (GBP) per year

    1 week ago

  • Work in company

    Security Engineer

    Only for registered members

    +Job summary · We're working with Amazon on this exciting opportunity.Join a leading cloud provider to build and manage services that proactively detect and mitigate cybersecurity threats across Amazon's massive global infrastructure, safeguarding customer trust and data. · ...

    London

    3 weeks ago

  • Work in company

    Security Engineer

    Only for registered members

    We're hiring a hands-on Security Engineer to join a large complex global environment focused on strengthening and optimising its cyber defence capability. · ...

    London £55,000 - £100,000 (GBP) per year

    2 weeks ago

  • Work in company

    Security Engineer

    Only for registered members

    We tackle the most complex problems in quantitative finance, by bringing scientific clarity to financial complexity. From our London HQ, we unite world-class researchers and engineers in an environment that values deep exploration and methodical execution - because the best ideas ...

    London

    1 month ago

  • Work in company

    Security Engineer

    Only for registered members

    A major security transformation programme is underway within a complex, large-scale hybrid cloud environment. We are building a specialist security rebuild team and are seeking both a Security Engineer and a Security Analyst to play critical roles in stabilisation, hardening, and ...

    London £500 - £600 (GBP)

    1 week ago

  • Work in company

    Security Engineer

    Only for registered members

    Role - Security Engineer · Location - London, UK (Hybrid) · Type - Contract (Inside IR35) · Job Description: · High-Level Skill Set · Strong understanding of secure‑by‑design infrastructure principles and engineering collaboration. · Broad expertise across PAM, encryption, back ...

    London £55,000 - £100,000 (GBP) per year

    1 day ago

Jobs
>
Security engineer
>
Jobs for Security engineer in London