DescriptionSenior Cloud Security Engineer (London or Bristol)
We are HealthHero Europes largest digital clinic. Join us at a pivotal moment as we scale our digital healthcare platform across Europe giving you the chance to shape security at the heart of a fast-growing AI-driven business. We are recruiting an exciting Senior Cloud Security Engineer on an initial 12 month fixed term contract with a view to becoming permanent based in either our London or Bristol office two days per week.
About the role
This role will form a fundamental part of a growing PlatformSecurity function where the team covers application security cloud security security operations culture and risk management. As a tech-centric organisation the Information Security team will play a critical part in embedding a security-first mindset into application development and continuous application monitoring. This role will co-own the cloud security posture and tooling across HealthHeros AWS and Azure estates and have the opportunity to tackle cloud security with an international scope. The role will be supported by a multidisciplinary force of Infrastructure Data Governance and Engineering team leads with a security focus as part of their remit. The role has a focus on infrastructure and cloud networking when it comes to security posture.
As an experienced Cloud Security Engineer your working day will include but not be limited to:
DevSecOps & SDLC
- Champion integration of security testing into CI/CD pipelines across all development teams and usage of automated security gates: SAST DAST dependency scanning secrets detection
- Enable self-serve security tooling for development teams
- Ability to set up development environment
Cloud Security
- Own cloud security posture management using Wiz (or similar CSPM) Define and enforce cloud security baselines guardrails and policies in AWS
- Implement and maintain IaC security scanning for Terraform
- Manage IAM policies network segmentation and secrets management
- Configure and tune SIEM (or similar) for cloud-focused detection
- Establish logging monitoring and alerting requirements based on threat modelling
- Investigate and respond to cloud security events
Risk & Compliance
- Identify articulate and escalate security risks to senior leadership with mitigation plans
- Track and remediate vulnerabilities across infrastructure
- Manage customer initiatives related to due diligence when required to
- Support and develop annual programme of Penetration Testing and associated remediations
Stakeholder Engagement
- Partner with internal and stakeholder management to support any requirements from the security function - particularly governance and accreditation requirements across different countries
- Provide expertise on emerging threats and vulnerabilities
- Support response to customer/client due diligence requests with timely and accurate information regarding vulnerability exposure
Key Skills and Experience
Essential
- Proven experience in application security DevSecOps or cloud security
- Strong understanding of cloud networking
- Experience securing cloud environments (AWS Azure)
- Ability to read and write IAC (Terraform) code comfortable with IAC lifecycles
- Familiarity with container security and Kubernetes
- Understanding of secure coding penetration testing techniques SIEM and vulnerability management
- Strong technical skills relevant to Information Security such as secure coding standards ethical hacking techniques network security and risk analysis
- Understanding of managing Secure Development Lifecycle and Vulnerability Management.
- Understanding and practical experience of ISO27001:2022 controls and audit processes
Desirable
- AWS Security Specialty or similar certification
- Experience in regulated environments (healthcare financial services)
- Familiarity with NHS DSPT
- Technical knowledge of GDPR and data protection requirements
- Hands-on with CI/CD security tooling and pipeline integration
- Interest in learning other countries health and security regulations (France / UK / IR / DE)
About us
We exist to simplify healthcare and improve lives by making care feel instant intelligent and human.
HealthHero is Europes largest digital health provider delivering 4 million consultations per year. But were just getting started. Weve built a seamless digital clinic that brings body and mind together from GP appointments and mental health support to long-term condition management. By sitting behind the worlds leading insurers and employers and supporting public health systems we make it easier for millions of people to get the care they need exactly when they need it.
We are a high-growth capital-backed business with a sophisticated scale strategy. Our team is a unique blend of digital-native pioneers management consultants creatives and industry-leading clinical experts.
We arent just digitising appointments; were building the next generation of healthcare. Were creating an AI-powered always-on ecosystem that learns from every interaction to shift the needle from reactive treatment to proactive sustainable health. At HealthHero we are digital when it should be and human where it counts.
Join us and help build a next generation health system the world is waiting for.
Were proud to be recognised as aGreat Place to Workwhich reflects our commitment to creating a supportive and engaging culture. We have also been featured as the fastest growing digital healthcare company of scale in the first Sunday Times 100 Tech list. This recognition shows our impact in the digital health sector and our dedication to innovation and excellence. Committed to achieving excellence in the delivery of person-centred care we invest in people resources and technology to continuously improve the quality of its services and organisational culture.
