Senior Security Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Security Engineer (Cybersecurity): Designing and implementing end-to-end security controls and automated scalable solutions for a global TV streaming platform with an accent on DevSecOps, cloud security, and threat modelling. Focus on embedding security into application architectures, automating vulnerability detection, and managing infrastructure as code across multiple cloud providers.
Location: Hybrid in Cambridge, United Kingdom (Monday through Thursday in office)
Company
is a leading TV streaming platform that connects consumers to content, enables publishers to monetize audiences, and provides unique engagement capabilities for advertisers.
What you will do
- Conduct enterprise, network, and application-level security reviews and threat modelling for infrastructure and platform initiatives.
- Partner with engineering teams to embed security into application architectures and deployment workflows as part of a robust SSDLC.
- Design and implement integrations with third-party security platforms to automate vulnerability management and cloud posture monitoring.
- Improve IAM policies, network configurations, DNS security, and cloud resource management practices.
- Respond to security incidents to triage, contain, remediate, and report.
- Automate vulnerability detection and compliance validation across cloud and containerised environments using reusable modules.
Requirements
- Experience in security consulting combined with hands-on implementation.
- Proven track record of leading DevSecOps initiatives and maintaining DSO platforms via IaC.
- Software engineering experience with at least one general-purpose language such as Python, Golang, C, or Rust.
- Experience deploying and operating Kubernetes clusters and multi-cloud infrastructure (AWS, GCP, Azure) in production.
- Expertise in designing and administering enterprise IAM solutions at scale (e.g., AD, EntraID, Okta).
- Must be based in or be able to work in Cambridge, UK to adhere to the hybrid office schedule.
Nice to have
- Experience with offensive cyber operations, including application, system, and network penetration testing.
- Background in implementing data tagging, data catalogs, or other data protection activities.
- Defensive cyber operations experience, such as operating a SIEM, managing a SOC, or leading cyber investigations.
Culture & Benefits
- Hybrid work approach with flexible Fridays for remote work.
- Comprehensive healthcare benefits, including medical, dental, and vision.
- Retirement options such as 401(k) or pension plans.
- Global access to mental health and financial wellness support and resources.
- Inclusive environment focusing on collaboration, problem-solving, and pragmatic innovation.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →