Rodeo
Get started

StackOne

Security Engineer

London
Posted 3 months ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

About StackOne

StackOne is the integration infrastructure for AI agents. Backed by GV and Workday Ventures ($24M raised), we make it possible for any AI agent — whether our customers build it into their product or buy it off the shelf — to take real action across the enterprise stack. Our platform gives agents 430+ connectors and 26,000+ pre-built actions, an AI connector builder for everything not covered yet, and the production layer agents actually need: semantic tool discovery that cuts token use by up to 80%, managed authentication and per-action permissions, the most accurate prompt injection defense on the market, and end-to-end observability.

Join us on our fast trajectory to build the future of agentic integrations.

About the role

We’re looking for a Security Engineer to be a key hire on our Engineering team and own our cloud and product security posture as we scale. You’ll work across our AWS and Cloudflare estate, harden our secure SDLC, run pen testing efforts end-to-end, and threat-model the features powering our connectors, OAuth flows, and agent execution paths.

It’s a hands-on, DevSecOps-heavy role: you write code, ship tooling, and embed security into how engineers work every day. You’ll report directly to the CTO and have broad scope across the platform (from CI/CD pipelines to multi-tenant APIs to incident response on authentication flows).

Responsibilities

  • Own the secure SDLC: drive SAST, dependency scanning, secrets detection, and PR-blocking standards across every repository.
  • Harden our AWS and Cloudflare estate: IAM, secrets, network segmentation, KMS, WAF, GuardDuty, and zero-trust patterns.
  • Run pen testing end-to-end: scope and coordinate engagements with both AI-driven scanners and human researchers, then drive findings through fix and retest.
  • Threat-model product features before they ship, new Auth provider, expanded multi-tenant APIs, connector executions, agent tool-calling paths etc.
  • Build detection and response capability around credential and authentication flows, with observability that closes incidents fast.
  • Partner with engineering to raise the bar day-to-day: architecture reviews, written standards, and security embedded in code review.
  • Use LLMs and agents to accelerate security workflows (triage, code review, evidence gathering) with guardrails you trust and help secure and monitor the (code/application/device) fleet.
  • Support compliance work where it intersects security engineering: SOC 2, ISO 27001, customer security reviews, and pen test responses.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

What we’re looking for

  • 3+ years in security engineering with hands-on AWS security: IAM, KMS, networking, secrets, GuardDuty / Security Hub.
  • Strong coding ability in TypeScript or Python or Go comfortable shipping production code, not just configs and scripts.
  • Application security fluency: OWASP Top 10, threat modeling, and code-level reviews on real systems.
  • Experience securing a B2B SaaS multi-tenant production environment.
  • Comfort owning end-to-end work: scope, ship, measure. You don’t wait for a queue.
  • Clear communication with engineers, product, and non-technical stakeholders.
  • Bias toward automating security checks instead of running manual checklists.
  • (Preferred) IaC fluency in AWS CDK or Terraform, comfortable reviewing infrastructure code for security misconfigs and writing custom scanning rules.
  • (Preferred) Experience with Aikido, Drata, Cloudflare Workers, or pen testing in a compliance-mature environment.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Our Stack

We’re pragmatic about tooling. Today’s stack includes:

Cloud & infra: AWS (ECS, RDS, Lambda, KMS, GuardDuty, Security Hub, Inspector), Cloudflare (Workers, WAF, Zero Trust)

IaC: AWS CDK, Terraform

Security tooling: Aikido (SAST, DAST, container scanning, pen testing), 1Password, GitHub (org-level enforcement, Advanced Security)

Compliance & ops: Drata, Iru, EasyLlama

Observability & IR: Datadog, Sentry, Logfire, Incident.io

Languages: TypeScript (Node.js), Python

Benefits

  • Join one of Europe's fastest-growing startups.
  • Work alongside an experienced team, with backgrounds from Google, Microsoft, Oracle, Coinbase, JP Morgan, and more.
  • Meaningful share options (EMI) — share in the company's success as we grow.
  • Flexible hours and hybrid working — some flexibility in start and finish times, with 2 days minimum in our London office (come in more if you prefer!)
  • 25 days holiday + 1 additional day per year of tenure.
  • Private health insurance — including dental & optical.
  • £15/day lunch budget when working from our London office, up to £180/month.
  • £1,000 for your home office setup + £500/year top-up.
  • Health, fitness and gift card discounts.
  • Cycle2Work and Electric Cars scheme.
  • Annual team offsites to sunny spots (last ones were in Croatia and Portugal ☀️)

We’re open to discussing flexible arrangements – please share any preferences in your application.

We believe diversity drives innovation. We encourage individuals from all backgrounds to apply. As an equal-opportunity employer, we celebrate diversity and are committed to creating an inclusive environment for all employees.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

AWS Security
TypeScript
Python
Application Security
Threat Modeling
DevSecOps
IAM
KMS
OWASP Top 10
Secure SDLC
Penetration Testing
OAuth
Multi-tenant API Security
Cloudflare
SAST
DAST

Location

London, England, United Kingdom

Sign up to applySee more jobs like this