Security Engineer – Cloud Migration to AWS

Version 1


Job Location:

London - UK

Monthly Salary: Not Disclosed
Posted on: 10 hours ago
Vacancies: 1 Vacancy

Job Summary

We are seeking a hands-on Security Engineer to embed within a large-scale cloud migration programme moving workloads into AWS. You will be responsible for designing automating and enforcing security controls throughout the migration lifecycle ensuring that every workload lands in AWS with a secure compliant and auditable posture. This is a technical build-focused role combining cloud security architecture infrastructure-as-code and Python automation. 

Key Responsibilities 

  • Define and implement the security controls guardrails and landing zone baseline for workloads migrating to AWS. 

  • Design and operate AWS-native security tooling across accounts and Organizations (see Technical Skills below). 

  • Build security automation in Python  remediation Lambdas compliance-check scripts event-driven response and integrations with ticketing/SIEM systems. 

  • Author review and maintain infrastructure-as-code (Terraform and/or CloudFormation) for security services guardrails IAM networking and encryption. 

  • Integrate security into GitLab CI/CD pipelines  SAST IaC scanning secrets detection dependency/container scanning and policy-as-code gates. 

  • Assess the security posture of workloads before during and after migration; identify and remediate misconfigurations and vulnerabilities. 

  • Design secure network segmentation and connectivity between source environments and AWS (Direct Connect / VPN Transit Gateway security groups NACLs). 

  • Implement IAM least-privilege models identity federation and secrets management for migrated workloads. 

  • Define encryption standards (at rest and in transit) using KMS ACM and TLS policy. 

  • Support compliance and audit requirements (e.g. CIS Benchmarks NIST ISO 27001 SOC 2 PCI-DSS as applicable) and produce evidence. 

  • Partner with migration platform and application teams to unblock security issues without slowing delivery. 

  • Contribute to incident detection and response runbooks for the AWS environment. 


Qualifications :

Required Technical Skills 

AWS Security Tooling 

  • AWS Security Hub  aggregated findings standards and posture management 

  • Amazon GuardDuty  threat detection 

  • AWS Config  configuration compliance and drift detection custom/conformance rules 

  • AWS IAM / IAM Identity Center  least-privilege roles policies permission boundaries federation 

  • AWS KMS & ACM  encryption key management and certificates 

  • AWS WAF & Shield  application and DDoS protection 

  • Amazon Inspector  vulnerability scanning for EC2/ECR/Lambda 

  • AWS CloudTrail  audit logging and monitoring 

  • AWS Organizations & Service Control Policies (SCPs)  multi-account guardrails 

  • AWS Secrets Manager / Systems Manager Parameter Store  secrets handling 

  • Amazon Macie  sensitive data discovery (desirable) 

  • AWS Control Tower / Landing Zone  governed account provisioning 

Automation & Infrastructure-as-Code 

  • Python  security automation boto3 Lambda functions remediation scripts custom Config rules 

  • Terraform  modules for security services guardrails IAM networking 

  • CloudFormation  templates and (desirable) StackSets across accounts 

  • Familiarity with policy-as-code (e.g. OPA/Conftest cfn-guard Checkov tfsec) is a strong plus 

CI/CD & Version Control 

  • GitLab  repositories merge requests and GitLab CI/CD pipeline development 

  • Integrating security scanning into pipelines: SAST DAST IaC scanning secrets scanning SCA container image scanning 

  • Git branching code review and shift-left security practices 

Migration & Infrastructure 

  • Workload discovery and assessment ahead of migration 

  • AWS migration tooling (Application Migration Service / MGN DMS Migration Hub) desirable 

  • Hybrid networking: Direct Connect VPN Transit Gateway VPC design security groups NACLs 

  • Operating system security hardening (Linux and/or Windows) 

Required Experience & Qualifications 

  • 4 years in security engineering cloud security or infrastructure security (adjust to seniority). 

  • Demonstrable hands-on experience securing production AWS environments. 

  • Proven experience delivering or securing a cloud migration programme. 

  • Strong scripting/automation ability in Python. 

  • Experience with IaC (Terraform and/or CloudFormation) in a production setting. 

  • Comfortable working in a GitLab-based DevSecOps workflow. 

  • Solid understanding of security frameworks and compliance standards. 

Additional Information :

Why Version 1 

At Version 1 we believe in providing our employees with a comprehensive benefits package that prioritises their wellbeing professional growth and financial stability. 

  • Share in our success with our Quarterly Performance-Related Profit Share Scheme where employees collectively benefit from a share of our companys profits 
  • Strong Career Progression & mentorship coaching through our Strength in Balance & Leadership schemes with a dedicated quarterly Pathways Career Development programme 
  • Flexible/remote working Version 1 is tremendously understanding of life events and peoples individual circumstances and offer flexibility to help achieve a healthy work life balance 
  • Financial Wellbeing initiatives including; Pension Private Healthcare Cover Life Assurance Financial advice and an Employee Discount scheme 
  • Employee Wellbeing schemes including Gym Discounts Bike to Work Fitness classes Mindfulness Workshops Employee Assistance Programme and much more. Generous holiday allowance enhanced maternity/paternity leave marriage/civil partnership leave and special leave policies 
  • Educational assistance incentivised certifications and accreditations including AWS Microsoft Oracle and Red Hat 
  • Reward schemes including Version 1s Annual Excellence Awards & Call-Out platform. 
  • Environment Social and Community First initiatives allow you to get involved in local fundraising and development opportunities as part of fostering our diversity inclusion and belonging schemes. 

And many more exciting benefits drop us a note to find out more. 

Version 1 is an equal opportunities employer. 
 
We are committed to building a diverse inclusive and respectful workplace where everyone feels valued and able to thrive. We welcome applications from people of all backgrounds identities and lived experiences and we value the different perspectives people bring. 
 
We want every candidate to have a positive and accessible recruitment experience. If you need reasonable adjustments at any stage of the process please contact at Version 1. We will consider all requests carefully respectfully and confidentially. 

#LI-SS1


Remote Work :

No


Employment Type :

Full-time

We are seeking a hands-on Security Engineer to embed within a large-scale cloud migration programme moving workloads into AWS. You will be responsible for designing automating and enforcing security controls throughout the migration lifecycle ensuring that every workload lands in AWS with a secure ...

About Company

Company Logo

Version 1 has celebrated over 26 years in Technology Services and continues to be trusted by global brands to deliver solutions that drive customer success. Version 1 has several strategic technology partners including Microsoft, AWS, Oracle, Red Hat, OutSystems and Snowflake. We’re a ... View more

View Profile View Profile