Implement security engineering, compliance automation, or DevSecOps ownership.

Bsfortis · United Kingdom · First seen 1 week ago
Mid level Cybersecurity
Apply on the employer's site

About this role

You will be a product-facing software engineer who uses managed services, event-driven architectures, serverless compute, and cloud SDKs as first-class building blocks within your application code. The ideal candidate writes elegant, testable software and reaches for the right cloud service to solve a problem, rather than re-engineering that service themselves. What this role is not . To be explicit about scope, this role does not involve: Building or maintaining internal developer platforms, CI/CD toolchains, or golden-path templates for other engineering teams. Managing cloud accounts, quotas, cost governance, or FinOps programmes. Acting as a cloud architect defining org-wide landing zones or guardrails. Running an SRE or on-call rota for infrastructure shared across the business. If you are energised by building software products that end users interact with, and cloud is your toolbox rather than your primary domain, this role is for you. What you’ll do Design, write, and own production-grade software services deployed to cloud infrastructure. Integrate cloud-native services (compute, storage, messaging, ML APIs, identity) directly into application logic — not as infrastructure concerns, but as engineering choices. Build and evolve event-driven, microservice, and serverless architectures that scale under real load. Write meaningful unit, integration, and end-to-end tests; own quality from commit to production. Participate in design and code reviews, raising the technical bar across the team. Instrument your services with logging, tracing, and metrics; respond to issues in the applications you own. Collaborate with product managers and other engineers to turn requirements into working, deployed software. Make pragmatic decisions about which cloud service (or which region) is the right choice for a given workload. Implement security engineering, compliance automation, or DevSecOps ownership. Software engineering foundation 5+ years of professional software engineering, with a strong portfolio of shipped, production systems. Fluency in at least two languages commonly used in cloud-native development — Python, Go, TypeScript/Node.js, Java, PHP, C#, or Rust. Strong grasp of software design principles: SOLID, DRY, domain-driven design, clean architecture, and knowing when not to apply them. Experience with RESTful and event-driven API design, including asynchronous patterns (queues, streams, pub/sub). Hands-on with containerisation (Docker) and container orchestration (Kubernetes or managed equivalents) as a consumer and developer. Solid understanding of distributed systems challenges: consistency, idempotency, retries, back-off, and failure modes. Proficiency with relational and non-relational databases — knowing when to choose which, and how to query and design schemas efficiently. Cloud proficiency…. hands-on, not conceptual Deep practical experience writing software that consumes services on at least one of AWS, Azure, or GCP — using their SDKs and APIs from application code. Familiarity with the others is a bonus, not a requirement.AWSAzureGCP Relevant AWS services (developer context): LambdaAPI GatewaySQS / SNSDynamoDBS3RDS / AuroraECS / EKSEventBridgeStep FunctionsCognitoIAM Ability to write infrastructure-as-code (Terraform, Pulumi, or CDK) to define the resources your own application depends on — not as a platform engineer, but as the developer responsible for your service’s full stack. Understanding of cloud IAM, least-privilege service accounts, and secret management as engineering hygiene, not a specialisation. Experience with cloud-native observability: structured logging, distributed tracing, and metrics dashboards. Delivery & collaboration Comfortable working in agile delivery cycles with high autonomy and accountability. Clear written and verbal communicator — able to articulate trade-offs to engineers and non-engineers alike. Deep expertise in one cloud is the baseline; multi-cloud experience is a significant advantage. Nice to have Experience building software deployed on more than one cloud provider, or migrating workloads between them. Familiarity with cloud-native data streaming platforms (Kafka, Kinesis, Pub/Sub) in a producer/consumer capacity. Exposure to ML/AI managed services (SageMaker, Azure ML, Vertex AI) integrated into application workflows. Prior experience contributing to open-source projects or cloud provider SDKs. Knowledge of service mesh patterns (Istio, Linkerd) or API gateway customisation. Experience in regulated industries (fintech, healthtech) where compliance shapes software design.

What this role is, and what else it is called

Employers in the UK advertise this kind of work as Security Engineer, Fire & Security Engineer, Cybersecurity Engineer and Cyber Security Consultant too, so it is worth searching more than one wording. It is a mid-level Cybersecurity role in the UK, advertised without a stated working pattern, which is worth asking about.

About hiring at Bsfortis

Bsfortis has 3 other live technology roles on its careers page, across Software Engineering, DevOps, Platform & SRE and Cybersecurity. See all Bsfortis roles, salaries and stack.

How this role compares to the market

1,965 live UK roles list Python right now, from 584 employers. The median advertised salary is £80,000; 30% are advertised as remote. Browse Python roles.

1,304 live UK roles list Java right now, from 330 employers. The median advertised salary is £90,000; 32% are advertised as remote. Browse Java roles.

Market figures are today's snapshot of live UK roles on employer careers pages; see hiring trends.

Technologies mentioned

Detected on Bsfortis's careers page. ProdReady Recruitment lists this vacancy as an aggregator and is not the employer; applications go to the employer's own site.

Get these jobs by email

New matching UK IT roles, straight to your inbox. No spam -- unsubscribe any time.

We'll email you a confirmation link first -- nothing is sent until you click it.