أبلاي إيدج ابدأ البحث عن عمل

Platform Security & Compliance Lead | Southwest, London | Hybrid, Permanent

MRP-Global · Greater London, England, United Kingdom

قدّم وتابع مع أبلاي إيدج
Platform Security & Compliance Lead | Southwest, London | Hybrid, four days on-site | PermanentA fast-growing global technology business is looking for an experienced Platform Security & Compliance Lead to take ownership of security across its digital platform.This is a proper build role.You’ll report directly to the CTO and have the autonomy to shape the company’s approach to platform security, application security, compliance and governance from end to end.You won’t be joining a huge security department or spending your life writing policies nobody reads. You’ll work closely with engineering, get under the bonnet of the platform and make practical decisions that help the business grow securely.The environment is AWS, Terraform and cloud-native. We need someone who is as comfortable getting hands-on with IAM, infrastructure and CI/CD as they are leading a SOC 2 programme or answering an enterprise customer’s security questions.What you’ll own:The security posture of the production AWS environment, including IAM, VPC, Secrets Manager, ECS, Aurora and access controlsIdentity and access management across the business, including Cloudflare Zero TrustSecurity within the engineering lifecycle, from threat modelling and secure design reviews through to vulnerability management and secure development practicesCI/CD and software supply-chain security, including dependencies, GitHub Actions, build provenance and container securitySecurity monitoring, penetration testing, incident response and remediationThe SOC 2 programme, including controls, evidence gathering, audits and ongoing improvementsUK GDPR and PECR compliance, including DPAs, sub-processors, processing records and privacy requirementsCustomer security reviews, enterprise questionnaires, vendor assessments and security due diligenceThe full security incident lifecycle, including response, notifications, post-incident reviews and making sure lessons turn into actionWhat we’re looking for:You’ll have deep, hands-on experience securing production AWS environments, particularly across IAM, networking, containers and databases.You’ll also bring:Strong Terraform and infrastructure-as-code experienceExcellent application, cloud and infrastructure security knowledgeExperience securing CI/CD pipelines and software supply chainsA solid understanding of vulnerability management and incident responseThe ability to make sensible, commercial decisions about riskThe confidence to work autonomously while building strong relationships with engineering teamsA bias towards solving problems, not simply identifying themExperience with SOC 2 and UK GDPR would be highly valuable, as would experience supporting enterprise customer reviews and security due diligence.Knowledge of Ruby on Rails or Go, ISO 27001, payments, ticketing or access-control platforms would also be useful, but none of these are essential.Security certifications such as CISSP or CISM are welcomed, but we care far more about what you’ve built, secured and improved in the real world.Why this role?The company is growing quickly, the platform is becoming increasingly important, and security needs someone with the credibility and freedom to really own it.For the right person, this is an opportunity to build the security function the right way, work directly with the CTO and have a visible impact on a global technology business at an important stage of its growth.