Security Engineer
Company
Netcraft
Date Posted
21-08-2025
Location
London, England, United Kingdom
About Netcraft
Netcraft is the global leader in cybercrime detection and disruption. We’re a trusted partner for three of the four largest companies in the world and many large country governments. We’ve blocked more than 200 million malicious sites and perform takedowns for around one-third of the world’s phishing sites.
Our purpose, passion, and expertise are focused on just one thing: protecting the world from cybercrime.
Our passion doesn’t stop at what we do—it shapes how we work, too. We’re proud of our talented team and the value each person brings. That’s why we’ve created a workplace where people feel supported and inspired, from great benefits and wellness programs to fun social events.
The Role
We are searching for a Security Engineer to join our growing engineering team. Based in either London, Manchester, or Bath, you'll report to our Engineering Team Lead in the Security team, part of the Platform Engineering department. You will work within a team to build and maintain security tooling to help improve internal security capabilities across our platforms.
Netcraft’s Engineering division maintains a wide range of services, from modern Go-based applications that run in Kubernetes to twenty-year-old Perl-based systems that run directly on Linux servers. We use AWS for our customer-facing workloads, both directly on EC2 and on managed services such as RDS, EKS, ElastiCache, OpenSearch, S3, RabbitMQ, Security Lake, and more, running at scale with a high degree of automation: taking down a malicious site from the internet every 12 seconds, classifying 20 million URLs a day, and inspecting 1.2 billion sites every month.
This role will give you the opportunity to work collaboratively both within the Platform Engineering department and across the Engineering division to help us to continually improve our internal security and to enable teams to secure their systems. Your day-to-day work will involve developing internal security tooling and security-related CI/CD pipelines, supporting maintenance of security infrastructure in AWS, and investigating and responding to security incidents.
You'll be:
- Designing, developing, and maintaining internal security tooling for use by both the Security team and the wider Engineering division.
- Taking ownership of security-related CI/CD pipelines, including SCA tooling (Black Duck) and SAST scanning.
- Collaborating with other Engineering teams to enable them to secure the systems they develop.
- Helping respond to security alerts and incident investigations, including as part of our on-call rota once you are familiar with our systems.
- Testing and documenting your work to a high standard.
- Working with cross-functional stakeholders to help propose, design and implement solutions to meet business needs, as well as to champion security best-practices.
- Advocating for and implementing improvements to the Netcraft developer experience, leveraging your skills and experience to add value that doesn’t necessarily relate to Security
What you need to be successful:
- A keen interest in cybersecurity and a love of automation.
- Commercial experience programming in Go or similar languages.
- Commercial experience deploying, using, and tuning DevSecOps tooling, such as SAST/DAST scanners and SCA tools.
- Experience with modern CI/CD pipeline development, ideally in developing and helping roll out pipelines that are designed to be used across multiple projects.
- Experience using cloud providers, such as AWS, including their infrastructure and managed services.
- Experience responding to security-related incidents and writing retrospectives.
- Strong technical communication skills; especially the ability to explain your reasoning to Engineers across the division.
Bonus points:
- Experience with the GitLab DevOps stack, especially in CI/CD.
- Exposure to Infrastructure-as-Code technologies, ideally Terraform.
- Exposure to configuration management tools such as Puppet.
- Exposure to Kubernetes (especially hosted on AWS EKS) and Docker or other containerization technologies, with even more bonus points if your exposure extends to cluster security.
- A keen interest in cybercrime disruption and internet security.
- Experience with AWS security tooling, such as Security Lake, GuardDuty, CloudTrail, CloudWatch, Config or similar.
- Exposure to Microsoft 365 security tooling, such Defender or Entra.
- Experience supporting external security audits (such as SOC 2 or ISO 27001) through evidence-gathering and walkthroughs.
The reward package
An excellent range of benefits including:
- Hybrid working: please note that our expectation is two days per week in the office, with the flexibility to agree which days with your manager and vary these from time to time as needed.
- Minimum of 33 days holiday per annum (incl. public holidays)
- Pension scheme membership with 4% employer contributions + NI savings
- Private health cover, including access to a private GP service
- Equity tracking scheme, so you can share in the rewards of Netcraft's long-term success (eligibility criteria apply)
- Comprehensive wellness and support provisions
- Enhanced family leave provisions
- Life Assurance
- Two days paid Volunteering Leave per year
- Free meals, drinks and snacks provided daily in the offices
- Regular social events such as board game nights, big summer party and annual kick-off
- Inclusive culture and environment, where you’ll feel genuinely valued and respected; and
- A tax-efficient cycle to work scheme.
Diversity, Equity and Inclusion
This is very important to us and through our ally network we support under-represented groups. We seek to maintain a working environment that is free from bias, harassment or discrimination, and we encourage candidates from any background to apply, regardless of their gender, gender identity, sexual orientation, race/ethnicity, ability/disability, age, religion, or any other specific characteristics.
We’re happy to make adjustments to our hiring process to ensure that all candidates can participate fully and comfortably.
Please note Netcraft does not accept any unsolicited approaches from external recruiters.