RefolkCandidates
Open nowEngineeringEngineering

Security Engineer

StackOne · London, London

Location
London, London, United Kingdom
Workplace
Hybrid
Employment
Full time
Level
Mid level
Posted
4 months ago

About this role

About StackOne

StackOne is the integration infrastructure for AI agents. Backed by GV and Workday Ventures ($24M raised), we make it possible for any AI agent - whether our customers build it into their product or buy it off the shelf - to take real action across the enterprise stack. Our platform gives agents 430+ connectors and 26,000+ pre-built actions, an AI connector builder for everything not covered yet, and the production layer agents actually need: semantic tool discovery that cuts token use by up to 80%, managed authentication and per-action permissions, the most accurate prompt injection defense on the market, and end-to-end observability.

Join us on our fast trajectory to build the future of agentic integrations.

About the role

We’re looking for a Security Engineer to be a key hire on our Engineering team and own our cloud and product security posture as we scale. You’ll work across our AWS and Cloudflare estate, harden our secure SDLC, run pen testing efforts end-to-end, and threat-model the features powering our connectors, OAuth flows, and agent execution paths.

It’s a hands-on, DevSecOps-heavy role: you write code, ship tooling, and embed security into how engineers work every day. You’ll report directly to the CTO and have broad scope across the platform (from CI/CD pipelines to multi-tenant APIs to incident response on authentication flows).

Responsibilities

  • Own the secure SDLC: drive SAST, dependency scanning, secrets detection, and PR-blocking standards across every repository.

  • Harden our AWS and Cloudflare estate: IAM, secrets, network segmentation, KMS, WAF, GuardDuty, and zero-trust patterns.

  • Run pen testing end-to-end: scope and coordinate engagements with both AI-driven scanners and human researchers, then drive findings through fix and retest.

  • Threat-model product features before they ship, new Auth provider, expanded multi-tenant APIs, connector executions, agent tool-calling paths etc.

  • Build detection and response capability around credential and authentication flows, with observability that closes incidents fast.

  • Partner with engineering to raise the bar day-to-day: architecture reviews, written standards, and security embedded in code review.

  • Use LLMs and agents to accelerate security workflows (triage, code review, evidence gathering) with guardrails you trust and help secure and monitor the (code/application/device) fleet.

  • Support compliance work where it intersects security engineering: SOC 2, ISO 27001, customer security reviews, and pen test responses.

What we’re looking for

  • 3+ years in security engineering with hands-on AWS security: IAM, KMS, networking, secrets, GuardDuty / Security Hub.

  • Strong coding ability in TypeScript or Python or Go comfortable shipping production code, not just configs and scripts.

  • Application security fluency: OWASP Top 10, threat modeling, and code-level reviews on real systems.

  • Experience securing a B2B SaaS multi-tenant production environment.

  • Comfort owning end-to-end work: scope, ship, measure. You don’t wait for a queue.

  • Clear communication with engineers, product, and non-technical stakeholders.

  • Bias toward automating security checks instead of running manual checklists.

  • (Preferred) IaC fluency in AWS CDK or Terraform , comfortable reviewing infrastructure code for security misconfigs and writing custom scanning rules.

  • (Preferred) Experience with Aikido, Drata, Cloudflare Workers, or pen testing in a compliance-mature environment.

Our Stack

We’re pragmatic about tooling. Today’s stack includes:

  • Cloud & infra: AWS (ECS, RDS, Lambda, KMS, GuardDuty, Security Hub, Inspector), Cloudflare (Workers, WAF, Zero Trust)

  • IaC: AWS CDK, Terraform

  • Security tooling: Aikido (SAST, DAST, container scanning, pen testing), 1Password, GitHub (org-level enforcement, Advanced Security)

  • Compliance & ops: Drata, Iru, EasyLlama

  • Observability & IR: Datadog, Sentry, Logfire, Incident.io

  • Languages: TypeScript (Node.js), Python

Benefits

  • Meaningful share options (EMI) - share in the company’s success as we grow

  • 25 days holiday + 1 additional day per year of tenure

  • Private health insurance - including dental & optical

  • £15/day lunch budget when working from our London office, up to £180/month

  • £1,000 for your home office set up + £500/year top-up

  • Annual team offsite to sunny spots (last ones were in Croatia and Portugal ☀️)

  • Join one of Europe’s fastest-growing startups

  • Work with a veteran team of ex-employees of Google, Microsoft, Oracle, Coinbase, JP Morgan and more

  • Health, fitness and gift card discounts

  • Cycle2Work and Electric Cars scheme

  • Hybrid working friendly - typically 2 days/week in our London office. We’re open to discussing flexible arrangements - please share any preferences in your application

We believe diversity drives innovation. We encourage individuals from all backgrounds to apply. As an equal-opportunity employer, we celebrate diversity and are committed to creating an inclusive environment for all employees.

As published by StackOne. Applications are handled on their site.

Skills this posting mentions

SDLCOAuthCompliance

About StackOne

StackOne is the Agentic Integration Gateway - a toolkit for building and managing production-grade AI Agent integrations that are reliable, observable, and secure. We handle multi-tenant auth & permissions, multi-step action generation with our code-based AI integration builder, context optimization, and tool calling accuracy. This enables agents to ship with reliable context and actions instead of flaky, limited integrations.

All 5 openings at StackOne

One click, then it is written

Apply to StackOne with a resume written for this role.

Queue Security Engineer and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in StackOne’s form for you.

  1. 01Drop your resume

    A PDF or a LinkedIn URL. About a minute, once.

  2. 02I rank the openings

    Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.

  3. 03Each one is written up

    Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.

  • 25 sent a week, free
  • No card
  • Nothing sent until you say so

More roles at StackOne

See all

Similar roles elsewhere

See more

Put this to work

Paste your career in once. Every application after that is written for you.

Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.

  1. 01Drop your resume

    A PDF or a LinkedIn URL. About a minute, once.

  2. 02I rank the openings

    Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.

  3. 03Each one is written up

    Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.

  • New matches ranked and written before you are up.
  • Every bullet stays inside what your history supports. Nothing invented.
  • Queued, submitted, interviewing, offer: one screen, not a spreadsheet.

500 free credits on sign-up. No card. Nothing is sent until you say so.

Listed from the job board StackOne publishes. Refolk is not the employer and does not handle their hiring. Applications go to StackOne directly.