Cloud Security Engineer – Leeds – National Security West
// Role Summary
Join BAE Systems Digital Intelligence as a Cloud Security Engineer in Leeds, developing innovative Security Operations Centre (SOC) capabilities. This role offers the chance to design, build, and maintain secure cloud-native solutions in a collaborative, cutting-edge environment.
// Key Responsibilities
- Design, build, and maintain secure cloud-native solutions for SOC capabilities.
- Develop and deploy cloud infrastructure using Infrastructure as Code (IaC).
- Implement secure AWS architectures aligning with security and compliance requirements.
- Build and maintain security monitoring, alerting, and automated response capabilities.
- Integrate cloud platforms with security tooling, including SIEM solutions.
// Role Specification
Cloud Security Engineer
BAE Systems Digital Intelligence is seeking talented and versatile Cloud Engineers to join our Engineering team in Leeds. You will be instrumental in supporting and developing our innovative Security Operations Centre (SOC) capabilities, working collaboratively to unlock digital advantage in demanding environments.
What You’ll Be Doing:
- Designing, building, and maintaining secure, cloud-native solutions to support our Security Operations Centre (SOC) capabilities.
- Developing and deploying cloud infrastructure using Infrastructure as Code (e.g., Terraform, CloudFormation, AWS CDK).
- Designing and implementing secure AWS architectures that align with security and compliance requirements.
- Building and maintaining security monitoring, alerting, and automated response capabilities across cloud environments.
- Integrating cloud platforms with security tooling, including SIEM solutions such as Microsoft Sentinel and Splunk.
- Leveraging AWS security services and promoting security best practices across engineering and development teams.
- Supporting incident response investigations, threat hunting activities, and security improvement initiatives.
- Developing reusable implementation patterns, standards, and automation to improve consistency and security across projects.
- Managing software configuration, source code repositories, and CI/CD pipelines in line with DevSecOps principles.
- Working closely with internal and external stakeholders to deliver secure and innovative cloud solutions.
- Identifying opportunities to leverage AI and automation to enhance security operations and operational efficiency.
- For Senior Engineers, leading technical delivery, mentoring engineers, and driving engineering best practices within the team.
What We’re Looking For:
- Skilled in a range of AWS services and committed to staying current with the latest releases and best practices.
- Experience with AWS security services and implementing cloud security best practices, including identity, monitoring, threat detection, and data protection.
- Understanding of Security Operations, including monitoring, alerting, incident response, threat detection, and SIEM platforms (e.g., Microsoft Sentinel, Splunk).
- Strong understanding of Identity and Access Management (IAM), least-privilege access principles, and privileged access controls.
- Knowledge of DevSecOps practices and integrating security controls into CI/CD pipelines.
- Experience using Infrastructure as Code (e.g., Terraform, CloudFormation, AWS CDK).
- Experience with monitoring and observability tools (e.g., CloudWatch, Grafana, Prometheus).
- Experience with container orchestration platforms (e.g., Kubernetes, Amazon ECS, OpenShift), including container security best practices.
- Understanding of networking principles and their application in cloud environments.
- Experience using configuration management tools (e.g., Ansible, Puppet, Chef).
- Proficiency in scripting in at least one language (e.g., Python, Bash, Go).
- A keen interest in AI and emerging cyber security technologies.
- Excellent troubleshooting, automation, and problem-solving skills.
- A collaborative mindset with a passion for learning new technologies and cyber security trends.
Support and Benefits:
We value work-life balance and offer 25 days holiday, flexible working hours, and the option to buy/sell/carry over holiday. Our flexible benefits package includes private medical and dental insurance, a competitive pension scheme, cycle to work scheme, and more. You’ll have a dedicated Career Manager and access to excellent training courses to support your professional development. AWS certifications are desirable but not essential; training and certification opportunities are provided.
Security Clearance:
Due to the nature of the work, successful candidates will be required to undergo Government SC clearance prior to starting and obtain Developed Vetting once employed. All applicants must achieve Baseline Personnel Security Standard (BPSS) as a minimum. A minimum of 5-10 years of continuous residency in the UK is typically required for National Security Vetting.