Cloud Security & Compliance Engineer
Listed on 2026-01-14
-
IT/Tech
Cybersecurity
Shape the Future of Service Excellence with Ten!
Driving Innovation. Building Trust. Redefining Service Excellence.
Ten is on a mission to become the most trusted service business in the world. We service the most valuable customers of the world’s leading private banks, premium financial services and luxury brands globally including HSBC, Bank of America, and Swisscard. Corporate clients use Ten’s services to acquire, engage and retain affluent, high net worth customers or valued employees. The service drives critical customer metrics, including revenue growth, net promoter score, and supports digital transformation initiatives.
Millions of individuals worldwide have access to Ten's services across lifestyle, travel, dining and entertainment. They rely on Ten to unlock seamless, curated experiences that enrich their lives.
We’re profitable, ambitious, and scaling fast. As the first B Corp listed on the London Stock Exchange, we’re setting the standard for sustainable growth and technology, AI driven innovation.
For more information, check out our Welcome to Ten video!
We are seeking a Cloud Security & Compliance Engineer with strong governance, risk, and compliance (GRC) expertise to support the design, implementation, and management of secure cloud infrastructure. This role ensures compliance with regulatory requirements, especially PCI DSS and SOC 2, while enhancing the resilience and security of our cloud environments.
Key Responsibilities:
Cloud Security Engineering & Operations:
- Monitor and respond to threats
:
Continuously monitor cloud infrastructures for security alerts and vulnerabilities, conduct risk assessments on vulnerabilities, and ensure that all cloud security alerts are managed. - Vulnerability Management
:
Conduct vulnerability assessments, manage vulnerability scanning technologies, facilitate and / or conduct frequent penetration testing activities, ensure timely remediation of all vulnerabilities according to SLA, and ensure all impacted parties are kept current on remediation activities and timelines. - Security Controls & Tooling
:
Implement and maintain all cloud security tooling, including but not limited to IAM, network security controls, data encryption, secrets management, WAFs, FIM, cloud security posture management, SIEM, and IDS/IPS, ensuring that these security tools meet or exceed compliance and internal security control requirements at all times. - Automation & Monitoring
:
Develop security automation scripts using Infrastructure as Code (Terraform, Cloud Formation), maintain inventories of assets and security protocols, and maintain real-time security monitoring and ensuring that alerting is in place and functioning for all cloud systems. - Security Architecture & Design
:
Collaborate with engineering and operations teams to build and maintain secure cloud architectures (AWS essential; Azure considered). - Incident Management
:
Coordinate and manage cloud security incidents, ensure incident playbooks are in place and maintained for cloud applications and infrastructure, coordinate forensic investigations, ensure cloud recovery objectives are in place and tested regularly, and facilitate cloud security incident response activities.
- Security Testing & Simulations
:
Conduct frequent security incident response tests and social engineering simulations. - Security Compliance
:
Support and manage PCI DSS and SOC 2 Type 2 compliance initiatives; act as the primary liaison with auditors, assessors, and internal stakeholders for all cloud applications and infrastructure. - Security Governance
:
Develop, maintain, enforce and regularly test the effectiveness of security controls, update and align information security policies and procedures, ensuring alignment to PCI DSS, SOC 2, NIST, and ISO 27001 standards. - Risk Management
:
Conduct cloud risk assessments, maintain the cloud security risk register, drive mitigation strategies, reporting cloud risks to the appropriate risk bodies. - Secure Software Development
:
Participate in and ensure that the cloud Secure SDLC aligns to Ten Group’s compliance obligations, internal policies , and ensure SAST and DAST alerts are responded to as required,…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: