Cybersecurity (Secure Software/Cloud Integration) Engineer

London
1 month ago
Applications closed

Related Jobs

View all jobs

Cybersecurity Analyst

Cybersecurity Officer

Cybersecurity Consultant

Cybersecurity Officer

Cybersecurity Risk Analyst

Cybersecurity Analyst

Overview

Expleo is a trusted partner for end-to-end, integrated engineering, quality services, and management consulting for digital transformation. We help businesses harness unrelenting technological change to deliver innovations that provide a competitive advantage and improve everyday life worldwide.

As part of the Expleo Digital and Emerging Technology (DET) team, you will report to the Head of Cybersecurity and play a key role within our forward-leaning Cybersecurity Practice. In this role, you will support the design and implementation of secure software development processes and cloud-native integration patterns for clients across multiple sectors.
This is a hands-on, delivery-focused role where you will embed DevSecOps principles into engineering pipelines, guide secure software development lifecycle (SSDLC) practices, and advise on adopting security tooling across cloud and hybrid environments. You will work closely with development, DevOps, and platform teams to uplift security maturity, enabling secure and scalable software delivery aligned with industry standards and compliance requirements.

Responsibilities

Embed security practices into software development pipelines by integrating DevSecOps principles, automation tools, and governance controls.
Support the definition, implementation, and continuous improvement of secure software development lifecycle (SSDLC) processes across internal and client delivery teams.
Advise on secure architecture patterns and controls for cloud-native, containerised, and hybrid applications, aligned with industry standards and best practices.
Collaborate with engineering, DevOps, and platform teams to guide the adoption of security tooling across CI/CD environments.
Conduct reviews of application architecture, infrastructure-as-code, and security configurations to identify risks and support remediation planning.
Provide input into security design decisions, threat modelling sessions, and architectural governance forums.
To support engineering teams and deliver clear, practical documentation, including secure development standards, integration guidelines, and process artefacts.
Stay informed on the evolving threat landscape, cloud security trends, and software security vulnerabilities to ensure contemporary and effective delivery.

Qualifications

A degree (or equivalent experience) in Cybersecurity, Computer Science, Software Engineering, or a related technical discipline.
Recognised industry certifications in cybersecurity or application security (CompTIA, ISC2, GIAC, ISACA, or CREST).
Highly desirable are certifications related to secure development and cloud security (CSSLP, AZ-500, SC-100/SC-200, AWS Security, GCSA, GCLD, or similar).
Familiarity with secure coding standards (OWASP, SEI CERT) and SSDLC models (Microsoft SDL, NIST (Apply online only) SSDF).
Knowledge or experience of Product Assurance Schemes (PAS) or product security frameworks (PAS 754, PAS 1296, or similar) is desirable.
DevOps, DevSecOps, or platform certifications (Kubernetes, Terraform, Azure DevOps, GitHub Actions) are advantageous.

Essential skills

Strong understanding of secure software development principles and the software development lifecycle (SDLC/SSDLC).
Proficiency in modern DevOps environments.
Practical experience with cloud security concepts and controls across at least one major cloud platform (AWS, Azure, or GCP).
Solid grasp of secure coding practices and common software vulnerabilities.
Ability to assess code, configurations, and architecture for security issues and provide practical remediation guidance.

Desired skills

Familiarity with infrastructure-as-code (IaC) security practices and tooling.
Knowledge of container orchestration platforms and associated security tooling.
Awareness of compliance and assurance frameworks relevant to secure software.
Understanding cloud-native security services and architectures, including Zero Trust models and shift-left security practices.
Exposure to secure software supply chain practices, including code provenance, dependency management, and SBOM generation.

Experience

Experience in cybersecurity, secure software engineering, or cloud security roles, with a strong emphasis on delivery.
Demonstrable experience embedding security controls and tooling into software development pipelines and DevOps environments.
Hands-on experience implementing or supporting secure development processes (SSDLC), code review practices, or CI/CD security integration.
Proven involvement in cloud-native or hybrid solution development with exposure to major cloud platforms.
Experience collaborating with developers, DevOps, architects, and platform teams to design and implement secure software solutions.
Exposure to application security tooling (SAST, DAST, SCA), cloud security services, and infrastructure-as-code security practices.
Familiarity with agile or DevOps-based delivery models and working across multiple stakeholders or client environments.

What do I need before I apply

You must have the right to work in the UK

Get the latest insights and jobs direct. Sign up for our newsletter.

By subscribing you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Top 10 Best UK Universities for Cyber Security Degrees (2025 Guide)

Discover ten of the strongest UK universities for Cyber Security degrees in 2025. Compare entry requirements, course content, research strength and industry links to choose the right programme for you. Cyber Security has moved from IT back-room concern to critical national infrastructure. With growing threats from ransomware, state-sponsored attacks and supply-chain compromise, demand for well-trained cyber professionals has never been higher. The UK is home to a clutch of universities recognised globally for excellence in this field. Below, we profile ten institutions offering robust undergraduate or postgraduate cyber-security pathways. While league tables shift year on year, these universities have a consistent record of first-class teaching, research and industry collaboration.

How to Write a Winning Cover Letter for Cyber Security Jobs: Proven 4-Paragraph Structure

Learn how to craft the perfect cover letter for cyber security jobs with this proven 4-paragraph structure. Ideal for entry-level candidates, career switchers, and professionals looking to advance in the cyber security sector. When applying for a cyber security job, your cover letter is an essential component of your application. The cyber security industry is continuously evolving, and organisations are always seeking professionals who can protect their networks, systems, and data. Your cover letter provides an opportunity to demonstrate your technical expertise, your enthusiasm for cyber security, and your ability to contribute to the protection of sensitive information. Whether you're just entering the field, transitioning from another career, or looking to advance in cyber security, this article will guide you through a proven four-paragraph structure to create a compelling cover letter. We’ll provide sample lines and tips to help you stand out in the competitive cyber security job market.

Quantum-Enhanced AI in Cyber Security: Guarding the Digital Frontier

The cyber security landscape has evolved dramatically over the past decade. Long gone are the days when businesses primarily worried about simplistic phishing or basic website defacements. Today’s threats include nation-state attacks, sophisticated ransomware, AI-generated phishing campaigns, and a wide array of stealthy intrusion methods. Organisations must defend vast digital ecosystems that include cloud infrastructure, IoT devices, and critical operational technology—any of which can become high-value targets for malicious actors. Amid these escalating challenges, a new technological wave is emerging: quantum computing. Although still in its infancy, quantum computing promises capabilities that could surpass even the most advanced classical supercomputers for specific tasks. Simultaneously, in the world of Artificial Intelligence (AI)—where data volumes and model complexity are exploding—quantum’s parallelism could significantly boost analysis, training, and decision-making. What unfolds when quantum computing and AI converge in the realm of cyber security? On one hand, quantum technologies could introduce stronger encryption and faster threat detection. On the other, adversaries armed with quantum power might break today’s cryptographic protocols or develop more potent attacks at unimaginable speeds. This article explores the phenomenon of quantum-enhanced AI for cyber security: the possibilities it unlocks, the challenges it poses, and the reasons it could reshape both defensive and offensive operations in the digital world.