Hiring.Camp

Senior Principal, Cloud Engineering

Forterro

·

1 week ago

Location
UK, Remote
Workplace
Remote
Department
Engineering
Seniority
Senior
Source
Pinpoint

Description

Senior Principal, Cloud Engineering

Department: Cloud Platform

Employment Type: Permanent

Location: UK, Remote



Description

Forterro is seeking a Senior DevSecOps Engineer to close the operational gap between Security tooling requirements, Platform automation and CloudOps execution across a multi-product AWS SaaS estate. This is a hands-on engineering role responsible for making security controls deployable, repeatable, measurable and operationally reliable.
The role is a dedicated for Security function but embedded within the Cloud Platform / Platform Engineering team so that it has the practical authority to implement controls through infrastructure-as-code, GitOps workflows, CI/CD pipelines and operational runbooks. Security will define risk, policy and control intent; Platform will provide automation patterns; CloudOps will maintain and patch operational systems; this role owns the bridge between those teams and ensures security tooling and configuration are successfully implemented and handed over.
You will take hands-on ownership of cloud workload protection, vulnerability and patch management automation, network perimeter controls, container and serverless security, and deployment health for security tooling such as CrowdStrike, Tenable, ManageEngine, Fortinet, Cloudflare and AWS-native security services. The role must close the gap by turning security requirements into working automation, verified configuration and clear operational acceptance criteria.
 


Responsibilities

  • Design, implement and maintain AWS security controls across IAM, networking, encryption, logging, account governance and guardrails.
  • Implement and maintain AWS-native security services and governance patterns, including AWS Organizations, Control Tower, Service Control Policies, IAM Access Analyzer, Security Hub, GuardDuty, Inspector, Config, CloudTrail, KMS and centralised logging where applicable.
  • Harden AWS accounts, services and workloads against CIS Benchmarks and Forterro security baselines, including documented exception and waiver processes for product-specific differences.
  • Translate security requirements into infrastructure-as-code, policy-as-code and reusable automation modules that can be deployed consistently across multiple products and environments.
  • Own the reliable deployment, configuration and operational health of security tooling across cloud and workload environments.
  • Ensure CrowdStrike Falcon endpoint and cloud workload protection is deployed, healthy, version-compliant and reporting correctly, including failed agent deployment remediation and coverage reporting.
  • Ensure Tenable scanning coverage is complete and reliable across cloud assets, with remediation workflows, exception handling and evidence reporting agreed with the Security team.
  • Operate and improve ManageEngine-based patch tooling and workflows, ensuring patch automation, compliance reporting, failure handling and maintenance windows are clear and repeatable.
  • Troubleshoot failed security-tool deployments and configuration drift across IAM, networking, Kubernetes, host agents, APIs, CI/CD and platform automation.
  • Operationalise vulnerability and patch management processes across the AWS estate, ensuring scan coverage, triage, remediation ownership and closure tracking are measurable.
  • Define, automate and report patch SLAs based on severity, asset criticality and business impact, including exception handling, rollback evidence and stakeholder communication.
  • Work with Security to prioritise risk and with CloudOps/Product teams to execute remediation safely through approved change-control processes.
  • Create dashboards and reports for patch compliance, vulnerability ageing, failed deployments, risk acceptance and remediation trends.
  • Implement, maintain and audit Fortinet firewall controls, including rule sets, segmentation, VPNs, policy reviews and configuration validation under change control.
  • Manage and validate Cloudflare services including WAF, DNS, CDN, DDoS protection and Zero Trust / access policies, using configuration-as-code where practical.
  • Partner with Security on policy intent while ensuring configuration is implemented accurately, tested and operationally supportable.
  • Secure and harden Kubernetes clusters, including Amazon EKS, RBAC, network policies, admission controls, secrets management, runtime controls and image provenance.
  • Integrate container image scanning, registry scanning, software composition analysis, secrets scanning and SBOM generation into CI/CD and runtime processes.
  • Establish and enforce baseline configurations and CIS Kubernetes Benchmark compliance using policy-as-code tooling such as OPA/Gatekeeper or Kyverno where appropriate.
  • Secure AWS Lambda and event-driven serverless services through least-privilege execution roles, dependency and code scanning, runtime monitoring, event-source control and API Gateway/WAF guardrails.
  • Implement and maintain infrastructure-as-code and automation using Terraform, Crossplane, CloudFormation where required, Ansible, Helm, Python, Bash/PowerShell and YAML.
  • Integrate security controls into GitLab CI/CD and GitOps workflows such as ArgoCD, including SAST, SCA, secrets scanning, IaC scanning, container scanning, policy gates and exception workflows.
  • Automate routine security operations including scanning, patch orchestration, configuration drift detection, evidence gathering and compliance reporting.
  • Convert repeatable runbooks into idempotent automation and reusable deployment patterns that CloudOps and product teams can consume safely.
  • Create clear runbooks, operational acceptance criteria, handover packs, service documentation, diagrams and support guidance for CloudOps and product teams.
  • Define and maintain a practical RACI for security tooling deployment and operation, reducing ambiguity between Security, Platform, CloudOps and product teams.
  • Participate in incident response and post-incident reviews where security tooling, control failures, vulnerability exposure or patch failures are involved.
  • Mentor engineers on secure practices and support continuous improvement across Platform Engineering, CloudOps and product delivery teams.
  • Evaluate new security technologies and products, produce evaluation reports, and recommend improvements aligned to business risk and SaaS platform strategy.


