Principal Security Architect (Cloud Security)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Principal Security Architect (Cloud Security): Setting security standards and guardrails for a specialty insurance product and platform with an accent on cloud security, secure development, identity, vulnerability management, and data protection. Focus on designing threat-modelling practices, controlling privileged access, protecting customer data in shared infrastructure, and helping engineering teams make secure decisions throughout the product lifecycle.
Location: Hybrid role based in the UK, with London office facilities and home-office support.
Company
develops technology that helps specialty insurance brokers and carriers automate complex operations and make faster, smarter decisions.
What you will do
- Provide practical security guidance to engineers throughout the software development lifecycle.
- Own secure development and secure coding standards, and coordinate penetration testing.
- Run threat modelling for high-risk initiatives and enable engineering teams to perform it independently.
- Define cloud security guardrails covering configuration, access, identity, encryption, and modern serverless architecture.
- Set approaches for vulnerability prioritisation, privileged access, data classification, customer-data separation, and loss prevention.
- Assess security risks associated with higher-risk suppliers and collaborate across engineering, platform, product, and security teams.
Requirements
- Extensive experience in a senior or principal security architecture or application security role.
- Hands-on experience with cloud security, secure configuration, identity and access management, encryption, and security guardrails.
- Strong knowledge of secure software development, threat modelling, OWASP Top 10 risks, automated security testing, and penetration testing.
- Practical experience with vulnerability management, privileged access, data security, and software supply-chain practices such as SBOMs.
- Ability to communicate security risks clearly and turn them into pragmatic decisions for technical and non-technical stakeholders.
- Willingness to explore practical applications of AI for product and application security.
Nice to have
- Experience in InsurTech, FinTech, or another regulated industry.
- Experience establishing a security function or practices at an early stage.
- Experience securing multi-tenant software running on shared infrastructure.
- CISSP, CCSP, or an AWS security certification.
- Experience training and coaching engineers on security.
Culture & Benefits
- Collaborative environment focused on curiosity, ownership, continuous learning, and measurable outcomes.
- Private medical, income protection, and life insurance.
- Twenty-eight days of holiday plus national holidays, enhanced parental pay, and life-events leave.
- Pension and nursery-fee salary exchange, financial wellbeing support, and company stock options.
- Home-office and equipment allowance, company MacBook, learning allowance, and conference or exam leave.
- London office gym and shower facilities, social events, employee assistance support, and an environmental tree-planting partnership.
Hiring process
- Background checks may include criminal record, credit history, previous-employer, and academic-qualification verification.
- Adjustments are available to support an accessible hiring process.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →