FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates extensive experience in security engineering with a focus on SOC 2 Type II controls, cloud security (AWS), and compliance with GDPR and PCI DSS. Proficient in penetration testing, secure architecture, and integrating security practices into the software development lifecycle.
Highest-signal resume keywords
SOC 2 Type II ControlsCloud Security (AWS)Penetration TestingGDPR CompliancePCI DSS Requirements
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Penetration TestingSecure ArchitectureThreat ModellingApplication SecurityCloud SecurityContainer SecurityInfrastructure-as-CodeSecurity AutomationSecurity ToolingIncident Response
Soft Skills
Clear Written CommunicationInfluencing Without Authority
Tools & Technologies
SASTDASTCI/CDKubernetesOpenTofuSIEMLogging ToolsSecurity Automation Tools
Certifications & Qualifications
OSCPOSWEGWAPT
Industry Keywords
GDPRPCI DSSISO 27001SaaSAI SecurityIncident SimulationsChaos Engineering
Tech Stack
Tools & technologiesAWSCloudKubernetesSDLC
About the role
Key responsibilities & impact- Own the engineering implementation and continuous improvement of security controls supporting SOC 2 Type II
- Work with IT on evidence collection and external audits
- Act as the security partner in architecture and design reviews
- Set secure-by-default patterns for new services, data flows, and integrations
- Design and tune sandboxing and isolation models for AI-assisted and AI-generated code
- Own offensive security testing across applications, cloud, and infrastructure
- Validate remediation of internal and third-party findings
- Maintain and extend GDPR and PCI DSS control posture
- Collaborate with Legal, Finance, Engineering, and Platform Engineering on compliance and security controls
- Tune security tooling and automation across the SDLC, including SAST, DAST, dependency and container scanning, IaC policy checks, and CI/CD gates
- Lead threat modelling for high-risk services and AI features
- Improve detection and response through logging coverage, alerting, runbooks, and incident response participation
- Support customer and prospect security reviews, questionnaires, and due diligence
- Raise the security baseline across engineering through guidance, tooling, and enablement
Requirements
What you’ll need- 5+ years in a security engineering, application security, or cloud security role, with meaningful time spent hands-on rather than purely advisory
- Direct experience operating or contributing to SOC 2 Type II controls in a live environment, sustaining and evidencing controls over time
- Practical penetration testing skills: web application, API, and cloud infrastructure testing
- Strong cloud security background (AWS): IAM design, network segmentation, encryption, secrets management, and workload isolation
- Working knowledge of PCI DSS requirements and how to scope, segment, and evidence a cardholder-data environment
- Solid grasp of GDPR as it applies to engineering: lawful basis, data minimisation, retention, subject rights, cross-border transfers, and sub-processor management
- Secure architecture and threat modelling experience across distributed, service-based systems
- Strong hands-on engineering ability: reading application code, writing scripts and automation, and integrating security checks into CI/CD
- Experience securing containerised workloads and infrastructure-as-code (Kubernetes, OpenTofu, or equivalents)
- Ability to influence engineers and product teams without authority and make pragmatic risk trade-offs
- Clear written communication for control documentation, findings, and customer-facing security responses
- Experience securing AI/LLM systems, including prompt injection, tool-use and agent permissions, model and data exfiltration risks, RAG pipeline security, and evaluation of AI-generated code
- Good to have: exposure to ISO 27001 or multi-framework compliance programmes
- Good to have: offensive security certifications (OSCP, OSWE, GWAPT) or equivalent demonstrable experience
- Good to have: detection engineering and SIEM experience
- Good to have: familiarity with OWASP Top 10 for LLM Applications, NIST AI RMF, or ISO/IEC 42001
- Good to have: experience in high-growth SaaS handling sensitive personal data at scale
- Good to have: EdTech, accessibility, FERPA, or institutional procurement security review experience
- Good to have: controlled security experiments, incident simulations, chaos engineering, or similar experience
- Good to have: prior involvement in incident response for a real production incident
- UK location/work authorization is implied by the stated UK remote location, but no explicit authorization requirement is provided
Benefits
Comp & perks- 35 days holiday per year (excluding public holidays!)
- Your birthday off
- 12 scheduled company wellness Fridays off per year
- Enhanced maternity & paternity allowance
- Flexible working hours
- Work-from-home allowance
- Cycle-to-work scheme (UK)
- Life Insurance up to 4 x salary
- Private health insurance
- Annual eye test and up to £100 towards frames for glasses required for DSE work
