{"version":"0.1","company":{"name":"YubHub","url":"https://yubhub.co","jobsUrl":"https://yubhub.co/jobs/skill/sboms"},"x-facet":{"type":"skill","slug":"sboms","display":"Sboms","count":2},"x-feed-size-limit":100,"x-feed-sort":"enriched_at desc","x-feed-notice":"This feed contains at most 100 jobs (the most recently enriched). For the full corpus, use the paginated /stats/by-facet endpoint or /search.","x-generator":"yubhub-xml-generator","x-rights":"Free to redistribute with attribution: \"Data by YubHub (https://yubhub.co)\"","x-schema":"Each entry in `jobs` follows https://schema.org/JobPosting. YubHub-native raw fields carry `x-` prefix.","jobs":[{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_50f687cf-610"},"title":"Cloud Security Software Engineer","description":"<p>As a Cloud Security Software Engineer at Engine by Starling, you will be a hands-on builder responsible for the security architecture of our multi-tenant core banking platform. You&#39;ll spend your days architecting and writing Go-based tooling, automating defenses, and ensuring our infrastructure across AWS and GCP is secure by design and compliant by default.</p>\n<p>Your mission is to solve complex security problems through software engineering, focusing on three core pillars:</p>\n<ul>\n<li>Identity &amp; Network Security: Engineering high-performance IAM controls and zero-trust network architectures.</li>\n<li>Unified Vulnerability Orchestration: Architecting a custom &#39;single pane of glass&#39; for security data.</li>\n<li>Compliance as Code: Building the automated systems that provide real-time evidence for frameworks like SOC 2, ISO 27001 &amp; PCI.</li>\n</ul>\n<p>You will be a key member of our growing Security Engineering team, working at the intersection of Infrastructure, Cross-Cutting, and GRC. We operate like a specialized product team: we identify security friction and build the software to eliminate it.</p>\n<p>You will lead the design and maintenance of our internal security tool suite, written primarily in Go, to automate evidence collection and real-time remediation of security alerts. You will also write and peer-review Terraform and custom providers to manage identity and core infrastructure across AWS and GCP.</p>\n<p>The team supports the use of Go, Terraform, Kubernetes, and Cilium. Experience with eBPF, Sigstore/Cosign, image provenance, and SBOMs is desirable.</p>\n<p>Engine by Starling offers a range of benefits, including 33 days holiday, an extra day&#39;s holiday for your birthday, annual leave increased with length of service, and a company-enhanced pension scheme.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_50f687cf-610","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Engine by Starling","sameAs":"https://www.enginebystarling.com/","logo":"https://logos.yubhub.co/enginebystarling.com.png"},"x-apply-url":"https://apply.workable.com/j/04657FA2B4","x-work-arrangement":"remote","x-experience-level":"mid","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["Go","Cloud Native","Container Expertise","Identity & Networking","Cloud Native Defense"],"x-skills-preferred":["Cilium","eBPF","Sigstore/Cosign","image provenance","SBOMs"],"datePosted":"2026-03-20T16:15:05.393Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"London"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Go, Cloud Native, Container Expertise, Identity & Networking, Cloud Native Defense, Cilium, eBPF, Sigstore/Cosign, image provenance, SBOMs"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_ee9f5559-165"},"title":"Cloud Security Software Engineer","description":"<p>Job Description:</p>\n<p>About Engineering at Engine by Starling</p>\n<p>At Engine by Starling, we don&#39;t do &#39;checkbox security&#39;,we build security software. We treat security as a first-class engineering discipline, where the solution to a threat isn&#39;t a policy, but a robust, concurrent system written in Go.</p>\n<p>As a Cloud Security Software Engineer, you will be a hands-on builder responsible for the security architecture of our multi-tenant core banking platform. You&#39;ll spend your days architecting and writing Go-based tooling, automating defenses, and ensuring our infrastructure across AWS and GCP is secure by design and compliant by default.</p>\n<p>The Mission</p>\n<p>Your mission is to solve complex security problems through software engineering, focusing on three core pillars:</p>\n<ul>\n<li>Identity &amp; Network Security: Engineering high-performance IAM controls and zero-trust network architectures. You will lead the way in refining edge-defense strategies and trust redirection, ensuring every request is verified and encrypted at scale.</li>\n<li>Unified Vulnerability Orchestration: Architecting a custom &#39;single pane of glass&#39; for security data. You will build Go-based API integrations and microservices that bridge scanning engines, dependency trackers, and internal portals into a seamless, automated ecosystem.