×
Register Here to Apply for Jobs or Post Jobs. X

Security Engineer (Cloud & Application Security

Job in Cardiff, Cardiff City Area, CF10, Wales, UK
Listing for: Segen Ltd.
Full Time position
Listed on 2026-08-09
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Cloud Computing: Infrastructure & Operations, Security Management & Operations
Salary/Wage Range or Industry Benchmark: 65000 GBP Yearly GBP 65000.00 YEAR
Job Description & How to Apply Below
Position: Security Engineer (Cloud & Application Security)

Department:
Technology

Reports to:

Global Head of Cyber Security

Salary: £65,000 per annum

Location:

UK (Hybrid)

About Segen
  • Own and continuously improve Segen’s security posture across our Cloud environment, including configuration hardening, policy enforcement, and security architecture.
  • Implement and manage cloud-native security controls using Microsoft Defender for Cloud, Azure Security Centre, and Azure Policy.
  • Design and enforce Identity and Access Management (IAM) controls, including Privileged Identity Management (PIM), Conditional Access, and Entra  (Azure AD) governance.
  • Manage cloud network security including virtual network segmentation, NSGs, Private Endpoints, and Azure Firewall.
  • Lead cloud security reviews for new infrastructure deployments, ensuring secure architecture patterns are followed (Zero Trust, least privilege, defence-in-depth).
  • Monitor cloud environments for misconfigurations and security drift using CSPM tooling, remediating findings in collaboration with Dev Ops and infrastructure teams.
Application & Development Security (App Sec)
  • Champion and embed secure software development lifecycle (SSDLC) practices across engineering teams.
  • Integrate and manage application security tooling within CI/CD pipelines, including SAST, DAST, SCA, and secrets scanning (e.g. Checkmarx, Snyk, Git Hub Advanced Security, OWASP ZAP).
  • Conduct and coordinate application security assessments, threat modelling sessions, and secure code reviews.
  • Act as the primary security liaison for development and Dev Ops teams, providing hands-on guidance on secure coding standards (OWASP Top 10, SANS CWE).
  • Manage the responsible disclosure and triage process for application vulnerabilities identified through internal testing or third-party penetration tests.
  • Develop and maintain application security standards, policies, and developer-facing guidance documentation.
Dev Sec Ops  & Security Automation
  • Build and maintain security automation pipelines to enforce policy-as-code, infrastructure-as-code (IaC) scanning, and automated compliance checks.
  • Implement and manage secrets management solutions (e.g. Azure Key Vault) and ensure secure handling of credentials and API keys across development environments.
  • Develop scripted tooling and automation using Power Shell, Python, or similar to improve detection, response, and security operational efficiency.
  • Collaborate with Dev Ops on container security, including image scanning, Kubernetes security posture, and runtime protection.
Vulnerability Management & Threat Intelligence
  • Own the application and cloud vulnerability management programme, including tooling, triage, SLA tracking, and remediation coordination.
  • Integrate threat intelligence feeds to contextualise cloud and application risk, informing prioritisation and defensive improvements.
  • Manage and track findings from penetration tests through to resolution.
Compliance & Risk
  • Support cloud and application compliance requirements including ISO 27001, Cyber Essentials/Plus, UK GDPR, and PCI DSS where applicable.
  • Contribute to security risk assessments for new cloud services, third‑party integrations, and application deployments.
  • Maintain security documentation, evidence packs, and control mappings for internal and external audit purposes.
Collaboration & Stakeholder Engagement
  • Work closely with software engineers, architects, and Dev Ops teams as a trusted security partner – not a gatekeeper.
  • Deliver security awareness and training for development teams, covering secure coding practices and common vulnerabilities.
  • Produce clear risk-based reporting on cloud and application security posture for the Head of Cyber Security and senior stakeholders.
Technical Competencies

Required Skills

  • Hands‑on experience securing Microsoft Azure environments, including Defender for Cloud, Azure Policy, Entra , Key Vault, and network security controls.
  • Practical experience implementing application security tooling within CI/CD pipelines (SAST, DAST, SCA, secrets scanning).
  • Strong understanding of the OWASP Top 10 and common application vulnerabilities (injection, broken auth, IDOR, XSS, etc.).
  • Experience with Infrastructure‑as‑Code security scanning (e.g. Checkov,…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary