
Platform Security Engineer/ 3 hours ago
Quick Summary
Who Are We?
Gear4music is a leading UK & European musical instrument retailer. Since our launch in 2003, our mission has been to make music accessible for everyone. We currently offer over 67,000 products, serve customers in 190 countries, and operate in 15 languages and 9 currencies. In 2022, we expanded our offerings with AV.com, specializing in HiFi, Home Cinema, and related accessories.
Our operations are supported by a growing technical team. We recently achieved a turnover of £190 million and continue to grow, evolve, and innovate within the industry.
Who Are You?
We are looking for a motivated, flexible, and talented engineer who is enthusiastic about continuous learning and challenging themselves. You thrive in a collaborative and friendly work environment that delivers tangible projects. You take pride in your work from inception to completion, demonstrating a keen attention to detail. You are also a champion for new technologies when they align with business needs. We value personality and would love to learn about your interests.
Your Mission
You will collaborate with like-minded professionals across our software engineering, architecture, infrastructure, and testing teams. Your passion will be to embed security into every aspect of our work, including threat modeling, hardening cloud environments, enhancing IAM, automating controls, and documenting best practices. You will set high standards for your work, contributing to a secure, stable, and trusted platform that enables:
- Secure-by-design applications and services.
- Safe, reliable, and automated releases (progressing towards full CI/CD).
- Strong detection, response, and observability capabilities.
- A culture where security is shared, understood, and championed.
Your Stack
Essential
- Google Cloud security fundamentals: IAM, VPC design, Cloud Armor, Secrets, KMS.
- Cloudflare: WAF, Zero Trust, Access, DNS, Bot Management.
- Infrastructure-as-Code security: Terraform, policy-as-code, secure pipelines.
- Container & Kubernetes security: GKE, admission controls, image scanning, RBAC.
- Experience mitigating real-world security threats and vulnerabilities.
- Understanding of DevSecOps best practices and secure SDLC.
- Familiarity with CI/CD systems such as GitHub Actions and securing build pipelines.
- Monitoring & alerting: Prometheus, Grafana, GCP Monitoring, SIEM concepts.
Nice to Have
- Knowledge of any of: PHP, JavaScript, Go (for reviewing and securing code).
- Experience with web servers & proxies: Apache, Nginx, Traefik, HAProxy.
- Exposure to databases such as MySQL, MongoDB, Firebase, Elastic, Redis.
- Event stack experience: Kafka, RabbitMQ, ActiveMQ, GCP Pub/Sub.
- Network & request tracing including HTTP/1–3 and gRPC.
- Experience running security workshops, threat modeling sessions, or training.
We encourage you to apply even if you don't meet every single requirement. We are interested in hearing from candidates who are familiar with this type of technology stack.
Soft Skills
- Ability to plan and manage your workload across multiple projects and priorities.
- Comfortable collaborating, influencing, and sharing knowledge with other teams.
- Passionate about secure, scalable, and complex distributed systems.
- Confident communicating security concepts to both technical and non-technical audiences.
- Motivated to advance security across the business, not just maintain it.
Why Join Us?
We prioritize our employees. Our culture extends beyond superficial perks; we believe you are the most vital aspect of our business. We are committed to fostering your growth in an open and supportive environment, creating a safe space for sharing ideas and making necessary mistakes without fear of failure, as mistakes are integral to growth.
We encourage authenticity and celebrate individual quirks, recognizing their importance for innovation. We actively seek development opportunities and respond constructively to feedback. We proactively share advice to accelerate collective growth with new insights and perspectives. We celebrate shared successes and learn together from challenges.
We provide essential support, including trained mental health first aiders, a wellbeing coach, a focus on work-life balance, and tailored personal progression plans. Our Slack channel serves as a central hub for team connection.
We are deeply technical, with technical leaders extending to the board level. Our flat organizational structure ensures directors are accessible and engaged with teams. We promote open and honest feedback, even when critiquing leadership, fostering an environment free of power dynamics.
What We Offer
- Competitive and timely pay.
- Respect for your time with no expectation of long hours.
- A personal development plan and regular 1:1s.
- Your choice of Mac, Linux, or Windows Laptop.
- Health Assured Employee Assistance Programme.
- A generous staff discount scheme.
- Flexible hours and no dress code.
- Mental health first aiders.
- A strong learning culture with support for external training.
Additional Benefits
- Cycle to work scheme.
- Eyecare vouchers.
- Company pension scheme.
- Employee referral bonuses.

