drjobs Principal Cloud Security Engineer

Principal Cloud Security Engineer

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

Glasgow - UK

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

Description

Are you ready to lead the way in securing cloud environments for a vital public service We are looking for a highly skilled Principal Cloud Security Engineer to join the Digital Risk & Security branch of our Chief Digital Office. In this pivotal role your expertise will be instrumental in protecting Social Security Scotlands critical information systems supporting our commitment to safeguarding public data and digital services.

As a key technical leader you will drive the adoption and evolution of DevSecOps practices across a complex multi-cloud environment. Collaborating closely with cloud engineers developers and architects you will lead the design and integration of security tooling into our cloud environments ensuring security is embedded at every stage of our organisation. Your role will be pivotal in implementing secure-by-design cloud architectures delivering scalable automated solutions that align with industry best practices and support our wider digital transformation goals.

This is a highly technical role requiring a deep understanding of cloud infrastructure and advanced security expertise. You will play a critical part in articulating security postures managing technical risks and implementing controls to mitigate potential threats. While this role does not involve direct security operations or governance your developer experience and stakeholder management skills will be vital. You will collaborate across teams influence senior management and drive forward innovative security solutions that balance security needs with operational agility.

A Principal Cloud Security Engineer designs builds manages and supports the security controls within our infrastructure services that underpin all internal user services and services to the public.

The Principal Cloud Security Engineer manages third party provision of cloud security services and the provision of expertise to develop secure architectural solutions for our cloud infrastructure services throughout the service product life cycle.

At this role level you will:

  • Oversee programmes and projects.
  • Work with technical architects and infrastructure engineers to translate the architectural designs into operations and support in operationalising the designs.
  • Lead and direct cloud security engineering teams in building managing supporting and maintaining solutions according to departmental policy (if taking a managerial path).

If you are passionate about cloud security and eager to make a real difference in public services we invite you to join our talented team and take the next step in your career.



Responsibilities

Responsibilities

  • Lead the design implementation and support of cloud infrastructure solutions with embedded security controls utilising industry-standard frameworks like AWS Well-Architected or Azure Security Centre.
  • Develop and enforce security controls within Infrastructure as Code (IaC) pipelines integrating security testing (SAST DAST SCA) and automated compliance checks into CI/CD processes.
  • Provide expert guidance on cloud security architecture articulating security postures and implementing mitigating controls to reduce risk.
  • Lead cross-functional teams in applying modern development and security standards to support complex projects ensuring security by design.
  • Proactively identify vulnerabilities and potential issues in cloud environments initiating preventative measures and continuous security improvements.
  • Collaborate with Architects Developers and DevOps teams to embed security into the end-to-end development pipeline promoting DevSecOps best practices.
  • Establish and maintain security frameworks and procedures across the service life-cycle ensuring compliance with standards such as ISO27001 and government policies.
  • Diagnose and troubleshoot security and infrastructure issues across diverse systems including compute storage networking and software.
  • Cultivate strong stakeholder relationships serving as the primary point of contact for cyber security matters and securing buy-in for security initiatives.
  • Advise on emerging security threats and future technology trends supporting strategic planning and security posture enhancement.
  • Lead system and acceptance testing strategies ensuring security controls are validated and operational risks are effectively managed.
  • Lead the development of security awareness and training programmes to promote a strong security culture within technical teams.


Qualifications

Success Profiles
We use an assessment framework called Success Profiles which lists the elements we test and provides detailed descriptions of each. Find out more about how we assess the Success Profile elements

Essential Experience

  1. Proven hands-on experience designing and implementing secure cloud infrastructure solutions including native security services (IAM WAFs threat detection) with a strong focus on embedding security within CI/CD pipelines using tools like Terraform AWS CloudFormation SAST DAST and SCA.
  2. Demonstrable experience leading DevSecOps initiatives integrating security controls seamlessly into development and operational workflows and collaborating effectively with Developers Architects and DevOps teams to promote security by design.
  3. Extensive experience engaging with senior stakeholders to communicate technical security solutions secure buy-in for security controls and lead cross-team efforts to embed security best practices into enterprise cloud environments.

Behaviours

You can find out more about Success Profiles Behaviours here: Success Profiles - Civil Service Behaviours ()

Technical/Professional Skills:
This role is aligned to
Infrastructure engineer - Government Digital and Data Profession Capability Framework within the Digital Data and Technology Profession.

DDaT Pay Supplement
This post is part of the Scottish Government Digital Data and Technology (DDAT) profession and as a member of the profession you will join the professional development system. This post currently attracts a 5000 annual DDAT pay supplement applicable after a 3 months competency qualifying period. The payment will be backdated to your start date in the role. Pay supplements are reviewed regularly and there is one currently underway. Changes will be communicated when the review is concluded.

Working pattern
Our standard hours are 35 hours per week and we offer a range of flexible working options depending on the needs of the role. We embrace a hybrid working style where all colleagues will spend time in either our Glasgow or Dundee offices. There is an expectation of a minimum 2 days per week in your assigned location which will be either Glasgow or you have specific questions about the role you are applying for please contact us.




Required Experience:

Staff IC

Employment Type

Full-Time

About Company

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.