Senior Cloud Security Engineer

Psychiatry Uk
Camelford, UK
2 days ago
Apply on www.adzuna.co.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
£66,365.0
Working hours
Regular working hours

Tech stack

Microsoft Access Microsoft Windows Application Programming Interfaces (APIs) Amazon Web Services Amazon Elastic Compute Cloud Amazon S3 Software System Penetration Testing Microsoft Azure Backup Devices Microsoft Online Services Cloud Computing Security Cloud Engineering
+36 more
Cyber Security Databases Query Languages Digital Forensics Github Identity and Access Management Intrusion Detection and Prevention Python (Programming Language) Key Management Network Security Microsoft Security Essentials Virtual Desktops Windows PowerShell Role-Based Access Control Azure Active Directory Aws Command Line Interface (CLI) Security Information and Event Management Software Engineering Software Vulnerability Management Datadog Data Logging Cloud Platform System Spring Cloud Software Security Mitre Att&ck Cloudformation Microsoft InTune Amazon Relational Database Service Information Technology Cloudflare AWS Fargate Cloudwatch Terraform Devsecops Security Orchestration, Automation & Response Static Application Security Testing

Job description

The Senior Cloud Security Engineer is a senior, technically hands-on role with responsibility across cloud security engineering, platform assurance, DevSecOps, threat detection and continuous control improvement. The post holder will translate security policies, risk requirements and best practice into practical security guardrails, reusable patterns, automation and clear assurance evidence.

Working collaboratively across the organisation, the role will partner closely with Cyber Security, Platform Engineering, Software Engineering, Digital Workplace/IT, Data Science, Information Governance and Service Management teams, as well as selected managed-service partners, to embed effective security controls and secure-by-design principles across our technology environment.

This is a home-based role (applicants must reside in the UK), though occasional travel may be required for face-to-face meetings at various locations within the UK., * Own and evolve security guardrails, reference architectures and technical standards across AWS, Azure and Microsoft 365.

  • Design and assure security controls across identity, networking, compute, containers, storage, databases, encryption, secrets management, backup and recovery.
  • Provide senior technical review and challenge of cloud designs, threat models, Architecture Decision Records and significant changes.
  • Lead remediation of control gaps, ensuring security controls are practical, measurable and proportionate to risk and service criticality.

AWS Platform Security

  • Support and strengthen the AWS security operating model, including landing zones, account boundaries, access controls, permission models and break-glass arrangements.
  • Engineer and assure cloud-native security capabilities including IAM, KMS, CloudTrail, Config, GuardDuty, Inspector, Security Hub, CloudWatch and AWS Backup.
  • Drive security improvements across AWS workloads, including EC2, RDS, S3, ECS/Fargate, Lambda, ECR and internet-facing services.

Microsoft Cloud & Identity Security

  • Support and improve security across Microsoft 365 E5, Azure, Defender, Intune, Azure Virtual Desktop, Purview and SIEM capabilities.
  • Work with Digital Workplace teams and managed-service partners to validate controls, evidence their effectiveness and drive remediation.

DevSecOps, Application Security & Assurance

  • Embed Secure-by-Design principles across key projects through PUK’s Security and Technology Assurance Framework, maintaining proportionate and effective assurance criteria.
  • Integrate security into engineering workflows, CI/CD pipelines and cloud deployment patterns while minimising unnecessary delivery friction.
  • Implement and improve security testing, including SAST, SCA, secrets scanning, infrastructure-as-code, container and application security testing.
  • Partner with engineering teams on threat modelling, vulnerability remediation, dependency management and release assurance, promoting secure-by-default patterns and reusable solutions.

Detection, Vulnerability Management & Incident Response

  • Ensure security telemetry across cloud, identity, network, workloads and applications is complete, protected and effectively monitored.
  • Lead technical assessment of complex vulnerabilities and misconfigurations, driving proportionate, risk-based remediation.
  • Act as a senior technical responder for cloud security incidents, supporting containment, investigation, recovery and lessons learned.
  • Work closely with PUK’s 24/7 SOC, digital forensics and incident response partners.

Governance, Compliance & Assurance

  • Translate regulatory, industry and organisational requirements-including ISO/IEC 27001, Cyber Essentials Plus, DSPT, NCSC frameworks and UK GDPR-into effective technical controls and evidence.
  • Maintain security engineering evidence to support audits, control testing, risk treatment and continuous improvement.
  • Provide security assurance for new systems, suppliers and material changes, covering areas such as access, encryption, logging, resilience, data residency and exit arrangements.
  • Contribute to security standards, hardening guidance, runbooks, architecture documentation and control reporting.

