Security Engineer
Job description
About the role
StackOne is building the integration infrastructure for AI agents and is seeking a Security Engineer to own cloud and product security posture as the company scales. You will work directly across the AWS and Cloudflare estate, hardening the secure SDLC, running pen testing efforts end-to-end, and threat modeling the features that power connectors, OAuth flows, and agent execution paths. This is a hands-on, DevSecOps-heavy role where you write code, ship tooling, and embed security into how engineers work every day. You will report directly to the CTO and have broad scope across the platform, from CI/CD pipelines to multi-tenant APIs to incident response on authentication flows. The role demands ownership of security controls, proactive defense of production systems, and collaboration with engineering to make security the default way of shipping.
Key facts
What you'll do
- Drive the secure SDLC by owning SAST, dependency scanning, secrets detection, and PR-blocking standards across every repository in the organization.
- Harden the AWS and Cloudflare estate by managing IAM, secrets, network segmentation, KMS, WAF, GuardDuty, and zero-trust patterns for production workloads.
- Run pen testing end-to-end by scoping engagements, coordinating both AI-driven scanners and human researchers, and driving findings through fix implementation and retesting.
- Threat-model product features before they ship, including new Auth providers, expanded multi-tenant APIs, connector executions, and agent tool-calling paths.
- Build detection and response capabilities around credential and authentication flows while establishing observability that accelerates incident closure.
- Partner with engineering teams to raise the security bar day-to-day through architecture reviews, written standards, and security practices embedded in code review.
- Use LLMs and agents to accelerate security workflows such as triage, code review, and evidence gathering, while implementing guardrails you trust and monitoring the fleet.
- Support compliance work where it intersects security engineering, including SOC 2, ISO 27001, customer security reviews, and pen test responses.
- Define and maintain security baselines for cloud infrastructure, ensuring consistent application across environments and services.
- Collaborate with product and platform teams to design secure architectures for new features and integrations from day one.
- Operate and evolve security tooling in production, responding to alerts, tuning detections, and improving runbooks.
- Measure and report on security posture, risk reduction, and program maturity to both technical and non-technical stakeholders.
- Mentor engineers on secure coding practices and foster a culture where security is a shared responsibility.
- Continuously evaluate new attack surfaces introduced by agentic workflows and autonomous tool usage.
Requirements
- Bring 3+ years of hands-on security engineering experience with a strong focus on AWS security, including IAM, KMS, networking, secrets management, GuardDuty, and Security Hub.
- Demonstrate strong coding ability in TypeScript, Python, or Go, with a track record of shipping production code rather than only writing configurations and scripts.
- Show application security fluency through knowledge of the OWASP Top 10, threat modeling practices, and code-level reviews on real systems.
- Have experience securing B2B SaaS multi-tenant production environments and managing security in complex access control scenarios.
- Exhibit comfort with owning end-to-end work, including scoping, implementation, measurement, and follow-through without waiting for a queue.
- Communicate clearly with engineers, product managers, and non-technical stakeholders while translating technical risk into actionable guidance.
- Bias toward automating security checks instead of relying on manual checklists, with a preference for evidence-driven processes.
- (Preferred) Hold IaC fluency in AWS CDK or Terraform, with the ability to review infrastructure code for security misconfigurations and write custom scanning rules.
- (Preferred) Have direct experience with Aikido, Drata, Cloudflare Workers, or pen testing in compliance-mature environments.
- (Required) Understand the importance of security in AI agent execution paths and the risks associated with tool-calling and semantic discovery.
- (Required) Be comfortable working in a fast-moving startup environment where responsibilities evolve quickly and ownership is expected at all times.
- (Required) Adhere to the company's standards for documentation, code quality, and peer review as part of the engineering culture.
Nice to have
- Experience using security tooling in agentic workflows and autonomous systems to reduce manual overhead.
- Familiarity with compliance frameworks and audit response processes for customer security questionnaires.
- Contributions to open source security tools or public disclosure experience in responsible vulnerability disclosure programs.
- Background in building integrations for enterprise platforms and managing API security at scale.
- Experience with security observability, log-based detection, and incident response playbooks.
- Knowledge of modern identity and access management patterns for B2B SaaS, including SSO, OAuth, and impersonation workflows.
Practical notes
- This is a full-time position based in London.
- Hybrid working is supported, with a typical expectation of 2 days per week in the London office.
- The company is open to discussing flexible arrangements; please share any preferences in your application.
- Applicants should be able to commit to the required working hours as defined by the role and location.
- No specific visa sponsorship details or deadlines are published in this listing.