Senior Security Engineer (SecOps)
Role details
Job location
Tech stack
Job description
As a Senior Security Engineer, you will work closely with our CISO, Security Lead and the wider infosec team to own and drive improvements in Accurx's critical security operations. You will enable Accurx in its mission to improve healthcare communication by ensuring the organisation is as prepared as possible for a cyber incident, understanding the main threats and risks it faces, and developing strategies to address them. As we grow into more care settings, by driving and encouraging high security standards, we empower our users to access better healthcare with confidence and safety. Your contributions will enable healthcare teams to confidently leverage technology, knowing their systems are secure, and focus on delivering the best care possible., As a Senior Security Engineer, you will be supporting and leading others on the implementation, execution, and maintenance of Accurx's core information security processes:
- Vulnerability Management
- Incident Detection, Readiness, & Response
- Security Hardening & Configuration
- Identity Management
- Security Advisory & Consulting
- Security Architecture & Design
- People Awareness
You will be responsible for driving these processes within one or more of the three security domains within Accurx:
-
Applications/product - The software products Accurx creates for our customers and users, such as Accurx Web/Desktop, Florey, Patient Portal, Switch, etc.
-
Cloud/platform - The cloud-based platforms, such as Azure, that Accurx maintains to host our products and cloud-based operational processes.
Requirements
- You've got experience working as a Senior Security Engineer, SecOps Engineer or as a Security Consultant
- You can craft appropriate and effective incident response procedures or playbooks for specific scenarios or security incidents that, based on your expert opinion, are most likely to affect an organisation like Accurx.
- You are well versed in vulnerability management concepts and tooling, and can use them to monitor and drive the management and remediation of an organisation's known vulnerabilities.
- You have an advanced understanding of cloud technology concepts and their associated security considerations including: user access control, network access control, logging and monitoring, encryption, cloud storage, secrets/key management, software/platform/infrastructure as a service
- You have a wide reaching knowledge of application security concepts, tools and vulnerabilities
- You have a proficient knowledge of core networking concepts and technologies, and understand the security risks associated with different networking technologies and protocols at each layer of the TCP/IP stack/OSI 7 Layer Model.
- You are comfortable leading as an organisation-wide security champion. You recognise important security knowledge, trends, events, or advice and are proactive in sharing it within an organisation and beyond where necessary.
- You're a high performer: you connect to our high-performance principles
- You're mission-driven: you care about positively impacting the lives of millions
- You're always collaborating: you place team success over personal success and you enjoy working in an open, collaborative environment.
- You demonstrate responsible ownership: when you see something not working, you'll flag it and be part of the solution
- You seek continuous improvement: you're always developing new skills and insights while exploring ways to do things better
- You're mindful of balance: you're conscious of your health and that of others. You think carefully about how best to focus your efforts, knowing when to push yourself to reach a goal.
Benefits & conditions
£85,000 - £100,000 salary + the value of £50,750 share options Access to Happl - a flexible benefits provider with a budget of £600 to spend on perks of your choice. Options include private health insurance, wellness providers and more.
We are office first, all accuFolk come to our office in Shoreditch 3 days per week, with the option to work remotely 2 days a week. Read more about our hybrid policy.
Allocated annual learning & development budget
Enhanced parental leave policy
Prayer, meditation and breastfeeding room
In-house therapists are available daily
Working abroad policy