StackOne
Posted 2mo ago

Security Engineer

StackOne
London, England, United Kingdom
HybridFull Time
Responsibilities
  • Own secure SDLC
  • Harden cloud estate
  • Run pen testing
Requirements
  • 3+ years in security engineering with hands-on AWS security
  • Strong coding in TypeScript/Python/Go
  • Application security expertise
  • Experience securing multi-tenant B2B SaaS
  • Autonomous ownership
  • Strong communication
  • Automation bias
Technical tools mentioned
AWSCloudflareAWS CDKTerraformAikido1PasswordGitHubDrataIruEasyLlamaDatadogSentryIncident.ioTypeScriptPython

Job description

About StackOne:

StackOne is the AI Integration Gateway for SaaS products and AI Agents. Backed by GV and Workday Ventures ($24M raised), we help builders of SaaS platforms and AI Agents orchestrate hundreds of scalable, accurate, and enterprise-grade integrations. Our platform combines 25,000 pre-mapped actions on 200 connectors, an AI-powered integration development toolkit, plus security by design: a real-time architecture, managed authentication and permissions, and end-to-end observability.

Join us on our fast trajectory to build the future of agentic integrations.

About the role

We’re looking for a Security Engineer to be a key hire on our Engineering team and own our cloud and product security posture as we scale. You’ll work across our AWS and Cloudflare estate, harden our secure SDLC, run pen testing efforts end-to-end, and threat-model the features powering our connectors, OAuth flows, and agent execution paths.

It’s a hands-on, DevSecOps-heavy role: you write code, ship tooling, and embed security into how engineers work every day. You’ll report directly to the CTO and have broad scope across the platform (from CI/CD pipelines to multi-tenant APIs to incident response on authentication flows).

Responsibilities

  • Own the secure SDLC: drive SAST, dependency scanning, secrets detection, and PR-blocking standards across every repository.

  • Harden our AWS and Cloudflare estate: IAM, secrets, network segmentation, KMS, WAF, GuardDuty, and zero-trust patterns.

  • Run pen testing end-to-end: scope and coordinate engagements with both AI-driven scanners and human researchers, then drive findings through fix and retest.

  • Threat-model product features before they ship, new Auth provider, expanded multi-tenant APIs, connector executions, agent tool-calling paths etc.

  • Build detection and response capability around credential and authentication flows, with observability that closes incidents fast.

  • Partner with engineering to raise the bar day-to-day: architecture reviews, written standards, and security embedded in code review.

  • Use LLMs and agents to accelerate security workflows (triage, code review, evidence gathering) with guardrails you trust and help secure and monitor the (code/application/device) fleet.

  • Support compliance work where it intersects security engineering: SOC 2, ISO 27001, customer security reviews, and pen test responses.

What we’re looking for

  • 3+ years in security engineering with hands-on AWS security: IAM, KMS, networking, secrets, GuardDuty / Security Hub.

  • Strong coding ability in TypeScript or Python or Go comfortable shipping production code, not just configs and scripts.

  • Application security fluency: OWASP Top 10, threat modeling, and code-level reviews on real systems.

  • Experience securing a B2B SaaS multi-tenant production environment.

  • Comfort owning end-to-end work: scope, ship, measure. You don’t wait for a queue.

  • Clear communication with engineers, product, and non-technical stakeholders.

  • Bias toward automating security checks instead of running manual checklists.

  • (Preferred) IaC fluency in AWS CDK or Terraform , comfortable reviewing infrastructure code for security misconfigs and writing custom scanning rules.

  • (Preferred) Experience with Aikido, Drata, Cloudflare Workers, or pen testing in a compliance-mature environment.

Our Stack

We’re pragmatic about tooling. Today’s stack includes:

  • Cloud & infra: AWS (ECS, RDS, Lambda, KMS, GuardDuty, Security Hub, Inspector), Cloudflare (Workers, WAF, Zero Trust)

  • IaC: AWS CDK, Terraform

  • Security tooling: Aikido (SAST, DAST, container scanning, pen testing), 1Password, GitHub (org-level enforcement, Advanced Security)

  • Compliance & ops: Drata, Iru, EasyLlama

  • Observability & IR: Datadog, Sentry, Logfire, Incident.io

  • Languages: TypeScript (Node.js), Python

Benefits

  • Meaningful share options (EMI) - share in the company’s success as we grow

  • 25 days holiday + 1 additional day per year of tenure

  • Private health insurance - including dental & optical

  • £15/day lunch budget when working from our London office, up to £120/month

  • £1,000 for your home office set up + £500/year top-up

  • Annual team offsite to sunny spots (last ones were in Spain and Portugal ☀️)

  • Join one of Europe’s fastest-growing startups

  • Work with a veteran team of ex-employees of Google, Microsoft, Oracle, Coinbase, JP Morgan and more

  • Health, fitness and gift card discounts

  • Cycle2Work and Electric Cars scheme

  • Hybrid working friendly - typically 2 days/week in our London office. We’re open to discussing flexible arrangements—please share any preferences in your application

We believe diversity drives innovation. We encourage individuals from all backgrounds to apply. As an equal-opportunity employer, we celebrate diversity and are committed to creating an inclusive environment for all employees.

