Carbon3.ai Logo

Carbon3.ai

Security Engineer

Posted 5 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in United Kingdom
Senior level
Remote
Hiring Remotely in United Kingdom
Senior level
Design, implement, and improve security controls across Kubernetes, cloud-native, and datacentre infrastructure. Secure networks and firewalls, integrate DevSecOps controls into CI/CD, lead vulnerability management, build detection/response capabilities, automate security workflows, and support incident response and threat hunting for GPU-accelerated and AI/ML platforms.
The summary above was generated by AI

Era4 develops, owns and operates AI infrastructure across the UK, powered by renewable energy. Converting legacy industrial and energy sites into modern data-centre facilities, Era4 is combining brownfield regeneration opportunities with cleaner, efficient, scalable compute capacity for healthcare, research, finance, enterprise, and public-sector organisations


Must have the ability to achieve Security Clearance. (Won't be an immediate request but within the next 12 months). 


We are seeking a Security Engineer to design, implement, and continuously improve security controls across our next-generation AI infrastructure and datacentre operations. This role focuses on protecting Kubernetes-based and cloud-native environments, securing our datacentre networking and infrastructure stack, strengthening security posture, identifying and mitigating risks, and enabling secure software delivery practices.

 

You will work closely with engineering, platform, and operations teams to integrate security into Era4's proprietary cloud infrastructure, datacentre networks, CI/CD pipelines, containerized workloads, GPU-accelerated compute, and AI/ML platforms. The successful candidate will combine hands-on technical expertise with a proactive approach to threat detection, vulnerability management, and security automation across our brownfield-to-modern bare metal and cloud infrastructure environments.

 

Key Responsibilities:

Cloud & Infrastructure Security

  • Design, implement, and maintain security standard and controls for on prem Kubernetes.
  • Review infrastructure architectures and perform security assessments to identify risks and recommend mitigations.

 

Application & DevSecOps Security

  • Integrate security controls into CI/CD pipelines, including SAST, DAST, dependency scanning, container image scanning, and secrets detection.
  • Partner with development teams to implement secure coding practices and remediate security findings.
  • Conduct threat modelling and security reviews for new applications, services, and infrastructure changes.

 

Vulnerability & Risk Management

  • Lead vulnerability identification, prioritisation, remediation, and reporting activities across infrastructure and applications.

 

Detection & Response

  • Develop and maintain security monitoring, alerting, detection capabilities and incident response playbooks.
  • Investigate security incidents, perform root cause analysis, and coordinate remediation activities.

 

Security Automation

  • Build automation to improve security monitoring, compliance validation, vulnerability management, and incident response workflows.
  • Leverage Infrastructure as Code and policy-as-code frameworks to enforce security standards at scale.


Required Qualifications & Experience

  • Experience in Security Engineering, Cloud Security, DevSecOps, Infrastructure Security, or Datacentre Security.
  • Hands-on experience with vulnerability management platforms and security assessment methodologies.
  • Familiarity with CI/CD security controls, secure software development practices, and supply chain security.
  • In-depth scripting and automation skills using Python, Bash, or similar languages.

 

Nice to have:

  • Experience securing AI/ML or GPU-based infrastructure, datacentre network security, firewalls, and network segmentation (Palo Alto firewalls, OpnSense, Nokia networking, or similar).
  • Familiarity with compliance frameworks such as SOC 2, ISO 27001, NIST CSF, CIS Benchmarks, or PCI DSS.
  • Experience with threat modelling, penetration testing, or red team engagements.
  • Security certifications such as CISSP, GSEC, GCIH, GCIA, CCSK, CCSP, or relevant cloud security certifications.


Why Join Era4:

You’ll be joining a mission-driven start-up building critical national infrastructure, where operational excellence directly enables growth. This role offers high visibility with leadership, real autonomy, and the chance to shape how a next-generation company operates at scale.


Diversity & Inclusion

Era4 is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. 

HQ

Carbon3.ai Tonbridge and Malling, England Office

Tonbridge and Malling, United Kingdom

Similar Jobs

Yesterday
Easy Apply
Remote
United Kingdom
Easy Apply
Entry level
Entry level
Cloud • Security • Software • Cybersecurity • Automation
Build and maintain Ruby on Rails backend features for vulnerability management, including security dashboards, reports, and ingestion pipelines. Improve system performance, reliability, and scalability; collaborate across backend, frontend, product, design, and security teams; review code; address technical debt; and participate in on-call rotations. The role requires relational database experience, distributed-team collaboration, technical problem-solving, and contributions across the stack when needed.
Top Skills: ElasticsearchGraph DatabasesJavaScriptPostgresRubyRuby On RailsVue
2 Days Ago
Remote
United Kingdom
Expert/Leader
Expert/Leader
Marketing Tech
Lead Pantheon's security operations strategy and roadmap, including SIEM/SOAR architecture, threat detection, incident response, threat intelligence, automation, vulnerability and abuse management, and operational resilience. Own security operations compliance for GDPR, NIS2, SOC 2, PCI DSS, and NIST CSF. Lead major incident response, executive reporting, cross-functional initiatives, and mentorship while remaining hands-on with cloud-native security, detection engineering, and security automation.
Top Skills: AWSBashChronicleCloud Security Posture ManagementEdr/XdrElastic SiemGCPIamMandiant AdvantageMitre Att&CkMitre D3FendNist CsfPalo Alto XsoarPythonRecorded FutureSIEMSoarSplunkTines
3 Days Ago
In-Office or Remote
London, Greater London, England, GBR
Senior level
Senior level
Utilities
Design and implement security for a cloud-native B2B SaaS platform. Responsibilities include cloud and Kubernetes security, threat modeling, application and infrastructure hardening, vulnerability management, detection and incident response, security automation, and compliance assurance. The role partners with Engineering, SRE, Risk, Product, Legal, and InfoSec teams to embed secure-by-design practices, automate controls through infrastructure as code and CI/CD, and improve security metrics, detection capabilities, and regulatory readiness.
Top Skills: AWSBashCi/CdCloudFormationDastEdrGoIamIdentity ProvidersIdsInfrastructure As CodeKmsKubernetesPythonSastSecure Web GatewaysTerraformWaf

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account