Forterro Logo

Forterro

Senior Principal, Cloud Engineering

Posted 6 Days Ago
Be an Early Applicant
Remote or Hybrid
Hiring Remotely in UK
Senior level
Remote or Hybrid
Hiring Remotely in UK
Senior level
Hands-on DevSecOps role bridging Security, Platform and CloudOps to implement deployable, repeatable AWS security controls. Responsibilities include automating vulnerability and patch management, deploying and maintaining security tooling (CrowdStrike, Tenable, ManageEngine, Fortinet, Cloudflare), securing Kubernetes/EKS and serverless, building IaC/GitOps automation (Terraform, CloudFormation, Crossplane, ArgoCD), and producing operational runbooks, SLAs and dashboards for sustained operational health across a multi-product SaaS AWS estate.
The summary above was generated by AI
Forterro is seeking a Senior DevSecOps Engineer to close the operational gap between Security tooling requirements, Platform automation and CloudOps execution across a multi-product AWS SaaS estate. This is a hands-on engineering role responsible for making security controls deployable, repeatable, measurable and operationally reliable.
The role is a dedicated for Security function but embedded within the Cloud Platform / Platform Engineering team so that it has the practical authority to implement controls through infrastructure-as-code, GitOps workflows, CI/CD pipelines and operational runbooks. Security will define risk, policy and control intent; Platform will provide automation patterns; CloudOps will maintain and patch operational systems; this role owns the bridge between those teams and ensures security tooling and configuration are successfully implemented and handed over.
You will take hands-on ownership of cloud workload protection, vulnerability and patch management automation, network perimeter controls, container and serverless security, and deployment health for security tooling such as CrowdStrike, Tenable, ManageEngine, Fortinet, Cloudflare and AWS-native security services. The role must close the gap by turning security requirements into working automation, verified configuration and clear operational acceptance criteria.
 

Responsibilities
Key ResponsibilitiesCloud Security Engineering - AWS
  • Design, implement and maintain AWS security controls across IAM, networking, encryption, logging, account governance and guardrails.
  • Implement and maintain AWS-native security services and governance patterns, including AWS Organizations, Control Tower, Service Control Policies, IAM Access Analyzer, Security Hub, GuardDuty, Inspector, Config, CloudTrail, KMS and centralised logging where applicable.
  • Harden AWS accounts, services and workloads against CIS Benchmarks and Forterro security baselines, including documented exception and waiver processes for product-specific differences.
  • Translate security requirements into infrastructure-as-code, policy-as-code and reusable automation modules that can be deployed consistently across multiple products and environments.
Security Tooling Deployment and Operational Health
  • Own the reliable deployment, configuration and operational health of security tooling across cloud and workload environments.
  • Ensure CrowdStrike Falcon endpoint and cloud workload protection is deployed, healthy, version-compliant and reporting correctly, including failed agent deployment remediation and coverage reporting.
  • Ensure Tenable scanning coverage is complete and reliable across cloud assets, with remediation workflows, exception handling and evidence reporting agreed with the Security team.
  • Operate and improve ManageEngine-based patch tooling and workflows, ensuring patch automation, compliance reporting, failure handling and maintenance windows are clear and repeatable.
  • Troubleshoot failed security-tool deployments and configuration drift across IAM, networking, Kubernetes, host agents, APIs, CI/CD and platform automation.
Vulnerability, Patch and Risk Remediation
  • Operationalise vulnerability and patch management processes across the AWS estate, ensuring scan coverage, triage, remediation ownership and closure tracking are measurable.
  • Define, automate and report patch SLAs based on severity, asset criticality and business impact, including exception handling, rollback evidence and stakeholder communication.
  • Work with Security to prioritise risk and with CloudOps/Product teams to execute remediation safely through approved change-control processes.
  • Create dashboards and reports for patch compliance, vulnerability ageing, failed deployments, risk acceptance and remediation trends.
Network and Perimeter Security
  • Implement, maintain and audit Fortinet firewall controls, including rule sets, segmentation, VPNs, policy reviews and configuration validation under change control.
  • Manage and validate Cloudflare services including WAF, DNS, CDN, DDoS protection and Zero Trust / access policies, using configuration-as-code where practical.
  • Partner with Security on policy intent while ensuring configuration is implemented accurately, tested and operationally supportable.
Kubernetes, Container and Serverless Security
  • Secure and harden Kubernetes clusters, including Amazon EKS, RBAC, network policies, admission controls, secrets management, runtime controls and image provenance.
  • Integrate container image scanning, registry scanning, software composition analysis, secrets scanning and SBOM generation into CI/CD and runtime processes.
  • Establish and enforce baseline configurations and CIS Kubernetes Benchmark compliance using policy-as-code tooling such as OPA/Gatekeeper or Kyverno where appropriate.
  • Secure AWS Lambda and event-driven serverless services through least-privilege execution roles, dependency and code scanning, runtime monitoring, event-source control and API Gateway/WAF guardrails.
DevSecOps, GitOps and Automation
  • Implement and maintain infrastructure-as-code and automation using Terraform, Crossplane, CloudFormation where required, Ansible, Helm, Python, Bash/PowerShell and YAML.
  • Integrate security controls into GitLab CI/CD and GitOps workflows such as ArgoCD, including SAST, SCA, secrets scanning, IaC scanning, container scanning, policy gates and exception workflows.
  • Automate routine security operations including scanning, patch orchestration, configuration drift detection, evidence gathering and compliance reporting.
  • Convert repeatable runbooks into idempotent automation and reusable deployment patterns that CloudOps and product teams can consume safely.
Operational Enablement, Governance and Collaboration
  • Create clear runbooks, operational acceptance criteria, handover packs, service documentation, diagrams and support guidance for CloudOps and product teams.
  • Define and maintain a practical RACI for security tooling deployment and operation, reducing ambiguity between Security, Platform, CloudOps and product teams.
  • Participate in incident response and post-incident reviews where security tooling, control failures, vulnerability exposure or patch failures are involved.
  • Mentor engineers on secure practices and support continuous improvement across Platform Engineering, CloudOps and product delivery teams.
  • Evaluate new security technologies and products, produce evaluation reports, and recommend improvements aligned to business risk and SaaS platform strategy.

