Skip to main content
AfterDuty

Security Platform Engineering Manager

CMC Markets · London, Greater London

Type
Full-time
Posted
16 days ago

Overview

Your incident command and risk assessment skills are less relevant here; this role demands deep cloud engineering and coding expertise.

About this role

We are looking for a Security Platform Engineering Manager to define, build and operate a portfolio of reusable security capabilities that can be consumed by engineering squads as part of our product delivery. This role will combine technical leadership with hands on engineering, ensuring that security controls are delivered as code, embedded into infrastructure and CI/CD pipelines, and aligned to our AWS first, Terraform led platform model.

We are looking to expand and mature further our Platform Engineering capabilities by introducing a Security Platform Engineering team, with a goal to make secure by default the best and easiest path for squads building customer facing services. This team will engineer and operate reusable security capabilities as internal products, embedding security controls directly into infrastructure, CI/CD pipelines and service templates. Working closely with Cloud Platform Engineering, Security Operations and other engineering squads, the function will focus on reducing risk through automation, consistency and developer experience.

The successful candidate will be responsible for shaping the roadmap, forming the team to deliver it, driving adoption across build and run squads, and ensuring that security becomes a scalable, automated and measurable capability rather than a manual or reactive process.

ROLE AND RESPONSIBILITIES

  • Work with the Head of Cloud and security stakeholders to define the strategic direction and technical vision of security platform engineering at CMC
  • Build and lead a small team responsible for delivering security capabilities as reusable platform “products”
  • Own the roadmap and technical delivery of these capabilities across cloud infrastructure, CI/CD, IAM, application integration patterns and more
  • Engage and collaborate with internal customers and understand up and coming use cases for the security platform
  • Deliver hands on contributions to the platform; set technical standards and approach
  • Operate and support the security platform services with clear reliability expectations and continuous improvement
  • Drive measurable adoption of security platform services across engineering teams and report on coverage, risk reduction and maturity
  • Stay up-to-date on industry trends and emerging technologies and incorporate them into the platform roadmap as necessary
  • Mentor and coach the team through pairing, feedback and your behaviour

KEY SKILLS AND EXPERIENCE

Required

Demonstrable experience in the following

  • Securing cloud native workloads, ideally within AWS and serverless architectures
  • Managing services required to deliver secure applications such as firewalls, package management and secrets management
  • Deep understanding of IAM, least privilege access design and secure service to service communication patterns
  • Integrating security controls into CI/CD pipelines, preferably using GitHub Actions
  • Enforcing security standards on Infrastructure as Code (e.g. via Policy as Code)
  • Ability to translate regulatory or security policy requirements into practical, automated engineering controls
  • Leading team technical delivery in a cross functional environment with multiple stakeholder groups
  • Building and operating security capabilities at scale to support product development

Preferred

  • Experience writing Terraform to configure and manage security tooling and services
  • Experience with GitHub Advanced Security features such as code scanning, dependency review and secret scanning
  • Experience in developing hardened golden image pipelines for containers and virtual machines
  • Experience integrating Wiz or similar CNAPP tools into developer workflows
  • Experience delivering identity or access management capabilities as shared internal services
  • Experience operating in a Platform Engineering model supporting build and run squads in a regulated environment

CMC Markets is an equal opportunities employer and positively encourages applications from suitably qualified and eligible candidates regardless of gender, sexual orientation, marital or civil partner status, gender reassignment, race, colour, nationality, ethnic or national origin, religion or belief, disability or age.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background

  • Working to legislation & regulation
  • Security operations
  • Team & shift leadership

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • £35,000 – £40,000Estimated

    Your risk assessment and incident management skills from policing are directly applicable to this GRC role.

    Posted 3 days ago

  • Full-time

    Your incident command and multi-agency coordination experience translates directly to operational resilience and third-party oversight.

    Posted 3 days ago

  • Full-time

    Your investigative mindset and evidence-handling discipline from policing transfer directly to digital forensics and incident response.

    Posted 4 days ago

  • GRC Manager - 6 month FTC

    Trayport · London

    Full-time

    Your experience managing risk, policy, and regulatory compliance under frameworks like PACE transfers directly to GRC.

    Posted 6 days ago