Senior Cloud Security Engineer

Company: Ki
Apply for the Senior Cloud Security Engineer
Location: Greater London
Job Description:

Overview

Who are we? Ki insures using advanced technology across a range of industries, including space, energy, and sports. Ki’s mission is to digitally disrupt and revolutionise a 335-year-old market. Working with Google and UCL, Ki has created a platform that uses algorithms, machine learning and large language models to give insurance brokers quotes in seconds, rather than days. Ki is the biggest global algorithmic insurance carrier, the fastest growing syndicate in the Lloyd’s of London market, and the first to reach $100m in profit in 3 years. Ki’s teams work in an agile, cross-functional way to build the best experience for customers. Ki has big ambitions and seeks excellent minds to challenge the status quo and reach new horizons.

Role

Where you come in? As a senior and highly experienced Cloud Security Engineer, you will work closely with engineering teams across Cloud Services, Infrastructure and Product to embed risk-conscious technical security controls in services, products, development workflows and activities. You will design, implement and manage robust security measures across cloud platforms, collaborate with cross-functional teams to develop security strategies, automate security processes, and proactively identify and mitigate threats. You will work on cloud-native security tooling, automate work, and leverage infrastructure as code. The role is expected to use AI to build automation and agentic AI workflows responsibly, to improve productivity while ensuring data protection and appropriate security controls.

What you will be doing

  • Cloud Security Architecture & Design: Design and implement security architectures for cloud-based systems and hybrid environments (GCP, Azure, AWS).
  • Design secure cloud architectures for AI/LLM workloads and AI-enabled services, including isolation patterns, secure networking, and hardened runtime configurations.
  • Ensure reproducibility of security configurations and infrastructure through infrastructure-as-code (IaC), specification-driven development (SDD), and automated deployment pipelines.
  • Automate cloud security processes leveraging agentic AI harnesses.
  • Design and implement robust security measures across Ki’s cloud platforms and be opinionated regarding Ki’s current architecture with constructive improvement suggestions.

Security Governance & Policy

  • Develop and enforce security policies, standards, and guidelines for cloud services.
  • Ensure cloud environments meet regulatory and compliance requirements (ISO 27001, SOC 2, SOX ITGC, NIST, GDPR, etc.).
  • Conduct and automate regular security assessments and audits.
  • Enable cloud security governance across Azure, GCP and AWS with security monitoring, cloud security posture management and vulnerability management.

Incident Response & Monitoring

  • Monitor cloud environments for security breaches and respond to incidents.
  • Conduct root cause analysis, create incident reports, and implement remediation strategies.
  • Triage and prioritise mitigation of vulnerabilities in line with remediation policies.

Identity & Access Management

  • Manage and implement IAM policies, roles, and permissions to enforce least privilege and zero trust.
  • Develop solutions for secure authentication and authorization mechanisms.

Data Security & Compliance

  • Ensure data security and compliance through encryption, data masking, and secure storage practices.
  • Implement DLP and data classification technologies.

Security Automation & DevSecOps

  • Develop automated security controls and work with Terraform and Kubernetes.
  • Define secure-by-default automation patterns for AI-enabled systems, including observability and policy-as-code controls.
  • Integrate security tools with CI/CD pipelines to enhance DevSecOps practices.
  • Automate work by writing code and contributing to infrastructure and security tooling in the cloud.

Collaboration & Enablement

  • Work with development, operations and product teams to integrate security into the system development lifecycle.
  • Mentor junior security engineers and provide guidance on cloud security best practices.
  • Provide guidance and hands-on implementation advice in application security, aligned to industry best practices and frameworks.
  • Organise regular penetration tests and ad-hoc security assessments.
  • Develop and optimise technical controls for platform integrations.
  • Document work diligently and share knowledge with engineers.
  • Help facilitate and manage the Security Champions network across engineering teams.
  • Organise regular security training sessions.

Requirements

A successful candidate will have:

  • Extensive experience with at least one major public cloud provider (preferably GCP and Azure) and an understanding of network infrastructure.
  • Strong understanding of identity management, network security, firewalls, VPNs, IDS/IPS and WAFs.
  • Hands-on scripting or programming experience with Python, Golang, or similar languages, delivering services or automation into production.
  • Hands-on experience with security tools such as SIEM, vulnerability scanners, EDR/XDR, and CSPM tools.
  • Understanding of the Kubernetes ecosystem and its security considerations.
  • Experience with AI-augmented development flows and the ability to steer agents for high-quality outcomes you can understand and explain.
  • Experience working with agile development teams.
  • Ability to troubleshoot and solve cloud-related security issues independently.
  • Experience with Google Cloud Platform and Azure.
  • Experience with CNAPP and CSPM tools like Wiz; container security (Kubernetes, Docker).
  • Experience with Infrastructure-as-Code using Terraform/OpenTofu and HCL.
  • Experience with CI tools such as GitHub Actions, Azure DevOps, pipeline builds, release packaging and artifact management.
  • Experience with enterprise-wide Agile methodologies and practices.

Desirable Qualifications

  • GCP Professional Cloud Security Engineer qualification is desirable.
  • Experience with securing LLM systems and AI agent harness and tool access patterns.

#J-18808-Ljbffr…

Posted: April 17th, 2026