Technical Leadership & Collaboration

  • Provide senior technical leadership, coaching and constructive challenge across Cyber, Platform, Engineering and Digital Workplace teams.
  • Lead technical investigations and security improvement initiatives, communicating clear recommendations to technical and non-technical stakeholders.
  • Work effectively with cloud, security and managed-service partners while retaining PUK ownership of security risk and control outcomes.
  • Manage priorities independently, escalating risks early and maintaining clear technical and assurance documentation.

Requirements

A collaborative, pragmatic and technically credible security professional who combines strong analytical thinking with a clear focus on patients, services and operational outcomes. You will be comfortable working autonomously, managing competing priorities and remaining calm and effective during incidents. Strong communication and influencing skills are essential, with the confidence to constructively challenge, explain complex technical risks to a range of audiences and build effective relationships across multidisciplinary teams. You will demonstrate integrity, sound judgement and accountability, alongside a commitment to knowledge sharing, developing others and continuous improvement., * Substantial hands-on experience in cloud or platform security, including designing, implementing and operating production security controls.

  • Strong AWS security engineering experience, including multi-account governance, IAM, logging, threat detection, vulnerability management, encryption, network controls and workload hardening.
  • Experience securing cloud-native applications, APIs, containers and CI/CD pipelines, with a strong understanding of DevSecOps and shared-responsibility models.
  • Experience building or reviewing infrastructure as code and security automation using technologies such as Terraform, CloudFormation, Python, PowerShell, AWS CLI or equivalent.
  • Experience of security monitoring, investigation and incident response using SIEM, cloud-native telemetry and relevant query languages.
  • Strong knowledge of network security, encryption, key and secrets management, resilience, vulnerability management and secure configuration.
  • Experience translating security risk, policy and compliance requirements into proportionate technical controls and auditable evidence.
  • Experience providing technical leadership, coaching or developing capability within security or engineering teams.
  • Strong understanding of security governance, risk management and the application of security controls within complex technology environments., * Practical experience of Microsoft Entra ID and Microsoft cloud security, including Conditional Access, MFA, PIM, RBAC and Defender capabilities.
  • Experience within healthcare, regulated digital services or environments processing sensitive or special category data.
  • Knowledge of relevant security and regulatory frameworks, including ISO/IEC 27001, Cyber Essentials Plus, DSPT, NCSC CAF, NCSC Cloud Security Principles, NIST CSF and UK GDPR.
  • Experience with security tooling such as Datadog, Cloudflare, Rapid7, GitHub security capabilities, CSPM/CNAPP platforms or managed SOC services.
  • Experience of penetration testing, red teaming, threat modelling, MITRE ATT&CK mapping or cloud forensic investigation.
  • Understanding of service management, change control, supplier assurance, business continuity and disaster recovery.
  • Degree or equivalent practical experience in cyber security, computer science, cloud engineering or a related discipline.
  • Relevant professional certifications, such as AWS Certified Security - Specialty, AWS Solutions Architect, Microsoft security certifications, CCSP, CISSP, CISM, GIAC or Terraform Associate. Certifications are welcomed as supporting evidence but are not a substitute for current, hands-on technical capability.

Benefits & conditions

We want you to enjoy your work while feeling healthy, happy, and appreciated. That’s why we’ve created a benefits package designed with you in mind. You’ll have access to a range of wellbeing perks, including a Health Cash Plan, Well Hub Subscription, access to an Employee Assistance Programme, Annual Volunteering Day, Enhanced Sickness and Family Leave pay, Length of Service Bonus, Work from Home allowance and Pension options.

At Psychiatry UK, we care about what matters to you.

Recruitment Process

At Psychiatry UK, we are committed to creating an inclusive and accessible recruitment process. Our process includes:

· Application

· Profile review

· Screening conversation

· Competency based interview(s)

If at any point you require any reasonable adjustments -such as additional time, assistive technology, or an alternative format for materials-please let us know. We are happy to accommodate your needs to ensure you have a fair and comfortable experience.

About the company

Psychiatry UK is the UK’s leading provider of digital psychiatry services, working both privately and with the NHS to support children, teenagers and adults with expert, patient-centred care.

A career with Psychiatry UK allows you to expand your knowledge, enhance your skills, and gain valuable life experience-all while enjoying the flexibility of a remote full-time role. As part of a leading online mental health service, you’ll collaborate with innovative, forward-thinking professionals in a dynamic, multidisciplinary team committed to making a real difference.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.co.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

1:36 min

Visualizing memory limits and isolating suspicious endpoints

Dina Matveev Dina Matveev · Europe 2026 Virtual

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

6:13 min

Defining cloud proficiency by technical role

Piet Van Dongen · LIVE

Videos

See all

Related articles

See all