Skills, Knowledge & Expertise

  • 5+ years of hands-on experience in DevSecOps, Cloud Security Engineering, Platform Engineering, SRE or senior cloud engineering roles.
  • Strong working knowledge of AWS security architecture and services, including IAM, networking, encryption, logging, Organizations/SCPs, Security Hub, GuardDuty, Inspector, Config, CloudTrail and KMS.
  • Practical experience deploying, configuring or operating security tools such as CrowdStrike, Tenable, ManageEngine, Fortinet firewalls and Cloudflare.
  • Strong experience with infrastructure-as-code, GitOps and CI/CD tooling such as Terraform, CloudFormation, Ansible, Helm, ArgoCD, GitLab CI/CD and Git.
  • Proficiency with scripting and automation using Python, Bash, PowerShell and YAML.
  • Experience securing Kubernetes/EKS, container platforms and serverless workloads, including RBAC, network policies, admission controls, image scanning, secrets management and runtime monitoring.
  • Solid grasp of vulnerability management, patch management, risk-based remediation, change control, SLAs and compliance evidence.
  • Hands-on ability to troubleshoot failed automation, configuration drift and deployment failures across cloud, network, endpoint, Kubernetes and CI/CD layers.
  • Experience operating in a multi-team, multi-product SaaS or enterprise cloud environment.
  • Excellent communication, stakeholder management and ownership mindset, with the ability to reduce ambiguity between Security, Platform, CloudOps and product teams.
  • Relevant certifications such as AWS Certified Security - Specialty, Certified Kubernetes Security Specialist (CKS), CISSP, CCSP, GIAC, Terraform Associate or equivalent experience.
  • Experience with SIEM/SOAR platforms, security incident response and threat-informed remediation.
  • Familiarity with compliance frameworks such as ISO 27001, SOC 2, NIST and CIS.
  • Experience implementing policy-as-code 
  • Experience in SaaS platform standardisation, shared services, mergers/acquisitions integration or multi-account AWS governance.

