# Security Engineer

[Stackone](https://gurify.com/jobs?q=Stackone) · London · Posted 4 months ago

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://jobs.ashbyhq.com/stackone/b3973ac2-f4eb-45c9-9584-c078f02fc5b6)

## Job description

### About StackOne

StackOne is the integration infrastructure for AI agents. Backed by GV and Workday Ventures ($24M raised), we make it possible for any AI agent — whether our customers build it into their product or buy it off the shelf — to take real action across the enterprise stack. Our platform gives agents 430+ connectors and 26,000+ pre-built actions, an AI connector builder for everything not covered yet, and the production layer agents actually need: semantic tool discovery that cuts token use by up to 80%, managed authentication and per-action permissions, the most accurate prompt injection defense on the market, and end-to-end observability.

Join us on our fast trajectory to build the future of agentic integrations.

### ABOUT THE ROLE

We’re looking for a Security Engineer to be a key hire on our Engineering team and own our cloud and product security posture as we scale. You’ll work across our AWS and Cloudflare estate, harden our secure SDLC, run pen testing efforts end-to-end, and threat-model the features powering our connectors, OAuth flows, and agent execution paths.

It’s a hands-on, DevSecOps-heavy role: you write code, ship tooling, and embed security into how engineers work every day. You’ll report directly to the CTO and have broad scope across the platform (from CI/CD pipelines to multi-tenant APIs to incident response on authentication flows).

### RESPONSIBILITIES

- Own the secure SDLC: drive SAST, dependency scanning, secrets detection, and PR-blocking standards across every repository.

- Harden our AWS and Cloudflare estate: IAM, secrets, network segmentation, KMS, WAF, GuardDuty, and zero-trust patterns.

- Run pen testing end-to-end: scope and coordinate engagements with both AI-driven scanners and human researchers, then drive findings through fix and retest.

- Threat-model product features before they ship, new Auth provider, expanded multi-tenant APIs, connector executions, agent tool-calling paths etc.

- Build detection and response capability around credential and authentication flows, with observability that closes incidents fast.

- Partner with engineering to raise the bar day-to-day: architecture reviews, written standards, and security embedded in code review.

- Use LLMs and agents to accelerate security workflows (triage, code review, evidence gathering) with guardrails you trust and help secure and monitor the (code/application/device) fleet.

- Support compliance work where it intersects security engineering: SOC 2, ISO 27001, customer security reviews, and pen test responses.

### WHAT WE’RE LOOKING FOR

- 3+ years in security engineering with hands-on AWS security: IAM, KMS, networking, secrets, GuardDuty / Security Hub.

- Strong coding ability in TypeScript or Python or Go comfortable shipping production code, not just configs and scripts.

- Application security fluency: OWASP Top 10, threat modeling, and code-level reviews on real systems.

- Experience securing a B2B SaaS multi-tenant production environment.

- Comfort owning end-to-end work: scope, ship, measure. You don’t wait for a queue.

- Clear communication with engineers, product, and non-technical stakeholders.

- Bias toward automating security checks instead of running manual checklists.

- (Preferred) IaC fluency in AWS CDK or Terraform , comfortable reviewing infrastructure code for security misconfigs and writing custom scanning rules.

- (Preferred) Experience with Aikido, Drata, Cloudflare Workers, or pen testing in a compliance-mature environment.

### OUR STACK

### We’re pragmatic about tooling. Today’s stack includes:

- Cloud & infra: AWS (ECS, RDS, Lambda, KMS, GuardDuty, Security Hub, Inspector), Cloudflare (Workers, WAF, Zero Trust)

- IaC: AWS CDK, Terraform

- Security tooling: Aikido (SAST, DAST, container scanning, pen testing), 1Password, GitHub (org-level enforcement, Advanced Security)

- Compliance & ops: Drata, Iru, EasyLlama

- Observability & IR: Datadog, Sentry, Logfire, Incident.io http://Incident.io

- Languages: TypeScript (Node.js), Python

### BENEFITS

- Meaningful share options (EMI) - share in the company’s success as we grow

- 25 days holiday + 1 additional day per year of tenure

- Private health insurance - including dental & optical

- £15/day lunch budget when working from our London office, up to £180/month

- £1,000 for your home office set up + £500/year top-up

- Annual team offsite to sunny spots (last ones were in Croatia and Portugal ☀️)

- Join one of Europe’s fastest-growing startups

- Work with a veteran team of ex-employees of Google, Microsoft, Oracle, Coinbase, JP Morgan and more

- Health, fitness and gift card discounts

- Cycle2Work and Electric Cars scheme

- Hybrid working friendly - typically 2 days/week in our London office. We’re open to discussing flexible arrangements – please share any preferences in your application

We believe diversity drives innovation. We encourage individuals from all backgrounds to apply. As an equal-opportunity employer, we celebrate diversity and are committed to creating an inclusive environment for all employees.

**Live in Stackone’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- IN [Senior Infrastructure and Cloud Security Engineer (m/f/d)](https://gurify.com/job/senior-infrastructure-and-cloud-security-engineer-m-f-d-at-3f7722b49cef) Internationalcopyrightenterpriseservices · London · 3 days ago
- CO [Security Engineer](https://gurify.com/job/security-engineer-at-conduct-354c5d006329) Conduct · London, United Kingdom · last week
- HA [Senior Security Engineer, Detection and Response](https://gurify.com/job/senior-security-engineer-detection-and-response-at-hackerone-45f09130ce13) Hackerone · London · last week
- CO [Cloud Native Security Engineer](https://gurify.com/job/cloud-native-security-engineer-at-controlplane-7b45fcfb1a4d) Controlplane · London · 6 days ago
- WR [Security engineer, detection and response (UK)](https://gurify.com/job/security-engineer-detection-and-response-uk-at-writer-f0528fa67725) Writer · London, United Kingdom · 2 weeks ago
- CC [Cyber Security Engineer I](https://gurify.com/job/cyber-security-engineer-i-at-checkout-com-b3744d8ed0a5) Checkout Com · London · 2 weeks ago

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Security Engineer","description":"\u003Ch3\u003EAbout StackOne\u003C/h3\u003E\u003Cp\u003EStackOne is the integration infrastructure for AI agents. Backed by GV and Workday Ventures ($24M raised), we make it possible for any AI agent \u2014 whether our customers build it into their product or buy it off the shelf \u2014 to take real action across the enterprise stack. Our platform gives agents 430\u002B connectors and 26,000\u002B pre-built actions, an AI connector builder for everything not covered yet, and the production layer agents actually need: semantic tool discovery that cuts token use by up to 80%, managed authentication and per-action permissions, the most accurate prompt injection defense on the market, and end-to-end observability.\u003C/p\u003E\u003Cp\u003EJoin us on our fast trajectory to build the future of agentic integrations.\u003C/p\u003E\u003Ch3\u003EABOUT THE ROLE\u003C/h3\u003E\u003Cp\u003EWe\u2019re looking for a Security Engineer to be a key hire on our Engineering team and own our cloud and product security posture as we scale. You\u2019ll work across our AWS and Cloudflare estate, harden our secure SDLC, run pen testing efforts end-to-end, and threat-model the features powering our connectors, OAuth flows, and agent execution paths.\u003C/p\u003E\u003Cp\u003EIt\u2019s a hands-on, DevSecOps-heavy role: you write code, ship tooling, and embed security into how engineers work every day. You\u2019ll report directly to the CTO and have broad scope across the platform (from CI/CD pipelines to multi-tenant APIs to incident response on authentication flows).\u003C/p\u003E\u003Ch3\u003ERESPONSIBILITIES\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EOwn the secure SDLC: drive SAST, dependency scanning, secrets detection, and PR-blocking standards across every repository.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHarden our AWS and Cloudflare estate: IAM, secrets, network segmentation, KMS, WAF, GuardDuty, and zero-trust patterns.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ERun pen testing end-to-end: scope and coordinate engagements with both AI-driven scanners and human researchers, then drive findings through fix and retest.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EThreat-model product features before they ship, new Auth provider, expanded multi-tenant APIs, connector executions, agent tool-calling paths etc.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild detection and response capability around credential and authentication flows, with observability that closes incidents fast.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPartner with engineering to raise the bar day-to-day: architecture reviews, written standards, and security embedded in code review.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EUse LLMs and agents to accelerate security workflows (triage, code review, evidence gathering) with guardrails you trust and help secure and monitor the (code/application/device) fleet.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESupport compliance work where it intersects security engineering: SOC 2, ISO 27001, customer security reviews, and pen test responses.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EWHAT WE\u2019RE LOOKING FOR\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003E3\u002B years in security engineering with hands-on AWS security: IAM, KMS, networking, secrets, GuardDuty / Security Hub.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong coding ability in TypeScript or Python or Go comfortable shipping production code, not just configs and scripts.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EApplication security fluency: OWASP Top 10, threat modeling, and code-level reviews on real systems.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience securing a B2B SaaS multi-tenant production environment.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EComfort owning end-to-end work: scope, ship, measure. You don\u2019t wait for a queue.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EClear communication with engineers, product, and non-technical stakeholders.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBias toward automating security checks instead of running manual checklists.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003E(Preferred) IaC fluency in AWS CDK or Terraform , comfortable reviewing infrastructure code for security misconfigs and writing custom scanning rules.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003E(Preferred) Experience with Aikido, Drata, Cloudflare Workers, or pen testing in a compliance-mature environment.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EOUR STACK\u003C/h3\u003E\u003Ch3\u003EWe\u2019re pragmatic about tooling. Today\u2019s stack includes:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003ECloud \u0026amp; infra: AWS (ECS, RDS, Lambda, KMS, GuardDuty, Security Hub, Inspector), Cloudflare (Workers, WAF, Zero Trust)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EIaC: AWS CDK, Terraform\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESecurity tooling: Aikido (SAST, DAST, container scanning, pen testing), 1Password, GitHub (org-level enforcement, Advanced Security)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECompliance \u0026amp; ops: Drata, Iru, EasyLlama\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EObservability \u0026amp; IR: Datadog, Sentry, Logfire, Incident.io http://Incident.io\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ELanguages: TypeScript (Node.js), Python\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EBENEFITS\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EMeaningful share options (EMI) - share in the company\u2019s success as we grow\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003E25 days holiday \u002B 1 additional day per year of tenure\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPrivate health insurance - including dental \u0026amp; optical\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003E\u0026#163;15/day lunch budget when working from our London office, up to \u0026#163;180/month\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003E\u0026#163;1,000 for your home office set up \u002B \u0026#163;500/year top-up\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAnnual team offsite to sunny spots (last ones were in Croatia and Portugal \u2600\uFE0F)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EJoin one of Europe\u2019s fastest-growing startups\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWork with a veteran team of ex-employees of Google, Microsoft, Oracle, Coinbase, JP Morgan and more\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHealth, fitness and gift card discounts\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECycle2Work and Electric Cars scheme\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHybrid working friendly - typically 2 days/week in our London office. We\u2019re open to discussing flexible arrangements \u2013 please share any preferences in your application\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003EWe believe diversity drives innovation. We encourage individuals from all backgrounds to apply. As an equal-opportunity employer, we celebrate diversity and are committed to creating an inclusive environment for all employees.\u003C/p\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"security-engineer-at-stackone-6c29a9805aad"},"url":"https://gurify.com/job/security-engineer-at-stackone-6c29a9805aad","datePosted":"2026-05-20","validThrough":"2026-11-04T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Stackone","sameAs":"https://jobs.ashbyhq.com/stackone"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"GB","addressLocality":"London"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"United Kingdom","item":"https://gurify.com/jobs/united-kingdom"},{"@type":"ListItem","position":3,"name":"Security Engineer","item":"https://gurify.com/job/security-engineer-at-stackone-6c29a9805aad"}]}
```