About StackOne

Unified API gateway for SaaS and AI agent integrations.

Year founded
2023
Employees
75
Organization type
Private
Latest investment
Raised $20.00M Series A (2025) — led by GV
Headquarters
GB

Similar jobs

Security Engineer roles near London, England
14h
Save
Mark Applied
Hide
Security Engineer
Farnborough, England, United Kingdom
OnsiteFull Time
SiXworks: Secure digital transformation for defence and national security.
Security engineering experience with SIEM, vulnerability management, secure CI/CD, threat frameworks, security documentation, and secure systems; UK highest-level clearance required or obtainable.
SIEM, ATT&CK, CI/CD, Kubernetes, Elastic EDR, EDR, Directory services, IdPs, Privileged Access Management, Windows, Linux, networking
5d
Save
Mark Applied
Hide
Security Engineer
London, England, United Kingdom
HybridFull Time
XTX Markets
XTX Markets: Provide liquidity to global financial markets through algorithmic trading.
1+ YOERequires 1–3 years of information security experience, proficiency in a statically typed language, systems knowledge, strong communication, clear writing, autonomy, and attention to detail; OSCP and CTF experience preferred.
Golang, Python
5d
Save
Mark Applied
Hide
Staff Security Engineer
Dublin or London
HybridFull Time
Ripple
Ripple: Provides blockchain solutions for global payments and liquidity.
7+ YOE7+ years in security operations, detection engineering, or incident response; advanced blue-team expertise, scripting, REST APIs, SIEM/data pipelines, security tooling, technical design, and complex problem-solving.
Google Security Operations, Tines, Claude Code, OpenAI Codex, REST APIs, SIEM, EDR
5d
Save
Mark Applied
Hide
Sr. Security Engineer - GRC EU/UK Regulation & Data Protection
London, England, United Kingdom
OnsiteFull Time
xAI
xAI: Develops advanced artificial intelligence systems to understand the universe.
5+ YOEBachelor's degree and 5+ years in GRC, information security compliance, or technology audit in regulated fintech or financial services; EU/UK regulatory, technical controls, and GRC automation experience required.
Vanta, AWS, GCP, Azure, IAM, CI/CD, ISO 27001, SOC 2, DORA, EU AI Act, NIS2, PSD2, PSR, UK GDPR, EU GDPR, UK Data Protection Act 2018, ePrivacy, Digital Services Act, MiCA, FCA Consumer Duty
6d
Save
Mark Applied
Hide
Senior Security Engineer
London, England, United Kingdom
HybridFull Time
Zepz
Zepz: Provides digital cross-border money transfer and remittance platform services.
Security fundamentals, incident response across endpoint, cloud, and containerized environments, scripting and automation, SIEM and EDR experience, Infrastructure as Code familiarity, and NIST framework familiarity.
SIEM, EDR, Terraform, CloudFormation, NIST
1w
Save
Mark Applied
Hide
Security Engineer, AWS Security
London, England, United Kingdom
OnsiteFull Time
Amazon
AmazonNASDAQ: AMZN: Global online retail and cloud computing technology provider.
Bachelor's degree in computer science, computer engineering, or related field; security assessment, threat modeling, penetration testing, remediation, and coding or scripting experience required.
Python, C, C++, Java, Ruby, PowerShell, AWS, Perl, Linux bash, SSL/TLS
1w
Save
Mark Applied
Hide
Security Engineer
London, England, United Kingdom
HybridFull Time
LemFi
LemFi: Financial platform for multi-currency accounts and international money transfers.
2+ YOERequires 2–5 years of hands-on security experience, scripting and REST API skills, exposure to cloud, endpoint, MDM, DLP, identity, or SIEM tools, and knowledge of a major compliance framework.
AWS, Azure, GCP, REST APIs, SIEM, MDM, DLP, SOC 2, ISO 27001, PCI DSS, DORA, Bug Bounty
1w
Save
Mark Applied
Hide
Security Engineer
London, England, United Kingdom
£70k-£85k/yr HybridFull Time
Accurx
Accurx: Software for healthcare staff to communicate with patients and colleagues.
Security operations experience with vulnerability management, cloud hardening, incident response, access auditing, threat modeling, AI risk review, and clear communication.
CIS, NIST, LLM, MCP, SSO