</li>\n<li>Compliance as Code: Building the automated systems that provide real-time evidence for frameworks like SOC 2, ISO 27001 &amp; PCI. You’ll ensure we stay compliant through continuous, automated validation rather than manual overhead.</li>\n</ul>\n<p>The Team</p>\n<p>You will be a key member of our growing Security Engineering team, working at the intersection of Infrastructure, Cross-Cutting, and GRC. We operate like a specialized product team: we identify security friction and build the software to eliminate it. You won’t work in a silo; you’ll collaborate with engineers across the business to deliver a platform that is resilient by default.</p>\n<p>About You</p>\n<p>We are looking for Software Engineers who are passionate about the Go ecosystem and want to apply those skills to mission-critical security challenges. Whether you come from a Security Engineering background or you are a Backend Engineer with a &#39;security-first&#39; mindset, we value your ability to write clean, maintainable, and efficient code.</p>\n<p>What you’ll get to do</p>\n<ul>\n<li>Engineering Security Tooling: Lead the design and maintenance of our internal security tool suite, written primarily in Go, to automate evidence collection and real-time remediation of security alerts.</li>\n<li>Infrastructure as Code: Write and peer-review Terraform and custom providers to manage identity and core infrastructure across AWS and GCP.</li>\n<li>Supply Chain Security: Build automated systems to manage container provenance and integrate security analysis into our CI/CD pipelines (GitHub Actions/TeamCity).</li>\n<li>Cloud Native Defense: Engineer Kubernetes security solutions leveraging Cilium, eBPF, and custom controllers to protect our microservices.</li>\n<li>Cryptographic Engineering (PKI): Build and maintain our Go-based Certificate Authority (CA) tooling and internal PKI infrastructure.</li>\n<li>Incident Response: Support the team in automated incident response, building the tools that help us investigate and mitigate threats faster.</li>\n</ul>\n<p>Requirements</p>\n<p>What skills are essential:</p>\n<ul>\n<li>Go Specialist: You are proficient in Go. You understand its concurrency models, testing patterns, and how to build idiomatic, performant services.</li>\n<li>The Builder Mindset: You find manual work a personal affront. If a task needs to be done twice, you’ve already started planning the automation for it.</li>\n<li>Cloud Native: Practical experience with AWS or GCP, ideally managed through Terraform.</li>\n<li>Container Expertise: You understand Kubernetes internals,from the runtime security to the service mesh.</li>\n<li>Identity &amp; Networking: Strong understanding of cloud identity models and network protocols.</li>\n</ul>\n<p>What skills are desirable:</p>\n<ul>\n<li>Experience with Cilium or eBPF-based security monitoring.</li>\n<li>Knowledge of Sigstore/Cosign, image provenance, and SBOMs.</li>\n<li>Familiarity with hardware security modules (HSMs) or advanced cryptography.</li>\n<li>Cloud-native security certifications (AWS/GCP).</li>\n</ul>\n<p>Benefits</p>\n<ul>\n<li>33 days holiday (including public holidays, which you can take when it works best for you)</li>\n<li>An extra day’s holiday for your birthday</li>\n<li>Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off</li>\n<li>16 hours paid volunteering time a year</li>\n<li>Salary sacrifice, company enhanced pension scheme</li>\n<li>Life insurance at 4x your salary &amp; group income protection</li>\n<li>Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&amp;Mrs Smith and Peloton</li>\n<li>Generous family-friendly policies</li>\n<li>Incentives refer a friend scheme</li>\n<li>Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks</li>\n<li>Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing</li>\n</ul>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_ee9f5559-165","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Engine by Starling","sameAs":"https://www.enginebystarling.com/","logo":"https://logos.yubhub.co/enginebystarling.com.png"},"x-apply-url":"https://apply.workable.com/j/094F13AD03","x-work-arrangement":"hybrid","x-experience-level":"mid","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["Go","Terraform","Kubernetes","Cilium","eBPF","Sigstore","Cosign","image provenance","SBOMs","hardware security modules","advanced cryptography","cloud-native security certifications"],"x-skills-preferred":[],"datePosted":"2026-03-20T16:14:38.230Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"London"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Go, Terraform, Kubernetes, Cilium, eBPF, Sigstore, Cosign, image provenance, SBOMs, hardware security modules, advanced cryptography, cloud-native security certifications"}]}