Cloud Security Engineer
Listed on 2026-06-01
-
Education / Teaching
Cybersecurity, Cloud Computing
Cloud Security Engineer - Manchester (Hybrid 3 Days Office)
Finova is the UK’s largest financial services technology provider, supporting one in every five mortgages nationwide. Our agile, cloud-native solutions enable over 60 banks, building societies, specialist lenders, equity release providers and a network of 2,400+ brokers to stay ahead in a competitive market.
Built on open architecture and backed by deep industry expertise, our platform is designed to scale. Each year, we process over £50 billion in loans, manage nearly £50 billion in savings, and support the digital servicing of more than 650,000 UK borrower accounts.
Be part of a team that’s driving innovation, enabling growth and shaping the future of UK lending.
About FinovaFinova offers a flexible, modular technology suite designed to help lenders move faster, scale efficiently and deliver standout digital experiences.
Financial Institutions use Finova to launch products faster, process applications up to 50% more efficiently and reduce operational costs — all while staying fully compliant in a fast-moving market.
About the RoleWe’re looking for a Cloud Security Engineer to own the security posture of our multi-cloud SaaS fintech platform across AWS, Azure, and GCP. This is a hands‑on, hybrid role. You’ll find yourself reviewing a Terraform pull request before stand‑up, tuning CSPM rules at midday, and tracing a misconfigured storage bucket across three accounts before the end of the day.
About you Must-Have ExperienceProfessional
Experience:
4–6 years in cloud security, security engineering, or security-focused platform engineering, with hands‑on production experience in regulated environments.Multi-Cloud Mastery: Hands‑on experience securing at least two of AWS, Azure, and GCP in production, and working familiarity with all three. You can navigate the consoles and APIs of all three without a tutorial open.
Infrastructure-as-Code: Deep experience with IaC security, primarily utilizing Terraform, plus at least one of Bicep, ARM, Cloud Formation, or Pulumi, alongside their associated policy-as-code tooling.
Cloud-Native Security Services: Practical knowledge of tools like Defender for Cloud, AWS Security Hub / Guard Duty / Macie / Inspector, and GCP Security Command Center / Chronicle—including their failure modes, not just their marketing.
Container Security: Practical experience with Kubernetes security (admission control, pod security, network policy, service mesh) and container supply‑chain security (image signing, SBOMs, SLSA).
Guardrails as Code: Experience defining and operating cloud guardrails as code (AWS SCPs, Azure Policy, GCP Org Policies), including safe rollout strategies that avoid production disruption.
Network & Core Security: Solid understanding of cloud network security patterns (VPC/VNet design, private connectivity, egress filtering, DNS security) and secrets management (KMS, Key Vault, Secrets Manager, Hashi Corp Vault).
Sec Ops & Multi-Tenancy: Familiarity with cloud detection engineering (Cloud Trail, Activity/Audit Logs) and an understanding of how cloud-layer choices (account structure, networking, KMS keys, storage layout) dictate real SaaS tenant isolation.
Consultative Delivery: Experience working as a delivery engineer or consultant for a vendor or consultancy. You have shipped cloud security into customer environments under tight deadlines, navigated diverse stakeholder landscapes, and learned to be effective without direct platform ownership.
Communication: Clear communicator capable of explaining a cloud risk to a developer, a CFO, and an auditor—adjusting technical depth and language appropriately without compromising facts.
Experience working within fintech, payments, banking, or insurance environments.
Hands‑on experience securing AI/ML cloud infrastructure (training clusters, GPU workloads, vector databases, model registries).
Experience with CNAPP / CIEM platforms (Wiz, Prisma Cloud, Orca, Microsoft Defender CNAPP, etc.) and an understanding of their trade‑offs.
Familiarity with eBPF-based runtime security tooling (Falco, Tetragon, or commercial equivalents).
Experience with FedRAMP,…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: