Senior Security Engineer

Company: Kainos
Apply for the Senior Security Engineer
Location: Birmingham
Job Description:

Overview

In this role you will design and implement secure, cloud-based software solutions within an Agile team, embedding DevSecOps practices across the software lifecycle. You’ll act as a security specialist for applications or cloud platforms, guiding threat modelling, vulnerability management, and automated security artifacts. Your work partners with development and operations to enforce secure by design principles and drive cyber security awareness. This is a hands-on, coaching-heavy opportunity in a growth-focused, people-first culture.

Responsibilities

  • Collaborate daily with application development and cloud platform teams to plan security requirements within the SSDLC
  • Advise on cloud security best practices and automate compliance with baselines (e.g., CIS Benchmarks)
  • Implement automated security tooling in CI pipelines to validate security requirements
  • Coordinate with external organisations to plan, scope, and facilitate penetration tests
  • Review security tool outputs and translate them into actionable security stories for delivery teams
  • Verify adherence to security principles, architectural patterns, and requirements
  • Champion cyber security practices within Agile delivery teams
  • Mentor and develop junior team members

Key requirements

  • Experience implementing application security or cloud platform security
  • Experience in Defence Sector
  • Active Security Clearance
  • Strong understanding of web application security
  • Knowledge of cryptography and encryption in transit/at rest, hashing, and digital signatures
  • Familiarity with threat modelling, vulnerability management, application security testing, and penetration testing
  • Experience integrating application security tools into the SSDLC (e.g., SAST, DAST)
  • Experience with version control (e.g., git) and scripting or programming languages (e.g., Bash, PowerShell, Python, Java, .NET, JS) or Infrastructure as Code (Terraform, ARM Templates, Ansible)
  • Ability to communicate security issues to both technical and non-technical audiences
  • Clear communication
  • Mentoring/coaching
  • Collaborative mindset
  • Secure software development lifecycle (SSDLC)
  • Cloud security and automation
  • Vulnerability management

…

Posted: September 14th, 2026