Cybersecurity (Secure Software/Cloud Integration) Engineer

London
1 week ago
Create job alert

Overview

Expleo is a trusted partner for end-to-end, integrated engineering, quality services, and management consulting for digital transformation. We help businesses harness unrelenting technological change to deliver innovations that provide a competitive advantage and improve everyday life worldwide.

As part of the Expleo Digital and Emerging Technology (DET) team, you will report to the Head of Cybersecurity and play a key role within our forward-leaning Cybersecurity Practice. In this role, you will support the design and implementation of secure software development processes and cloud-native integration patterns for clients across multiple sectors.
This is a hands-on, delivery-focused role where you will embed DevSecOps principles into engineering pipelines, guide secure software development lifecycle (SSDLC) practices, and advise on adopting security tooling across cloud and hybrid environments. You will work closely with development, DevOps, and platform teams to uplift security maturity, enabling secure and scalable software delivery aligned with industry standards and compliance requirements.

Responsibilities

Embed security practices into software development pipelines by integrating DevSecOps principles, automation tools, and governance controls.
Support the definition, implementation, and continuous improvement of secure software development lifecycle (SSDLC) processes across internal and client delivery teams.
Advise on secure architecture patterns and controls for cloud-native, containerised, and hybrid applications, aligned with industry standards and best practices.
Collaborate with engineering, DevOps, and platform teams to guide the adoption of security tooling across CI/CD environments.
Conduct reviews of application architecture, infrastructure-as-code, and security configurations to identify risks and support remediation planning.
Provide input into security design decisions, threat modelling sessions, and architectural governance forums.
To support engineering teams and deliver clear, practical documentation, including secure development standards, integration guidelines, and process artefacts.
Stay informed on the evolving threat landscape, cloud security trends, and software security vulnerabilities to ensure contemporary and effective delivery.

Qualifications

A degree (or equivalent experience) in Cybersecurity, Computer Science, Software Engineering, or a related technical discipline.
Recognised industry certifications in cybersecurity or application security (CompTIA, ISC2, GIAC, ISACA, or CREST).
Highly desirable are certifications related to secure development and cloud security (CSSLP, AZ-500, SC-100/SC-200, AWS Security, GCSA, GCLD, or similar).
Familiarity with secure coding standards (OWASP, SEI CERT) and SSDLC models (Microsoft SDL, NIST (Apply online only) SSDF).
Knowledge or experience of Product Assurance Schemes (PAS) or product security frameworks (PAS 754, PAS 1296, or similar) is desirable.
DevOps, DevSecOps, or platform certifications (Kubernetes, Terraform, Azure DevOps, GitHub Actions) are advantageous.

Essential skills

Strong understanding of secure software development principles and the software development lifecycle (SDLC/SSDLC).
Proficiency in modern DevOps environments.
Practical experience with cloud security concepts and controls across at least one major cloud platform (AWS, Azure, or GCP).
Solid grasp of secure coding practices and common software vulnerabilities.
Ability to assess code, configurations, and architecture for security issues and provide practical remediation guidance.

Desired skills

Familiarity with infrastructure-as-code (IaC) security practices and tooling.
Knowledge of container orchestration platforms and associated security tooling.
Awareness of compliance and assurance frameworks relevant to secure software.
Understanding cloud-native security services and architectures, including Zero Trust models and shift-left security practices.
Exposure to secure software supply chain practices, including code provenance, dependency management, and SBOM generation.

Experience

Experience in cybersecurity, secure software engineering, or cloud security roles, with a strong emphasis on delivery.
Demonstrable experience embedding security controls and tooling into software development pipelines and DevOps environments.
Hands-on experience implementing or supporting secure development processes (SSDLC), code review practices, or CI/CD security integration.
Proven involvement in cloud-native or hybrid solution development with exposure to major cloud platforms.
Experience collaborating with developers, DevOps, architects, and platform teams to design and implement secure software solutions.
Exposure to application security tooling (SAST, DAST, SCA), cloud security services, and infrastructure-as-code security practices.
Familiarity with agile or DevOps-based delivery models and working across multiple stakeholders or client environments.

What do I need before I apply

You must have the right to work in the UK

Related Jobs

View all jobs

Cybersecurity Solutions Engineer

Cyber Security Consultant

Senior Security Architect

Business Development Manager - MSP/IT as a Service

IT Manager

Sales executive

Get the latest insights and jobs direct. Sign up for our newsletter.

By subscribing you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Cloud Computing Job Interview Warm‑Up: 30 Real Coding & System‑Design Questions

The world of cloud computing has rapidly evolved into a critical backbone for modern businesses. From running microservices on containerised infrastructure and automating continuous deployments, to architecting highly available, secure solutions at global scale—the cloud domain offers endless career opportunities. Whether you aim to become an AWS Solutions Architect, an Azure DevOps Engineer, or a GCP Cloud Developer, your expertise in designing, coding, and managing cloud‑native services can open doors across every industry. However, cloud job interviews can be challenging. Employers typically probe a wide array of topics, from traditional software engineering and system design to security, scalability, and cost optimisation in cloud environments. For many candidates, this means a broad but in-depth skillset, along with hands‑on demonstrations of your knowledge. In this guide, we’ll walk you through 30 real coding & system-design questions you might face when interviewing for cloud roles. Each question or scenario is designed to test both fundamental programming skills and the architectural insight needed for building, deploying, and maintaining cloud platforms. If you’re seeking new opportunities in the UK’s thriving cloud sector, www.cloud-jobs.co.uk is an excellent place to start. You’ll find roles spanning everything from core infrastructure engineering to hybrid cloud consulting. Let’s begin your interview prep journey now.

Negotiating Your Cloud Job Offer: Equity, Bonuses & Perks Explained

How to Secure a Compensation Package That Reflects Your Value in the UK’s Booming Cloud Computing Sector Introduction Cloud computing has become the backbone of modern enterprise infrastructure. From small start-ups deploying microservices to multinational corporations scaling complex data analytics, the demand for cloud-savvy professionals continues to accelerate. If you’re working in cloud architecture, DevOps, infrastructure security, or any other mid‑senior role in the cloud domain, your expertise is in high demand—and so is your ability to negotiate a well-rounded compensation package. While an attractive base salary is essential, limiting your focus to that figure alone can mean missing out on substantial financial and lifestyle gains. Cloud-focused employers, including both tech giants (AWS, Microsoft Azure, Google Cloud) and smaller cloud-native consultancies, often layer their offers with equity, bonuses, and a host of perks to stand out in a competitive market. By delving deeper into these compensation components, you can maximise your earnings and ensure your new role supports both your career growth and personal well-being. In this comprehensive guide, we’ll explore every dimension of negotiating a cloud job offer. Whether you’re an established Cloud Solutions Architect eyeing a role at a cutting-edge start-up or a mid‑senior DevOps engineer seeking a leadership position at a global corporation, you’ll find insights on how to evaluate, compare, and negotiate all elements—from salary and equity to perks like flexible working and training budgets. Read on to discover how to turn a standard job offer into a holistic package that truly reflects your impact in the cloud computing arena.

Cloud Jobs in the Public Sector: Exploring Opportunities Across GDS, NHS, MOD, and More

Cloud computing has become a cornerstone of modern IT infrastructure, reshaping how organisations store data, run applications, and manage complex workloads. While the private sector has long embraced this shift, the UK public sector is now catching up at an accelerated pace. From the Government Digital Service (GDS) to the National Health Service (NHS), and even the Ministry of Defence (MOD), major public sector bodies are migrating critical systems to cloud platforms like AWS, Azure, and Google Cloud. For IT professionals and aspiring technologists, cloud jobs in the public sector offer a unique blend of technical challenge, job stability, and the opportunity to make a tangible impact on society. In this blog post, we’ll explore why cloud computing is so vital to government and healthcare, the types of roles available, the skills and qualifications you’ll need, and how to stand out in a competitive recruitment landscape.