Overview
In this role you will help strengthen the cloud security posture for a global retail organisation. You will work hybrid in London or Manchester, bridging security with stakeholders to shape governance and assurance models. You will balance hands-on technical work with high-level architecture reviews to ensure secure cloud designs. You will contribute to building a Cloud Security assurance model and embed DevSecOps practices across CI/CD pipelines, delivering measurable risk reduction.
Responsibilities
- Strengthen cloud security posture across Azure and GCP platforms
- Review cloud architectures to identify security improvements
- Develop and implement the Cloud Security assurance model
- Contribute to security-focused CI/CD pipelines and automation practices
- Hands-on security work alongside stakeholder engagement and governance
- Leverage IaC (Terraform) to enforce security controls
- Promote DevSecOps principles across development teams
Key requirements
- Knowledge of securing Azure and GCP platforms (preferred)
- Strong architecture review capability
- Experience with Infrastructure as Code (Terraform)
- Automation experience using Python
- Experience in DevSecOps and security CI/CD pipelines
- Familiarity with CIS, NIST or similar frameworks
- Stakeholder engagement experience in security initiatives
- Effective communication with technical and non-technical stakeholders
- Collaborative, cross-functional teamwork
- Problem-solving and analytical thinking
- Terraform
- Azure
- Google Cloud Platform
…
