We're looking for people to join the Access family, who share our passion for believing in better, and who will help us continue to grow.
Love Work. Love Life. Be You. - is central to our success and how we give our customers the freedom to do more of what's important to them.
What does Access offer you?
We offer a flexible, hybrid working environment where you can balance work and life while maintaining a strong office team-based culture. We deliver on what we say, taking the development of our people seriously. We'll work with you to progress your success plan and provide opportunities to accelerate your career. On top of a competitive salary, our wellbeing days taking you to 25 days leave a year and a health contribution, you'll also be able to choose from a range of benefits to suit you. We're an organisation that likes to give back, so you'll also have three charity days allocated to support a cause that matters to you.
Position Overview :
We are seeking an experienced Cloud Security Engineer to lead our cloud infrastructure security initiatives as part of our Infrastructure Vulnerability Management program. This role focuses on securing our cloud infrastructure and ensuring robust security posture across multi-cloud environments, with specific emphasis on identifying, assessing, and managing security vulnerabilities and misconfigurations across Azure (primary), AWS, and Google Cloud Platform environments.
As a Cloud Security Engineer, you will serve as the primary technical expert for cloud security vulnerability management, working closely with DevOps, cloud architects, and development teams to secure our cloud-native infrastructure, reduce cloud-specific attack surfaces, and integrate security throughout the cloud development lifecycle.
Key Responsibilities :
Cloud Security Architecture & Posture Management
- Design and implement security controls for cloud infrastructure across Azure, AWS, and GCP environments
- Implement, configure, and manage Cloud Security Posture Management (CSPM) tools across all cloud platforms
- Deploy and maintain cloud vulnerability scanning solutions including Prisma Cloud, and native cloud security services
- Continuously monitor cloud infrastructure for security misconfigurations, and compliance violations
- Develop and maintain cloud security baselines and configuration standards
- Assess cloud-native services, serverless functions, and container environments for security vulnerabilities
Infrastructure Vulnerability Management
Manage comprehensive vulnerability scanning and remediation for cloud infrastructure, ensuring asset coverage and timely patchingConduct comprehensive security assessments across multi-cloud environments and hybrid infrastructurePerform vulnerability scanning of cloud workloads, virtual machines, containers, and cloud-native applicationsAnalyze cloud security findings and validate vulnerabilities specific to cloud environmentsMonitor and assess Infrastructure as Code (IaC) templates for security misconfigurations before deploymentTrack and prioritize cloud infrastructure vulnerabilities based on risk and business impactDevSecOps Integration & Security Automation
Integrate cloud security tools into CI / CD pipelines and support container security initiativesImplement security scanning integration into CI / CD pipelines and DevOps workflowsDevelop and maintain Infrastructure as Code (IaC) security templates and automated security policy enforcementDevelop automation scripts for cloud security monitoring, alerting, and remediation workflowsCollaborate with DevOps teams to implement "shift-left" security practices in cloud deploymentsCreate and maintain cloud security automation using tools like Terraform, CloudFormation, ARM templatesImplement cloud security orchestration and automated response capabilitiesCloud Risk Assessment & Compliance Monitoring
Ensure compliance with cloud security frameworks including CIS Benchmarks, AWS Well-Architected Framework, Azure Security Benchmark, and GCP Security Command Center recommendationsConduct cloud security assessments for regulatory compliance in cloud environmentsCreate and maintain risk documentation for cloud security exceptions and accepted risksCreate and maintain cloud security policies, standards, and procedures aligned with NIST CSF 2.0Cloud Remediation Coordination & Incident Response
Partner with cloud engineering, DevOps, and development teams to coordinate cloud security remediationProvide technical guidance on cloud security best practices and remediation approachesTrack cloud security remediation progress and ensure issues are addressed within established SLAsParticipate in cloud security incident response and forensic investigationsSupport incident response for cloud security events and breachesMaintain cloud security remediation tracking and reporting dashboardsRequired Qualifications :
Education & Experience
Bachelor's degree in Cybersecurity, Cloud Computing, Information Technology, or related field2-3 years of hands-on experience in cloud security, cloud infrastructure, or related cybersecurity roles1 year of experience with cloud vulnerability management and CSPM toolsStrong experience with AzureExperience managing security across major cloud platforms in enterprise environmentsCloud Security Expertise
Proficiency with Cloud Security Posture Management (CSPM) platform : Prisma Cloud or similar solutionsStrong experience with native cloud security services : AWS Security Hub / Config, Azure Security Center / Defender, GCP Security Command CenterProficiency with cloud vulnerability scanning and cloud workload protection platformsWorking knowledge of container security tools and Kubernetes security scanningUnderstanding of cloud compliance frameworks and automated compliance monitoringTechnical Skills
Advanced knowledge of major cloud platforms : AWS, Microsoft Azure, Google Cloud PlatformInfrastructure as Code expertise : Terraform, CloudFormation, ARM templatesContainer and orchestration experience : Docker, Kubernetes, or similarScripting and automation : Python, PowerShell, Bash, YAML for cloud security automationCI / CD integration : Jenkins, GitLab CI, Azure DevOps, GitHub Actions for security pipeline integrationCloud networking : VPCs, security groups, network ACLs, cloud firewalls, and micro-segmentationUnderstanding of network security in cloud environments and container technologiesDevSecOps & Development
Experience with DevSecOps practices and security integration in cloud-native developmentKnowledge of secure coding practices for cloud applications and microservicesUnderstanding of API security and cloud service authentication mechanismsFamiliarity with cloud-native application architectures and serverless security considerationsCompliance & Standards
Knowledge of cloud security frameworks : CIS Cloud Benchmarks, NIST Cloud Computing Framework, Cloud Controls MatrixUnderstanding of shared responsibility models across different cloud providersFamiliarity with cloud compliance programs : SOC 2, ISO 27001, PCI-DSS, FedRAMPFamiliarity with data protection regulations in cloud environments : GDPR, CCPA, HIPAAKey Performance Indicator :
Achieve 99%+ asset coverage and scanning coverage across all cloud environmentsSuccessfully integrate security scanning into >90% of cloud deployment pipelines
Minimize critical cloud vulnerability exposure time toTrack cloud security remediation progress and ensure SLA complianceRespond to cloud security incidents within 30 minutes of detectionAutomate 80%+ of routine security configuration and compliance checksReduce cloud security incidents through proactive vulnerability managementSuccessfully integrate security controls into development workflowsAchieve high adoption rates of cloud security tools and practices across teamsWhat are we all about?
The Access Group is one of the largest UK-headquartered providers of business management software to small and mid-sized organisations in the UK, Ireland, USA and Asia Pacific. It helps more than 100,000 customers across commercial and non-profit sectors become more productive and efficient. Our products and solutions go beyond providing technology, we connect the right people with the right data, at the right time, through Access Workspace.
At Access, we are committed to creating a welcoming and inclusive environment where everyone can thrive. If you're excited about this role, (even if your previous experience doesn't align perfectly), you might just be the perfect fit for us We wholeheartedly believe in equality for all and the transformative power of diversity. Why not join our vibrant team where you can love what you do, love how you live, and most importantly, be authentically you? Let's make a difference together.
Love Work. Love Life. Be You.