×
Register Here to Apply for Jobs or Post Jobs. X

Senior Cloud Security Engineer

Job in Greater London, London, Greater London, W1B, England, UK
Listing for: HealthHero
Contract position
Listed on 2026-07-02
Job specializations:
  • IT/Tech
    Cybersecurity, Cloud Computing: Infrastructure & Operations, Information Security, Security Manager
Salary/Wage Range or Industry Benchmark: 60000 - 80000 GBP Yearly GBP 60000.00 80000.00 YEAR
Job Description & How to Apply Below
Location: Greater London

Senior Cloud Security Engineer (London or Bristol)

We are Health Hero, Europe’s largest digital clinic. Join us at a pivotal moment as we scale our digital healthcare platform across Europe — giving you the chance to shape security at the heart of a fast‑growing, AI‑driven business. We are recruiting an exciting Senior Cloud Security Engineer on an initial 12 month fixed term contract, with a view to becoming permanent – based in either our London or Bristol office two days per week.

About

the role

This role will form a fundamental part of a growing Platform Security function, where the team covers application security, cloud security, security operations, culture and risk management. As a tech‑centric organisation the Information Security team will play a critical part in embedding a security‑first mindset into application development and continuous application monitoring. This role will co‑own the cloud security posture and tooling across Health Hero’s AWS and Azure estates and have the opportunity to tackle cloud security with an international scope.

The role will be supported by a multidisciplinary force of Infrastructure, Data Governance and Engineering team leads with a security focus as part of their remit. The role has a focus on infrastructure and cloud networking when it comes to security posture.

As an experienced Cloud Security Engineer, your working day will include but not be limited to:

Dev Sec Ops  & SDLC
  • Champion integration of security testing into CI/CD pipelines across all development teams and usage of automated security gates: SAST, DAST, dependency scanning, secrets detection
  • Enable self‑serve security tooling for development teams
  • Ability to set up development environment
  • Own cloud security posture management using Wiz (or similar CSPM)
  • Define and enforce cloud security baselines, guardrails, and policies in AWS
  • Implement and maintain IaC security scanning for Terraform
  • Manage IAM policies, network segmentation, and secrets management
  • Configure and tune SIEM (or similar) for cloud‑focused detection
  • Establish logging, monitoring, and alerting requirements based on threat modelling
  • Investigate and respond to cloud security events
  • Identify, articulate, and elevate security risks to senior leadership with mitigation plans
  • Track and remediate vulnerabilities across infrastructure
  • Manage customer initiatives related to due diligence when required to
  • Support and develop annual programme of Penetration Testing and associated remediations
Stakeholder Engagement
  • Partner with internal and stakeholder management to support any requirements from the security function – particularly governance and accreditation requirements across different countries
  • Provide expertise on emerging threats and vulnerabilities
  • Support response to customer/client due diligence requests with timely and accurate information regarding vulnerability exposure
Key Skills and Experience
  • Proven experience in application security, Dev Sec Ops , or cloud security
  • Strong understanding of cloud networking
  • Experience securing cloud environments (AWS, Azure)
  • Ability to read and write IAC (Terraform) code, comfortable with IAC life cycles
  • Familiarity with container security and Kubernetes
  • Understanding of secure coding, penetration testing techniques, SIEM, and vulnerability management
  • Strong technical skills relevant to Information Security such as secure coding standards, ethical hacking techniques, network security and risk analysis
  • Understanding of managing Secure Development Lifecycle and Vulnerability Management.
  • Understanding and practical experience of ISO
    27001:2022 controls and audit processes
  • AWS Security Specialty or similar certification
  • Experience in regulated environments (healthcare, financial services)
  • Familiarity with NHS DSPT
  • Technical knowledge of GDPR and data protection requirements
  • Hands‑on with CI/CD security tooling and pipeline integration
  • Interest in learning other countries health and security regulations (France / UK / IR / DE)
About us

We exist to simplify healthcare and improve lives by making care feel instant, intelligent and human.

Health Hero is Europe’s largest digital health provider, delivering 4 million consultations…

Position Requirements
10+ Years work experience
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary