Cloud Engineer – Security at Simmons & Simmons | Bristol, England, GB | Rezi

Cloud Engineer – Security at Simmons & Simmons

Cloud Engineer – Security

Simmons & Simmons · Bristol, England, GB

1 months ago

Cloud Engineer – Security

Simmons & Simmons · Bristol, England, GB

2 months ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

Simmons & Simmons is building an Internal Developer Platform (IDP) on Azure to provide product teams with a fast, self-service, and well-governed route to ship software. This role focuses on embedding security as a default within this platform, acting as the security specialist for the Cloud Engineering team. You will design, build, and scale security controls, guardrails, and tooling, ensuring developers can securely ship code without extensive manual effort. This is a build-and-enable role, emphasizing a code-first, pipeline-driven approach using Azure, GitHub, and agentic AI.

Responsibilities

  • Act as the security point of contact for the Cloud Engineering team and the bridge between the central Security team and product teams.
  • Translate security requirements into working platform features.
  • Represent the platform's security posture to Security, assurance, and audit teams.
  • Bring Security's priorities into the engineering roadmap.
  • Coach and support product teams to make secure patterns self-service defaults.
  • Shape and build the IDP to ensure secure-by-default paths are the easiest.
  • Design and implement guardrails as code, including policy-as-code and identity/access patterns.
  • Automate compliance checks to ensure the estate is compliant by construction.
  • Ensure evidence for assurance and audit is a by-product of the platform's pipelines.
  • Select, integrate, and operate security tooling across Azure and GitHub.
  • Implement automated security checks in pipelines, including code and dependency scanning, secret detection, and posture management.
  • Define and document engineering standards and reusable patterns.
  • Continuously improve the security baseline across the estate.
  • Apply agentic AI tooling to accelerate security engineering tasks like policy authoring and change-impact analysis.
  • Help the team adopt agentic AI safely and effectively.
  • Design, build, and operate the core Azure platform for the IDP, including landing zones, networking, and identity.
  • Deliver infrastructure as code using reusable Bicep/Terraform modules, pipeline templates, and golden paths.
  • Own the operational health of the platform, including observability, cost management, resilience, and lifecycle management.
  • Partner with product teams to evolve the platform based on real consumption.

Requirements

  • Demonstrable experience securing cloud platforms in production.
  • Strong hands-on Azure experience, including identity and access, networking, and governance.
  • A code-first way of working: infrastructure and policy as code.
  • Confident use of GitHub (or equivalent) with CI/CD pipelines as the primary delivery mechanism.
  • Practical experience embedding security into pipelines (scanning, policy gates, secrets management).
  • Hands-on experience embedding SAST and DAST into CI/CD pipelines, including triaging, tuning, and enforcing findings as policy gates.
  • Hands-on use of agentic AI tooling in an engineering context.
  • Communication and relationship skills to bridge between central security and delivery teams.
  • Ability to explain security to mixed technical audiences and influence without authority.
  • A platform-as-a-product mindset, treating developers as customers.
  • Experience in a regulated environment (legal, financial, or professional services) is desirable.
  • Familiarity with assurance and audit evidence is desirable.
  • Specific Azure and GitHub security tooling experience is desirable (Microsoft Defender for Cloud, Microsoft Sentinel, GitHub Advanced Security, Entra ID PIM and RBAC, Bicep, PowerShell).
  • Experience with policy-as-code frameworks (e.g., Azure Policy, Enterprise Policy as Code) and OIDC-federated pipeline identity is desirable.
  • A relevant degree is preferable but not required.

Skills

  • Azure
  • GitHub
  • CI/CD pipelines
  • Infrastructure as Code (IaC)
  • Policy as Code
  • SAST (Static Application Security Testing)
  • DAST (Dynamic Application Security Testing)
  • Agentic AI tooling
  • Bicep
  • Terraform
  • Microsoft Defender for Cloud
  • Microsoft Sentinel
  • GitHub Advanced Security
  • Entra ID PIM
  • Entra ID RBAC
  • PowerShell
  • Azure Policy
  • Enterprise Policy as Code
  • OIDC-federated pipeline identity

Location

  • Bristol
  • London

Work Type

  • Hybrid

Experience Level

  • Level 3

Education Level

  • Degree preferable but not required

Benefits

  • Competitive package including bonuses
  • Private medical insurance
  • Pension contribution
  • Global skills academy with learning opportunities
  • Range of social and sports committees
  • Summer and winter parties
  • Monthly get togethers
  • Range of diversity networks
  • Support for the art community

About the Company

  • Simmons & Simmons is an international law firm with expert teams across Europe, the Middle East, and Asia.
  • We partner with leading organisations on complex projects.
  • We foster a collaborative, open, and non-hierarchical culture where everyone is treated with respect and dignity.
  • We prioritize the wellbeing of our people.
  • We encourage an enquiring mind and sharing of ideas.
  • We offer innovative learning and development opportunities.
  • We have a history of supporting the art community, including up-and-coming artists.
  • We have introduced a Strategic Advisory Council to propose strategic initiatives.
  • Our in-house generative AI tool, Percy, won an award for innovation.
  • We have been commended in The Times Best Law Firms 2026.
  • We are proud to rank as a Times Top 50 Employer for Gender Equality, a Stonewall Top Global Employer, and a Top 75 Employer for Social Mobility.

Equal Opportunity

  • Committed to fostering equality, diversity, and inclusion.
  • Ensuring equal employment opportunities.
  • Upholding equal opportunities regardless of race, ethnicity, religion, belief, age, disability, sexual orientation, sex, gender reassignment, gender identity, marital status, or pregnancy, including maternity and paternity.
  • Addressing perceived or associative discrimination and harassment.
  • Ensuring fair treatment for those who are serving or have served in the armed forces, along with their families.
  • Accommodating requests for flexible working arrangements whenever possible.
  • Making roles accessible to individuals with diverse abilities.
  • Encouraging applications even if not every requirement is met.
  • Seeking individuals who are passionate and eager to learn and grow.
  • Recognizing the value of unique experiences and perspectives.
  • Reserving the right to close the vacancy early if sufficient applications are received.