Overview
In this role, you will assess platforms and cloud environments to identify security risks and strengthen the organisation’s security posture. You’ll focus on CSPM, security tooling, and secure-by-design practices, partnering with engineering, DevOps, and product teams. You’ll translate findings into practical remediation plans and help advance cloud and platform security capabilities. This hybrid position combines hands-on assessments with collaboration on secure architecture and reporting to diverse stakeholders.
Responsibilities
- Conduct security assessments of platforms, applications, and cloud environments to identify risks, misconfigurations, and control weaknesses
- Use CSPM, vulnerability management, and related security tools to continuously monitor cloud and platform security posture
- Review configurations across cloud services, infrastructure, identity, networking, containers, and platform components against security baselines and best practices
- Analyse findings from security tools and prioritise remediation based on risk, exploitability, and business impact
- Partner with engineering, DevOps, infrastructure, and product teams to define practical remediation plans and track closure of identified issues
- Support secure design and architecture reviews for new and existing platforms
- Validate that security controls are implemented effectively and aligned with organisational policies, standards, and regulatory requirements
- Assist in developing and maintaining security assessment methodologies, procedures, standards, and reporting templates
- Prepare clear, concise reports and dashboards summarising risks, trends, exceptions, and remediation progress for technical and non-technical stakeholders
- Contribute to continuous improvement of the organisation’s cloud and platform security capabilities, including automation opportunities and tool optimisation
- Stay current with emerging threats, cloud security risks, and evolving security tooling relevant to platform environments
Key requirements
- Experience in cybersecurity, cloud security, platform security, or risk assessment roles
- Hands-on experience performing technical security assessments across cloud or platform environments
- Strong understanding of cloud security concepts, including identity and access management, network security, logging and monitoring, encryption, secrets management, and workload protection
- Experience using CSPM tools and other security technologies such as vulnerability scanners, SIEM, CNAPP, or configuration assessment platforms
- collaboration with cross-functional teams
- ability to translate technical findings to non-technical stakeholders
- problem-solving and prioritisation
- CSPM
- vulnerability management
- security tooling (SIEM, CNAPP)
…