Why us
Our values guide us every day we strive toSimplify Own Aspire and Respect (SOAR)
and were rewarded when we do.
What we offer
- A full induction training programme which will be undertaken via Microsoft Teams.
- An opportunity to work as part of an experienced team who are passionate in their field supportive diverse and dynamic.
- 25 days leave.
- Bank Holidays and your birthday off as leave.
- Regular 1-2-1s with your line Manager.
- 24/7 on-call staff support.
- Auto-enrolment pension scheme.
- Health Scheme and access to our Employee Assistance Programme.
- Life Insurance Scheme.
Apply
If you are interested in making a difference and believe this role is a good fit for you we would love to hear from you. If you have any questions please contact our Recruitment Team at
Hybrid:London or Bristol (There is a requirement to work in the office for a minimum of two days per week)
Closing date for applications: Friday 29 May (5pm)
Additional information
*We reserve the right to close this job in the event we receive a sufficient number of applications.
**Please note that we are unfortunately unable to offer a sponsor licence to candidates who require sponsorship from their employer.
Equality Inclusivity and Diversity
In line with our commitment to Equality Inclusivity and Diversity we welcome and encourage applications from all suitably qualified candidates from all backgrounds. We are committed to supporting and promoting equality and diversity and aim to establish an inclusive working environment. As such we welcome diverse applications from candidates irrespective of age disability gender reassignment marriage and civil partnership pregnancy and maternity race (including colour nationality ethnic and national origin) religion or belief sex or sexual orientation.
We are a certified Disability Confident Employer and is committed to affording equal opportunities for candidates with disabilities or special needs. Should you require any reasonable adjustments to be made at any part of your application process please let us know by contacting us at
Safeguarding
Please seeherefor information relating to our commitment to safeguarding.
Required Experience:
Senior IC
DescriptionSenior Cloud Security Engineer (London or Bristol)We are HealthHero Europes largest digital clinic. Join us at a pivotal moment as we scale our digital healthcare platform across Europe giving you the chance to shape security at the heart of a fast-growing AI-driven business. We are recr...
DescriptionSenior Cloud Security Engineer (London or Bristol)
We are HealthHero Europes largest digital clinic. Join us at a pivotal moment as we scale our digital healthcare platform across Europe giving you the chance to shape security at the heart of a fast-growing AI-driven business. We are recruiting an exciting Senior Cloud Security Engineer on an initial 12 month fixed term contract with a view to becoming permanent based in either our London or Bristol office two days per week.
About the role
This role will form a fundamental part of a growing PlatformSecurity function where the team covers application security cloud security security operations culture and risk management. As a tech-centric organisation the Information Security team will play a critical part in embedding a security-first mindset into application development and continuous application monitoring. This role will co-own the cloud security posture and tooling across HealthHeros AWS and Azure estates and have the opportunity to tackle cloud security with an international scope. The role will be supported by a multidisciplinary force of Infrastructure Data Governance and Engineering team leads with a security focus as part of their remit. The role has a focus on infrastructure and cloud networking when it comes to security posture.
As an experienced Cloud Security Engineer your working day will include but not be limited to:
DevSecOps & SDLC
- Champion integration of security testing into CI/CD pipelines across all development teams and usage of automated security gates: SAST DAST dependency scanning secrets detection
- Enable self-serve security tooling for development teams
- Ability to set up development environment
Cloud Security
- Own cloud security posture management using Wiz (or similar CSPM) Define and enforce cloud security baselines guardrails and policies in AWS
- Implement and maintain IaC security scanning for Terraform
- Manage IAM policies network segmentation and secrets management
- Configure and tune SIEM (or similar) for cloud-focused detection
- Establish logging monitoring and alerting requirements based on threat modelling
- Investigate and respond to cloud security events
Risk & Compliance
- Identify articulate and escalate security risks to senior leadership with mitigation plans
- Track and remediate vulnerabilities across infrastructure
- Manage customer initiatives related to due diligence when required to
- Support and develop annual programme of Penetration Testing and associated remediations
Stakeholder Engagement
- Partner with internal and stakeholder management to support any requirements from the security function - particularly governance and accreditation requirements across different countries
- Provide expertise on emerging threats and vulnerabilities
- Support response to customer/client due diligence requests with timely and accurate information regarding vulnerability exposure
Key Skills and Experience
Essential
- Proven experience in application security DevSecOps or cloud security
- Strong understanding of cloud networking
- Experience securing cloud environments (AWS Azure)
- Ability to read and write IAC (Terraform) code comfortable with IAC lifecycles
- Familiarity with container security and Kubernetes
- Understanding of secure coding penetration testing techniques SIEM and vulnerability management
- Strong technical skills relevant to Information Security such as secure coding standards ethical hacking techniques network security and risk analysis
- Understanding of managing Secure Development Lifecycle and Vulnerability Management.
