Senior Cloud Security Engineer

Location    London (Uxbridge), UK, Oslo (Fornebu), Norway

Ava is a global technology company with offices in the UK, Norway, and the USA. We exist because we believe that we can create a better, smarter way to deliver security.

We inject intelligence into our approach to security and all our solutions. We help organisations see, understand, and act on their surroundings to protect their people, business, and reputation in real-time.

We know that the best way to meet our goals is with a diverse team, where everyone’s voice is heard. We’re proud that our company comprises 24 nationalities and we’re always looking to increase the variety of ideas and points of view at Ava.

We founded Ava Cyber in 2016 and Ava Video in 2018 and the two companies merged in 2020 to become a unified security provider with extensive capital investment from Ubon Partners.

About this position

You will work alongside the Ava Security Group to improve product security processes and tooling, across both the Reveal and Aware cloud deployments. Your work will help shape and implement the Secure Software Development Lifecycle (SSDL) within Ava Security.

This job requires both hands on security work and high level planning and prioritisation.

Work will include all aspects of the SSDL and you will support the product teams by:

  • Using modeling and analysis to direct testing of software, systems and processes for vulnerabilities
  • Finding security flaws either by development or by use of existing  tools, as well as driving tools to deliver on a test plan of your devising
  • Dealing with vulnerabilities when they have been found, including suggesting fixes and identifying process failures that led to vulnerabilities being present
  • Repeating the above and continuously improving on it.

We are looking for someone who can show empathy towards the development process.  You will be able to work creatively to improve security in a way that fits the product teams, but be a leader and shape the process when it's inadequate.

We are a small company with a diverse team, so you will also be involved in mentoring graduates. This is extremely important and is a part of all of our experienced roles.

About you

You will have several years experience doing security work. You’re not expected to have all of the following skills, but they will be useful in performing your job.

  • Practical understanding of how data is protected at rest and in transit, including the particulars of TLS, PKI, encryption, key management, identity management and RBAC.
  • Familiarity with common problems found in software development - and mitigations in different circumstances. Think OWASP Top Ten.
  • Enthusiastic about writing threat models, and have kept them up to date as projects changed in previous roles.
  • Knowledge of securing a cloud environment, including Kubernetes.  Experience specifically with Google Cloud and GKE is a plus.
  • Experience with the software build process, static analysis and understanding of the benefits of Continuous Integration.
  • Understanding of security testing, for example using tools such as OWASP Zap, Burp Suite or Nmap.

At Ava Security we default to using Go, but also use a wide variety of different languages and frameworks. It's not expected that you would be familiar with Go (or any of the other languages we use) but you should be an enthusiastic programmer willing to learn new things.

Does this sound like you? We'd love you to apply, even if you don't meet 100% of the requirements and qualifications.

What we offer

  • Attractive salary with possibility for stock options.
  • Flexible working hours.
  • A remote-friendly organisation, with colleagues working remotely either part or full-time.
  • A startup with solid financial backing and long-term horizon.
  • Travel opportunities, as we have R&D offices in London & Oslo and Sales offices in the US.
  • An international group of colleagues, working on anything from hardware, software, user experience, artificial intelligence, machine learning, audio/video processing, and analytics, mechanical, and industrial design.
  • Visa sponsorship available.
  • Newly refurbished and modern offices with disabled access at Technopolis in Fornebu, right outside Oslo, Norway or at The Charter Building in Uxbridge, London, UK.

Ava is dedicated to encouraging and sustaining a culture of inclusion. We know that we are able to develop and learn better with a diverse group of people. The experiences, ideas, knowledge, self-expression and talent of our employees form our culture and are instrumental in our success.

We are an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to and will not be discriminated against based on age, race, gender, colour, religion, national origin, sexual orientation, gender identity, disability or any other protected category.