Senior Cloud Security Engineer

Healthhero
London, UK
26 days ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Amazon Web Services Software System Penetration Testing Microsoft Azure Cloud Computing Cloud Computing Security Cyber Security Continuous Integration Data Governance HP Systems Insight Manager Identity and Access Management Integrated Development Environments
+18 more
Key Management Network Security Network Segmentation Systems Development Life Cycle Secure Coding Security Software Security Information and Event Management Software Engineering Software Vulnerability Management Data Logging Cloud Platform System Software Security Kubernetes Enterprise Integration Terraform Devsecops Static Application Security Testing Dynamic Application Security Testing

Job description

This role will form a fundamental part of a growing Platform Security function, where the team covers application security, cloud security, security operations, culture and risk management. As a tech-centric organisation the Information Security team will play a critical part in embedding a security-first mindset into application development and continuous application monitoring. This role will co-own the cloud security posture and tooling across HealthHero’s AWS and Azure estates and have the opportunity to tackle cloud security with an international scope. The role will be supported by a multidisciplinary force of Infrastructure, Data Governance and Engineering team leads with a security focus as part of their remit. The role has a focus on infrastructure and cloud networking when it comes to security posture.

As an experienced Cloud Security Engineer, your working day will include but not be limited to:

DevSecOps & SDLC

  • Champion integration of security testing into CI/CD pipelines across all development teams and usage of automated security gates: SAST, DAST, dependency scanning, secrets detection
  • Enable self-serve security tooling for development teams
  • Ability to set up development environment

Cloud Security

  • Own cloud security posture management using Wiz (or similar CSPM) Define and enforce cloud security baselines, guardrails, and policies in AWS
  • Implement and maintain IaC security scanning for Terraform
  • Manage IAM policies, network segmentation, and secrets management
  • Configure and tune SIEM (or similar) for cloud-focused detection
  • Establish logging, monitoring, and alerting requirements based on threat modelling
  • Investigate and respond to cloud security events

Risk & Compliance

  • Identify, articulate, and escalate security risks to senior leadership with mitigation plans
  • Track and remediate vulnerabilities across infrastructure
  • Manage customer initiatives related to due diligence when required to
  • Support and develop annual programme of Penetration Testing and associated remediations

Stakeholder Engagement

  • Partner with internal and stakeholder management to support any requirements from the security function - particularly governance and accreditation requirements across different countries
  • Provide expertise on emerging threats and vulnerabilities
  • Support response to customer/client due diligence requests with timely and accurate information regarding vulnerability exposure

Requirements

Essential

  • Proven experience in application security, DevSecOps, or cloud security
  • Strong understanding of cloud networking
  • Experience securing cloud environments (AWS, Azure)
  • Ability to read and write IAC (Terraform) code, comfortable with IAC lifecycles
  • Familiarity with container security and Kubernetes
  • Understanding of secure coding, penetration testing techniques, SIEM, and vulnerability management
  • Strong technical skills relevant to Information Security such as secure coding standards, ethical hacking techniques, network security and risk analysis
  • Understanding of managing Secure Development Lifecycle and Vulnerability Management.
  • Understanding and practical experience of ISO27001:2022 controls and audit processes

Desirable

  • AWS Security Specialty or similar certification
  • Experience in regulated environments (healthcare, financial services)
  • Familiarity with NHS DSPT
  • Technical knowledge of GDPR and data protection requirements
  • Hands-on with CI/CD security tooling and pipeline integration
  • Interest in learning other countries health and security regulations (France / UK / IR / DE), * Cloud Security

Benefits & conditions

  • An opportunity to work as part of an experienced team who are passionate in their field, supportive, diverse and dynamic.
  • 25 days leave.
  • Bank Holidays and your birthday off as leave.
  • Regular 1-2-1s with your line Manager.
  • 24/7 on-call staff support.
  • Auto-enrolment pension scheme.
  • Health Scheme and access to our Employee Assistance Programme.
  • Life Insurance Scheme.

About the company

We are HealthHero, Europe’s largest digital clinic. Join us at a pivotal moment as we scale our digital healthcare platform across Europe - giving you the chance to shape security at the heart of a fast-growing, AI-driven business. We are recruiting an exciting Senior Cloud Security Engineer on an initial 12 month fixed term contract, with a view to becoming permanent - based in either our London or Bristol office two days per week., We exist to simplify healthcare and improve lives by making care feel instant, intelligent and human.

HealthHero is Europe’s largest digital health provider, delivering 4 million consultations per year. But we’re just getting started. We’ve built a seamless digital clinic that brings body and mind together - from GP appointments and mental health support to long-term condition management. By sitting behind the world’s leading insurers and employers and supporting public health systems, we make it easier for millions of people to get the care they need, exactly when they need it.

We are a high-growth, capital-backed business with a sophisticated scale strategy. Our team is a unique blend of those with strong digital experience, management consultants, creatives and industry-leading clinical experts.

We aren’t just digitising appointments; we’re building the next generation of healthcare. We’re creating an AI-powered, always-on ecosystem that learns from every interaction to shift the needle from reactive treatment to proactive, sustainable health. At HealthHero, we are digital when it should be and human where it counts.

Join us, and help build a next generation health system the world is waiting for.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.reed.co.uk

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

2:28 min

Understanding Kubernetes architecture and core cluster components

Marc Nimmerrichter · WWC 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all