- Understanding and practical experience of ISO27001:2022 controls and audit processes
Desirable
- AWS Security Specialty or similar certification
- Experience in regulated environments (healthcare financial services)
- Familiarity with NHS DSPT
- Technical knowledge of GDPR and data protection requirements
- Hands-on with CI/CD security tooling and pipeline integration
- Interest in learning other countries health and security regulations (France / UK / IR / DE)
About us
We exist to simplify healthcare and improve lives by making care feel instant intelligent and human.
HealthHero is Europes largest digital health provider delivering 4 million consultations per year. But were just getting started. Weve built a seamless digital clinic that brings body and mind together from GP appointments and mental health support to long-term condition management. By sitting behind the worlds leading insurers and employers and supporting public health systems we make it easier for millions of people to get the care they need exactly when they need it.
We are a high-growth capital-backed business with a sophisticated scale strategy. Our team is a unique blend of digital-native pioneers management consultants creatives and industry-leading clinical experts.
We arent just digitising appointments; were building the next generation of healthcare. Were creating an AI-powered always-on ecosystem that learns from every interaction to shift the needle from reactive treatment to proactive sustainable health. At HealthHero we are digital when it should be and human where it counts.
Join us and help build a next generation health system the world is waiting for.
Were proud to be recognised as aGreat Place to Workwhich reflects our commitment to creating a supportive and engaging culture. We have also been featured as the fastest growing digital healthcare company of scale in the first Sunday Times 100 Tech list. This recognition shows our impact in the digital health sector and our dedication to innovation and excellence. Committed to achieving excellence in the delivery of person-centred care we invest in people resources and technology to continuously improve the quality of its services and organisational culture.
Why us
Our values guide us every day we strive toSimplify Own Aspire and Respect (SOAR)
and were rewarded when we do.
What we offer
- A full induction training programme which will be undertaken via Microsoft Teams.
- An opportunity to work as part of an experienced team who are passionate in their field supportive diverse and dynamic.
- 25 days leave.
- Bank Holidays and your birthday off as leave.
- Regular 1-2-1s with your line Manager.
- 24/7 on-call staff support.
- Auto-enrolment pension scheme.
- Health Scheme and access to our Employee Assistance Programme.
- Life Insurance Scheme.
Apply
If you are interested in making a difference and believe this role is a good fit for you we would love to hear from you. If you have any questions please contact our Recruitment Team at
Hybrid:London or Bristol (There is a requirement to work in the office for a minimum of two days per week)
Closing date for applications: Friday 29 May (5pm)
Additional information
*We reserve the right to close this job in the event we receive a sufficient number of applications.
**Please note that we are unfortunately unable to offer a sponsor licence to candidates who require sponsorship from their employer.
Equality Inclusivity and Diversity
In line with our commitment to Equality Inclusivity and Diversity we welcome and encourage applications from all suitably qualified candidates from all backgrounds. We are committed to supporting and promoting equality and diversity and aim to establish an inclusive working environment. As such we welcome diverse applications from candidates irrespective of age disability gender reassignment marriage and civil partnership pregnancy and maternity race (including colour nationality ethnic and national origin) religion or belief sex or sexual orientation.
We are a certified Disability Confident Employer and is committed to affording equal opportunities for candidates with disabilities or special needs. Should you require any reasonable adjustments to be made at any part of your application process please let us know by contacting us at
Safeguarding
Please seeherefor information relating to our commitment to safeguarding.
Required Experience:
Senior IC
View more
View less