
Version 1 has celebrated 30 years in business and continues to be trusted by global brands to deliver technology and transformation solutions that drive customer success. Our deep expertise enables our customers to navigate the rapidly evolving technology landscape. We foster strong partnerships with global technology leaders including Microsoft, AWS, Oracle, Red Hat, OutSystems, Snowflake, ensuring that our customers are provided with the highest quality solutions and services.
We’re an award-winning employer reflecting how our employees are at the very heart of what we do:
We’re a core values [link to values] driven company, we hire people who share our values, and we reward those who display and foster them, it’s deeply embedded within our DNA. Invest in us and we’ll invest in you.
We are seeking a hands-on Security Engineer to embed within a large-scale cloud migration programme, moving workloads into AWS. You will be responsible for designing, automating, and enforcing security controls throughout the migration lifecycle — ensuring that every workload lands in AWS with a secure, compliant, and auditable posture. This is a technical, build-focused role combining cloud security architecture, infrastructure-as-code, and Python automation.
Key Responsibilities
Define and implement the security controls, guardrails, and landing zone baseline for workloads migrating to AWS.
Design and operate AWS-native security tooling across accounts and Organizations (see Technical Skills below).
Build security automation in Python — remediation Lambdas, compliance-check scripts, event-driven response, and integrations with ticketing/SIEM systems.
Author, review, and maintain infrastructure-as-code (Terraform and/or CloudFormation) for security services, guardrails, IAM, networking, and encryption.
Integrate security into GitLab CI/CD pipelines — SAST, IaC scanning, secrets detection, dependency/container scanning, and policy-as-code gates.
Assess the security posture of workloads before, during, and after migration; identify and remediate misconfigurations and vulnerabilities.
Design secure network segmentation and connectivity between source environments and AWS (Direct Connect / VPN, Transit Gateway, security groups, NACLs).
Implement IAM least-privilege models, identity federation, and secrets management for migrated workloads.
Define encryption standards (at rest and in transit) using KMS, ACM, and TLS policy.
Support compliance and audit requirements (e.g. CIS Benchmarks, NIST, ISO 27001, SOC 2, PCI-DSS as applicable) and produce evidence.
Partner with migration, platform, and application teams to unblock security issues without slowing delivery.
Contribute to incident detection and response runbooks for the AWS environment.
Required Technical Skills
AWS Security Tooling
AWS Security Hub – aggregated findings, standards, and posture management
Amazon GuardDuty – threat detection
AWS Config – configuration compliance and drift detection, custom/conformance rules
AWS IAM / IAM Identity Center – least-privilege roles, policies, permission boundaries, federation
AWS KMS & ACM – encryption key management and certificates
AWS WAF & Shield – application and DDoS protection
Amazon Inspector – vulnerability scanning for EC2/ECR/Lambda
AWS CloudTrail – audit logging and monitoring
AWS Organizations & Service Control Policies (SCPs) – multi-account guardrails
AWS Secrets Manager / Systems Manager Parameter Store – secrets handling
Amazon Macie – sensitive data discovery (desirable)
AWS Control Tower / Landing Zone – governed account provisioning
Automation & Infrastructure-as-Code
Python – security automation, boto3, Lambda functions, remediation scripts, custom Config rules
Terraform – modules for security services, guardrails, IAM, networking
CloudFormation – templates and (desirable) StackSets across accounts
Familiarity with policy-as-code (e.g. OPA/Conftest, cfn-guard, Checkov, tfsec) is a strong plus
CI/CD & Version Control
GitLab – repositories, merge requests, and GitLab CI/CD pipeline development
Integrating security scanning into pipelines: SAST, DAST, IaC scanning, secrets scanning, SCA, container image scanning
Git branching, code review, and shift-left security practices
Migration & Infrastructure
Workload discovery and assessment ahead of migration
AWS migration tooling (Application Migration Service / MGN, DMS, Migration Hub) – desirable
Hybrid networking: Direct Connect, VPN, Transit Gateway, VPC design, security groups, NACLs
Operating system security hardening (Linux and/or Windows)
Required Experience & Qualifications
4+ years in security engineering, cloud security, or infrastructure security (adjust to seniority).
Demonstrable hands-on experience securing production AWS environments.
Proven experience delivering or securing a cloud migration programme.
Strong scripting/automation ability in Python.
Experience with IaC (Terraform and/or CloudFormation) in a production setting.
Comfortable working in a GitLab-based DevSecOps workflow.
Why Version 1?
At Version 1, we believe in providing our employees with a comprehensive benefits package that prioritises their wellbeing, professional growth, and financial stability.
And many more exciting benefits… drop us a note to find out more.
Version 1 is an equal opportunities employer.
We are committed to building a diverse, inclusive and respectful workplace where everyone feels valued and able to thrive. We welcome applications from people of all backgrounds, identities and lived experiences, and we value the different perspectives people bring.
We want every candidate to have a positive and accessible recruitment experience. If you need reasonable adjustments at any stage of the process, please contact Paul.Steed@version1.com at Version 1. We will consider all requests carefully, respectfully and confidentially.
#LI-SS1

Version 1 is a leader in AI and digital transformation, partnering strategically with global organisations to transform and adopt technology and drive innovation in a responsible way.
With an end-to-end offer designed to address the most difficult challenges faced by customers, and supported by the latest cutting-edge technologies, Version 1 is focused on delivering successful customer outcomes through the power of world-class teams.
This pledge is underscored by the key principles of the organisation, a triangle of balanced priorities comprising customer success, empowered people, and a strong organisation.
Version 1 is made up of a fast-growing team of 3,200+ people across 4 continents, all innovating differently to drive value through sustainable transformation.