Kainos Logo

Kainos

Senior Security Engineer

Posted Yesterday
Be an Early Applicant
In-Office or Remote
Hiring Remotely in UK
Senior level
In-Office or Remote
Hiring Remotely in UK
Senior level
Design and implement secure cloud-based solutions and DevSecOps practices. Automate security tooling in CI pipelines, perform threat modelling and vulnerability management, support penetration testing, review security outputs, convert findings into actionable work, verify secure architectures, and coach junior team members.
The summary above was generated by AI
Join Kainos and Shape the Future 

At Kainos, we’re problem solvers, innovators, and collaborators - driven by a shared mission to create real impact. Whether we’re transforming digital services for millions, delivering cutting-edge Workday solutions, or pushing the boundaries of technology, we do it together.

We believe in a people-first culture, where your ideas are valued, your growth is supported, and your contributions truly make a difference. Here, you’ll be part of a diverse, ambitious team that celebrates creativity and collaboration.

Ready to make your mark? Join us and be part of something bigger.

As a Senior Security Engineer, you will work in close collaboration with our technology teams to design and implement secure, cloud-based software solutions for our clients. Working as part of a multi-disciplinary Agile team, you will implement DevSecOps practices throughout the software development lifecycle, embedding security practices (e.g. vulnerability management, threat modelling etc.) and automating security artifact generation (e.g. secret scanning, container security, SAST, DAST etc.). You will provide subject matter expertise in application security or cloud security – sharing knowledge on threats and vulnerabilities, identifying appropriate security controls, and increasing cyber security awareness within teams.

Your key responsibilities will include:

  • Daily collaboration with the application development and cloud platform teams to plan and prioritise security requirements as part of the secure software development lifecycle (SSDLC).

  • Recommending security best practices for cloud platforms and automating compliance with cloud security baselines (e.g. CIS Benchmarks).

  • Implementation of automated security tooling (e.g. within a Continuous Integration (CI) pipeline) to validate security requirements and identify potential issues.

  • Working with external organisations to plan, scope and facilitate penetration tests.

  • Reviewing the outputs from security tools and security practices. You will filter and prioritise these into security stories that can be understood and actioned by the delivery teams.

  • Verifying the implementation of security principles, architectural patterns, and requirements.

  • Driving the adoption of cyber security practices (e.g. vulnerability management, threat modelling etc.) within Agile delivery teams.

  • Putting people first & developing others – You’ll help coach and develop more junior members of the team.

Minimum (essential) requirements:

  • Experience of implementing application security or Cloud platform security.

  • Experience in Defence Sector

  • Active Security Clearance

  • A detailed understanding of web application security.

  • An understanding of modern cryptography and its application for encryption in-transit, encryption at-rest, hashing and digital signatures.

  • An understanding of security practices such as threat modelling, vulnerability management, application security testing, and penetration testing.

  • Experience of integrating application security tools (e.g. static analysis, dynamic analysis etc.) into the SSDLC.

  • Experience of using modern version control systems (e.g. git) and either a scripting language (e.g. Bash, Powershell etc.), or a programming language (e.g. Python, Java, .NET, JS etc.), or an Infrastructure as Code language (e.g. Terraform, ARM Templates, Ansible etc.) to automate tasks.

  • The ability to convey security issues to technical and non-technical people.

Desirable:

  • An industry recognised qualification in Cyber Security.

  • AWS or Azure mid-level certifications.

  • Participation in the cyber security community (e.g. OWASP, HackTheBox, CTFs etc.).

  • Experience working with agile software development methodologies (e.g. Scrum or Kanban).

Embracing our differences   

At Kainos, we believe in the power of diversity, equity and inclusion. We are committed to building a team that is as diverse as the world we live in, where everyone is valued, respected, and given an equal chance to thrive.   We actively seek out talented people from all backgrounds, regardless of age, race, ethnicity, gender, sexual orientation, religion, disability, or any other characteristic that makes them who they are.   We also believe every candidate deserves a level playing field. 

Our friendly talent acquisition team is here to support you every step of the way, so if you require any accommodations or adjustments, we encourage you to reach out. 

We understand that everyone's journey is different, and by having a private conversation we can ensure that our recruitment process is tailored to your needs.


Kainos London, England Office

2nd Floor, 21 Farringdon Road Clerkenwell, London, United Kingdom, EC1M 3HA

Similar Jobs

Yesterday
In-Office or Remote
United Kingdom
Senior level
Senior level
Blockchain
Lead and own the information security program and security engineering at NEAR Foundation. Drive SOC 2 Type 2 and ISO 27001 readiness, run logging/monitoring/incident response, manage vulnerability and third-party risk, harden identity/access/endpoint stacks, automate security and compliance across SaaS, and advise on tooling and cloud security (AWS/GCP).
Top Skills: AWSBashEdrEntraGCPGoGoogle WorkspaceIamIso 27001LoggingMdmMfaMonitoringOktaPythonSIEMSoc IiSso
Yesterday
In-Office or Remote
United Kingdom
Senior level
Senior level
Big Data • Healthtech • Software • Biotech
Lead security engineering across web apps, APIs, cloud (AWS/OCI), Kubernetes, and on-prem systems. Build CI/CD security, secure genomic and PHI/PII pipelines (HIPAA), run monitoring and incident response, prepare for HIPAA/SOC2/ISO27001 audits, perform pentesting/vulnerability discovery, improve logging/SIEM, and drive remediation with engineering and DevOps while raising company-wide security awareness.
Top Skills: AWSBurp SuiteCi/CdCloudflareCloudtrailCodeqlContainersDockerFalcoGitGitGoogle WorkspaceIamKubernetesLog AggregationMetasploitNetwork PoliciesOciOwasp ZapRbacSecrets ManagementSemgrepSIEMTerraform
Yesterday
Remote
GBR
Senior level
Senior level
Information Technology
Lead security engineering for Hummingbird's infrastructure: harden AWS (Terraform), manage vulnerability and dependency tooling, develop threat intelligence, own incident response and disaster recovery, and shape long-term security posture while collaborating across a small senior engineering team.
Top Skills: AWSAzureCircleCID3DockerGraphQLJavaScriptNixOpenaiPostgresPythonReactRedisRubyRuby On RailsTerraformTypescript

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account