Skills

PythonAWSKubernetesTerraformAnsibleCI/CDGitGitLabSIEMSOCSREComplianceSOC 2ISO 27001AWS CertifiedCISSP

Similar Jobs

30

Cloud Architect, Sr. Principal

Gdit · USA NE Offutt AFB - Offutt AFB (NEC003), United States of America · Hybrid

2 days ago

Cloud Architect, Sr. Principal

GDIT · USA NE Offutt AFB - Offutt AFB (NEC003), United States of America · Hybrid

2 days ago

Senior Principal Software Engineer - Cloud, Distributed Systems & Data Platforms

JPMorgan Chase · Bengaluru, Karnataka, India

4 days ago

Senior Principal Software Engineer - Cloud, Distributed Systems & Data Platforms

JP Morgan Chase · Bengaluru, Karnataka, India

4 days ago

Senior/Principal Product Manager, IaC Cloud

Pulumicorporation · Seattle, WA +1 · Remote

5 days ago

Principal/Sr. Principal Cloud Engineer (AHT)

Northrop Grumman · Wright-Patterson AFB, OH,US, US

1 week ago

Principal/Sr. Principal Cloud Engineer

Northrop Grumman · Rome, NY,US, US

1 week ago

Principal/ Sr. Principal Cloud Engineer

Northrop Grumman · Wright-Patterson AFB, OH,US, US

1 week ago

Sr. Principal Program Manager (Hyperscaler Cloud Data Center - full lifecycle program ownership)

Marvell · US-CA - Santa Clara, United States of America +2

1 week ago

Principal/Sr. Principal Cloud Engineer (AHT)

Northrop Grumman · OHWP10GC, United States of America

1 week ago

Principal/Sr. Principal Cloud Engineer

Northrop Grumman · NYRO03, United States of America

1 week ago

Principal/ Sr. Principal Cloud Engineer

Northrop Grumman · OHWP10GC, United States of America

1 week ago

Senior Principal Cloud Engineer

E-INFOSOL · Chantilly, VA

2 weeks ago

Sr. Principal Engineer/ Principal Engineer – Cloud Platform

Extremenetworks · San Jose, California, United States · Hybrid

2 weeks ago

Sr Principal Systems Administrator – X-Lab Cloud Tech Admin (26-244)

Northrop Grumman · Colorado Springs, CO,US, US · Onsite

2 weeks ago

Sr Principal Systems Administrator – X-Lab Cloud Tech Admin (26-244)

Northrop Grumman · COSC04GC, United States of America · Onsite

2 weeks ago

Oracle Cloud Financials Senior Principal Consultant

Apps Associates · Canada

3 weeks ago

Senior Principal Consultant - Oracle Cloud SCM

Apps Associates · United States, US · Remote

3 weeks ago

Senior Principal Consultant - Oracle Cloud SCM

Apps Associates · Canada

3 weeks ago

Senior Principal Consultant - Oracle Cloud SCM

Apps Associates · Ontario, Canada · Hybrid

4 weeks ago

Senior Principal Cloud Development Engineer

Depository Trust Company · LONDON, United Kingdom, GB

1 month ago

Sr Principal Software Engineer - Cloud

Northrop Grumman · CAES902, United States of America +1

1 month ago

Sr. Principal Cloud Lead

Waters · , US

1 month ago

Sr. Principal Cloud Lead

Us Waters · , US

1 month ago

Sr. Principal Product Engineer - Cloud and Hyperscale platforms

Jabil · USA - Austin, United States of America +1 · Remote

1 month ago

Sr. Principal AWS Cloud Architect – On Site at Wright Patt (TS/SCI)(AHT)

Northrop Grumman · Wright-Patterson AFB, OH,US, US · Onsite

1 month ago

Sr. Principal AWS Cloud Architect – On Site at Wright Patt (TS/SCI)(AHT)

Northrop Grumman · OHWP10GC, United States of America · Onsite

1 month ago

Senior Principal - Oracle Cloud Infrastructure AI Network Engineering

Oracle · Austin, TX, United States

1 month ago

Lead Senior Principal Cloud Developer with Node.JS and React.JS

GDIT · USA WA Home Office (WAHOME), United States of America · Remote

1 month ago

Sr Principal DevOps Engineer (Cloud) (26-297)

Northrop Grumman · Colorado Springs, CO,US, US · Remote, Onsite

1 month ago