Skills, Knowledge & Expertise
Required Qualifications
  • 5+ years of hands-on experience in DevSecOps, Cloud Security Engineering, Platform Engineering, SRE or senior cloud engineering roles.
  • Strong working knowledge of AWS security architecture and services, including IAM, networking, encryption, logging, Organizations/SCPs, Security Hub, GuardDuty, Inspector, Config, CloudTrail and KMS.
  • Practical experience deploying, configuring or operating security tools such as CrowdStrike, Tenable, ManageEngine, Fortinet firewalls and Cloudflare.
  • Strong experience with infrastructure-as-code, GitOps and CI/CD tooling such as Terraform, CloudFormation, Ansible, Helm, ArgoCD, GitLab CI/CD and Git.
  • Proficiency with scripting and automation using Python, Bash, PowerShell and YAML.
  • Experience securing Kubernetes/EKS, container platforms and serverless workloads, including RBAC, network policies, admission controls, image scanning, secrets management and runtime monitoring.
  • Solid grasp of vulnerability management, patch management, risk-based remediation, change control, SLAs and compliance evidence.
  • Hands-on ability to troubleshoot failed automation, configuration drift and deployment failures across cloud, network, endpoint, Kubernetes and CI/CD layers.
  • Experience operating in a multi-team, multi-product SaaS or enterprise cloud environment.
  • Excellent communication, stakeholder management and ownership mindset, with the ability to reduce ambiguity between Security, Platform, CloudOps and product teams.
Preferred Qualifications
  • Relevant certifications such as AWS Certified Security - Specialty, Certified Kubernetes Security Specialist (CKS), CISSP, CCSP, GIAC, Terraform Associate or equivalent experience.
  • Experience with SIEM/SOAR platforms, security incident response and threat-informed remediation.
  • Familiarity with compliance frameworks such as ISO 27001, SOC 2, NIST and CIS.
  • Experience implementing policy-as-code 
  • Experience in SaaS platform standardisation, shared services, mergers/acquisitions integration or multi-account AWS governance.

About
Forterro is a federation of ERP software and services companies serving small to mid market companies around the globe, with offices in UK, Germany, Sweden, Switzerland, France, Poland, Bulgaria, India, Morocco and USA. At Forterro, we invest in and help to fortify both local and niche ERP software businesses.Our product line businesses are local, not localized and vertical, not verticalized.

Similar Jobs

7 Hours Ago
Remote
United Kingdom
Senior level
Senior level
Cloud • Information Technology • Productivity • Security • Software • App development • Automation
Serve as a trusted executive advisor to strategic enterprise customers, driving adoption, measurable business outcomes, and expansion. Lead Customer Success Plans, complex transformation programs, and AI enablement. Mitigate risk, advocate customer needs internally, and collaborate cross-functionally with sales, product, support, and advisory teams to maximize long-term value.
Top Skills: AIAtlassianConfluenceGainsightJIRASalesforceTableau
7 Hours Ago
Remote
United Kingdom
Senior level
Senior level
Cloud • Information Technology • Productivity • Security • Software • App development • Automation
Lead strategic enterprise customers in realizing value from Atlassian products through trusted-advisor engagements, success plans, adoption strategies, risk mitigation, QBRs, cross-functional collaboration, and expansion of Atlassian solutions.
Top Skills: ConfluenceGainsightJIRASalesforceTableau
9 Hours Ago
In-Office or Remote
Senior level
Senior level
Cloud • Information Technology • Productivity • Security • Software • App development • Automation
Field-based enterprise account executive responsible for hunting and closing net-new logos in the UK. Build territory and named account plans, engage C-level stakeholders, qualify and negotiate complex deals, collaborate with cross-functional teams (SEs, Channel, Marketing, SDRs), maintain pipeline hygiene in CRM, and travel to meet prospects and attend events to accelerate new business acquisition.
Top Skills: Atlassian ProductsItsmJira Service Management (Jsm)Salesforce

What you need to know about the Bristol Tech Scene

Along with Gloucester, Swindon and Bath, Bristol is part of the "Silicon Gorge" tech hub, a region in the U.K. renowned for its high-tech and research-driven industries, with a particular emphasis on sustainability and reducing environmental impact. As the European Green Capital, Bristol is home to 25,000 cleantech companies, including Baker Hughes and unicorn Ovo Energy. The city has committed to achieving net-zero emissions within the next decade.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account