Senior Cloud Security Engineer

Company: HealthHero
Apply for the Senior Cloud Security Engineer
Location: London
Job Description:

Senior Cloud Security Engineer (London or Bristol)

We are HealthHero, Europe’s largest digital clinic. We are recruiting an exciting Senior Cloud Security Engineer on a 12‑month fixed‑term contract with a view to becoming permanent. The role is based in either London or Bristol, with on‑site attendance two days per week.

About the role

This role will form a fundamental part of a growing Platform Security function, covering application security, cloud security, security operations, culture and risk management. As a tech‑centric organisation, the Information Security team will embed a security‑first mindset into application development and continuous application monitoring, co‑owning the cloud security posture and tooling across HealthHero’s AWS and Azure estates with an international scope. The role focuses on infrastructure and cloud networking security posture.

DevSecOps & SDLC

  • Champion integration of security testing into CI/CD pipelines across all development teams and usage of automated security gates: SAST, DAST, dependency scanning, secrets detection
  • Enable self‑serve security tooling for development teams
  • Ability to set up development environment
  • Own cloud security posture management using Wiz (or similar CSPM)
  • Define and enforce cloud security baselines, guardrails, and policies in AWS
  • Implement and maintain IaC security scanning for Terraform
  • Manage IAM policies, network segmentation, and secrets management
  • Configure and tune SIEM (or similar) for cloud‑focused detection
  • Establish logging, monitoring, and alerting requirements based on threat modelling
  • Investigate and respond to cloud security events
  • Identify, articulate, and elevate security risks to senior leadership with mitigation plans
  • Track and remediate vulnerabilities across infrastructure
  • Manage customer initiatives related to due diligence when required
  • Support and develop annual programme of Penetration Testing and associated remediations

Stakeholder Engagement

  • Partner with internal stakeholders to support any security function requirements, particularly governance and accreditation across different countries
  • Provide expertise on emerging threats and vulnerabilities
  • Support response to customer/client due diligence requests with timely and accurate information regarding vulnerability exposure

Key Skills and Experience

  • Proven experience in application security, DevSecOps, or cloud security
  • Strong understanding of cloud networking
  • Experience securing cloud environments (AWS, Azure)
  • Ability to read and write IAC (Terraform) code, comfortable with IAC lifecycles
  • Familiarity with container security and Kubernetes
  • Understanding of secure coding, penetration testing techniques, SIEM, and vulnerability management
  • Strong technical skills relevant to Information Security such as secure coding standards, ethical hacking techniques, network security and risk analysis
  • Understanding of managing Secure Development Lifecycle and Vulnerability Management
  • Understanding and practical experience of ISO27001:2022 controls and audit processes
  • AWS Security Specialty or similar certification
  • Experience in regulated environments (healthcare, financial services)
  • Familiarity with NHS DSPT
  • Technical knowledge of GDPR and data protection requirements
  • Hands‑on CI/CD security tooling and pipeline integration
  • Interest in learning other countries health and security regulations (France / UK / IR / DE)

What we offer

  • A full induction training programme, which will be undertaken via Microsoft Teams
  • An opportunity to work as part of an experienced team that is passionate, supportive, diverse and dynamic
  • 25 days leave
  • Bank holidays and your birthday off as leave
  • Regular 1‑2‑1s with your line manager
  • 24/7 on‑call staff support
  • Health scheme and access to the Employee Assistance Programme
  • Life insurance scheme

Location: London or Bristol (requires two days per week of on‑site work).

Equality, Inclusivity and Diversity

In line with our commitment to Equality, Inclusivity and Diversity, we welcome and encourage applications from all suitably qualified candidates from all backgrounds. We are committed to supporting and promoting equality and diversity and aim to establish an inclusive working environment. As such, we welcome diverse applications from candidates irrespective of age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race (including colour, nationality, ethnic and national origin), religion or belief, sex, or sexual orientation.

We are a certified Disability Confident Employer and are committed to affording equal opportunities for candidates with disabilities or special needs. Should you require any reasonable adjustments to be made at any part of your application process, please let us know by contacting us at recruitment-team@healthhero.com

#J-18808-Ljbffr…

Posted: May 24th, 2026