Skip to main content
Version 1

Security Engineer – Cloud Migration to AWS

RemoteUnited Kingdom only
Published
Role
Security
Experience
Mid
Employment
Full-time
Company size
Enterprise
Salary not disclosed
Check eligibility

Open to GB only. Set where you work from to check your eligibility.

No BS summary

Hands-on Security Engineer for a large AWS cloud migration programme. Needs 4+ years in security/cloud/infrastructure security, production AWS security experience, Python automation, IaC with Terraform and/or CloudFormation, and GitLab DevSecOps. UK-based role across listed UK locations with flexible/remote working.

Core skills

PythonTerraform/CloudFormationAWS Security

Required skills

AWSAWS Security HubAmazon GuardDutyAWS ConfigAWS IAMIAM Identity CenterAWS KMSACMAWS WAFAWS ShieldAmazon InspectorAWS CloudTrailAWS OrganizationsService Control PoliciesAWS Secrets ManagerSystems Manager Parameter StoreAWS Control TowerLanding Zoneboto3AWS LambdaGitLabGitLab CI/CDSASTDASTIaC scanningsecrets scanningSCAcontainer image scanningGitDirect ConnectVPNTransit GatewayVPCsecurity groupsNACLsLinux/WindowsKMSTLS

Optional skills

Amazon MacieStackSetsOPAConftestcfn-guardCheckovtfsecApplication Migration Service

What you'll do

  • Define and implement the security controls, guardrails, and landing zone baseline for workloads migrating to AWS.
  • Design and operate AWS-native security tooling across accounts and Organizations.
  • Build security automation in Python — remediation Lambdas, compliance-check scripts, event-driven response, and integrations with ticketing/SIEM systems.
  • Author, review, and maintain infrastructure-as-code (Terraform and/or CloudFormation) for security services, guardrails, IAM, networking, and encryption.
  • Integrate security into GitLab CI/CD pipelines — SAST, IaC scanning, secrets detection, dependency/container scanning, and policy-as-code gates.
  • Assess the security posture of workloads before, during, and after migration; identify and remediate misconfigurations and vulnerabilities.
  • Design secure network segmentation and connectivity between source environments and AWS (Direct Connect / VPN, Transit Gateway, security groups, NACLs).
  • Implement IAM least-privilege models, identity federation, and secrets management for migrated workloads.
  • Define encryption standards (at rest and in transit) using KMS, ACM, and TLS policy.
  • Support compliance and audit requirements (e.g. CIS Benchmarks, NIST, ISO 27001, SOC 2, PCI-DSS as applicable) and produce evidence.
  • Partner with migration, platform, and application teams to unblock security issues without slowing delivery.
  • Contribute to incident detection and response runbooks for the AWS environment.

What they require

  • AWS Security Hub – aggregated findings, standards, and posture management
  • Amazon GuardDuty – threat detection
  • AWS Config – configuration compliance and drift detection, custom/conformance rules
  • AWS IAM / IAM Identity Center – least-privilege roles, policies, permission boundaries, federation
  • AWS KMS & ACM – encryption key management and certificates
  • AWS WAF & Shield – application and DDoS protection
  • Amazon Inspector – vulnerability scanning for EC2/ECR/Lambda
  • AWS CloudTrail – audit logging and monitoring
  • AWS Organizations & Service Control Policies (SCPs) – multi-account guardrails
  • AWS Secrets Manager / Systems Manager Parameter Store – secrets handling
  • AWS Control Tower / Landing Zone – governed account provisioning
  • Python – security automation, boto3, Lambda functions, remediation scripts, custom Config rules
  • Terraform – modules for security services, guardrails, IAM, networking
  • CloudFormation – templates and StackSets across accounts
  • Preferred: Amazon Macie – sensitive data discovery
  • Preferred: Familiarity with policy-as-code is a strong plus
  • GitLab – repositories, merge requests, and GitLab CI/CD pipeline development
  • Integrating security scanning into pipelines: SAST, DAST, IaC scanning, secrets scanning, SCA, container image scanning
  • Git branching, code review, and shift-left security practices
  • Workload discovery and assessment ahead of migration
  • Hybrid networking: Direct Connect, VPN, Transit Gateway, VPC design, security groups, NACLs
  • Operating system security hardening (Linux and/or Windows)
  • Preferred: AWS migration tooling (Application Migration Service / MGN, DMS, Migration Hub)
  • 4+ years in security engineering, cloud security, or infrastructure security (adjust to seniority).
  • Demonstrable hands-on experience securing production AWS environments.
  • Proven experience delivering or securing a cloud migration programme.
  • Strong scripting/automation ability in Python.
  • Experience with IaC (Terraform and/or CloudFormation) in a production setting.
  • Comfortable working in a GitLab-based DevSecOps workflow.
  • Solid understanding of security frameworks and compliance standards.

Benefits

  • Share in our success with our Quarterly Performance-Related Profit Share Scheme, where employees collectively benefit from a share of our company's profits
  • Strong Career Progression & mentorship coaching through our Strength in Balance & Leadership schemes with a dedicated quarterly Pathways Career Development programme
  • Flexible/remote working, Version 1 is tremendously understanding of life events and people’s individual circumstances and offer flexibility to help achieve a healthy work life balance
  • Financial Wellbeing initiatives including; Pension, Private Healthcare Cover, Life Assurance, Financial advice and an Employee Discount scheme
  • Employee Wellbeing schemes including Gym Discounts, Bike to Work, Fitness classes, Mindfulness Workshops, Employee Assistance Programme and much more.
  • Generous holiday allowance, enhanced maternity/paternity leave, marriage/civil partnership leave and special leave policies
  • Educational assistance, incentivised certifications, and accreditations, including AWS, Microsoft, Oracle, and Red Hat
  • Reward schemes including Version 1’s Annual Excellence Awards & ‘Call-Out’ platform.
  • Environment, Social and Community First initiatives allow you to get involved in local fundraising and development opportunities as part of fostering our diversity, inclusion and belonging schemes.
  • And many more exciting benefits… drop us a note to find out more.

Version 1 delivers technology and transformation solutions for global brands and partners with technology leaders including Microsoft, AWS, Oracle, Red Hat, OutSystems, and Snowflake.

IT ServicesEnterpriseversion1.com
Salary not disclosed