About the job
Ebury empowers ambitious businesses to unlock global growth, and we extend the same philosophy to our team members. We promote innovation, collaboration, and problem-solving, creating an inclusive environment where everyone feels valued, supported, and empowered to thrive.
If you are a collaborative individual eager to transform how businesses operate on a global scale, we invite you to connect with us. Discover how Ebury can fast-track your career and help you shape the future.
Senior Security Engineer - Cloud Infrastructure
Hybrid (4 days in office) in London
Ebury is making significant investments in its cloud infrastructure security to ensure the integrity and safety of our global financial services. As a Senior Security Engineer specializing in Cloud Infrastructure, you will be responsible for enhancing and managing the security posture of our cloud environments across AWS and GCP, focusing on network security, perimeter defense, and attack surface management.
This hands-on position requires extensive expertise in cloud-native security controls, network architecture, and proactive defensive security operations. You will design, implement, and maintain security infrastructure that identifies and mitigates threats before they affect our operations. Collaborating closely with platform, infrastructure, and security operations teams, you will embed security best practices into our cloud foundations.
Key Responsibilities
- Manage cloud security posture and attack surface: Ensure comprehensive visibility and control across AWS and GCP environments. Implement cloud-native security monitoring, detection, and alerting mechanisms to proactively identify and mitigate threats, establishing and enforcing security baselines through policy-as-code.
- Design and oversee web application firewall infrastructure: Maintain WAF configurations across AWS and GCP, creating and fine-tuning detection rules in line with application threat models and emerging attack patterns. Develop operational processes for rule management and incident response integration, collaborating with application teams to implement protections without disrupting availability.
- Architect network segmentation and isolation: Design and implement strategies ensuring proper separation between development, staging, and production environments. Define consistent patterns across multi-cloud infrastructure, apply zero-trust principles to workload communication, and document reference architectures for engineering teams.

