G

Platform Security Engineer

Gear4music United Kingdom

Retail Musical Instruments · 201-500 employees

Sep 03
Remote security Mid (2-5 yrs) Full-time United Kingdom
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

You will work alongside engineering and infrastructure teams to build security into all processes, including threat modelling and cloud environment hardening. Your role involves automating security controls, improving IAM, and fostering a culture where security is shared and championed across the organization.

What they look for

Google Cloud IAM Cloudflare Terraform Kubernetes CI/CD DevSecOps Threat modelling Prometheus Grafana Security hardening Infrastructure-as-Code Container security Vulnerability mitigation Observability Automation

Requirements

The ideal candidate has strong experience with Google Cloud security, Cloudflare, and Infrastructure-as-Code tools like Terraform. You should be proficient in container security, CI/CD pipeline security, and have a solid understanding of DevSecOps best practices.

Benefits

Personal development plan Staff discount scheme Health Assured Employee Assistance Programme Cycle to work scheme Eyecare vouchers Company pension scheme Employee referral bonuses Flexible hours Mental health first aiders

Full description

Who Are We?Gear4music is a leading UK & European musical retailer. Since launching in 2003, our mission has been to make music accessible for all. We now offer over 67,000 products, serve customers in 190 countries, and operate in 15 languages and 9 currencies. In 2022, we also launched AV.com – retailing HiFi, Home Cinema, and accessories. Behind the scenes, we’re powered by a growing technical team who make all of this possible. We recently turned over £190m and continue to grow, evolve, and innovate.

Who Are You? You are a motivated, flexible and talented engineer who is enthusiastic about learning new things and challenging themselves. You’re not a lone ranger but believe in a joined up and friendly work environment that delivers real projects, working collaboratively excites you. You’re someone who takes pride in the things you do and likes to see things from beginning to end. You love the attention to detail and might admit it's a blessing and a curse. You will champion new technologies when it’s right for the business. You’ll also need some personality, a strong GIF-game, and we’d love to know what you’re into.. to an extent. Your Mission To work alongside like‑minded people across our software engineering, architecture, infrastructure and testing teams. To be passionate about building security into everything we do; whether that’s threat modelling, hardening cloud environments, improving IAM, automating controls, or documenting best practice (or all of the above). To set high standards for yourself and the work you deliver, helping us create a secure, stable and trusted platform, enabling:

  • Secure‑by‑design applications and services
  • Safe, reliable and automated releases (working towards full CI/CD)
  • Strong detection, response and observability
  • A culture where security is shared, understood and championed

Your Stack Essential

  • Google Cloud security fundamentals: IAM, VPC design, Cloud Armor, Secrets, KMS
  • Cloudflare: WAF, Zero Trust, Access, DNS, Bot Management
  • Infrastructure‑as‑Code security: Terraform, policy‑as‑code, secure pipelines
  • Container & Kubernetes security: GKE, admission controls, image scanning, RBAC
  • Experience mitigating real‑world security threats and vulnerabilities
  • Understanding of DevSecOps best practice and secure SDLC
  • Familiarity with CI/CD systems such as GitHub Actions and securing build pipelines
  • Monitoring & alerting: Prometheus, Grafana, GCP Monitoring, SIEM concepts

Nice to Have

  • Knowledge of any of: PHP, JavaScript, Go (for reviewing and securing code)
  • Experience with web servers & proxies: Apache, Nginx, Traefik, HAProxy
  • Exposure to databases such as MySQL, MongoDB, Firebase, Elastic, Redis
  • Event stack experience: Kafka, RabbitMQ, ActiveMQ, GCP Pub/Sub
  • Network & request tracing including HTTP/1–3 and gRPC
  • Experience running security workshops, threat modelling sessions or training

Soft and Fluffy Description of Skills

  • Able to plan and manage your workload across multiple projects and priorities
  • Comfortable collaborating, influencing and sharing knowledge with other teams
  • Passionate about secure, scalable and complex distributed systems
  • Confident communicating security concepts to both technical and non‑technical people
  • Motivated to push security forward across the business, not just maintain it

Don’t worry if you can’t tick all of these boxes! If you did, you might be exaggerating. We’d like to hear from you if this sounds like the kind of tech stack you’re used to working with.

Why Us? Because we care about YOU. We pride ourselves on our culture, offering more than gimmicky branded merch and a PS5 you don’t have time to play. You are the most important aspect of our business. We want to grow and nurture you in an open and supportive environment. We create a safe and conducive atmosphere for you to share your ideas and make the necessary mistakes without the fear of failing - after all, mistakes are growing pains! We bring our most authentic selves forward - no need to pretend to be something you’re not, we’d rather your energy went into something more fulfilling. We embrace and encourage individual quirks and believe these qualities should be celebrated as they are vital to our innovation. We actively seek new ways to develop ourselves and respond to feedback constructively. We proactively share advice with others to accelerate our growth with new insights and perspectives. We celebrate each others success because when we win, we win together and if we don't win, we learn together! We've got important things covered, like having properly trained mental health first aiders, a wellbeing coach, work-life balance, tailored personal progression plans and the glue that holds us all together - our Slack channel. We’re techy to the core, with technical leaders through to board level. We pride ourselves on our flat structure where directors sit in with the teams and are there when you need them. We encourage open and honest feedback, even if you’re critiquing your boss. No power games here!

What We Will Offer

  • Great pay – and it’s always on time.
  • No expectation of long hours. We respect your time.
  • A personal development plan and regular 1:1s.
  • Your choice of Mac, Linux or Windows Laptop
  • Health Assured Employee Assistance Programme.
  • A generous staff discount scheme.
  • Flexible hours and no dress code.
  • Mental health first aiders.
  • A strong learning culture with support for external training.

And the usual good stuff:

  • Cycle to work scheme.
  • Eyecare vouchers.
  • Company pension scheme.
  • Employee referral bonuses.

Similar roles