Senior Security Cloud Engineer

Health Hero
W1T1Af, W1T 1AF, United Kingdom
5 days ago
Job Type
Contract
Work Location
Hybrid
Seniority
Senior
Education
Degree
Posted
26 May 2026 (5 days ago)

Senior Cloud Security Engineer (London or Bristol)

We are HealthHero, Europe’s largest digital clinic. Join us at a pivotal moment as we scale our digital healthcare platform across Europe — giving you the chance to shape security at the heart of a fast-growing, AI-driven business. We are recruiting an exciting Senior Cloud Security Engineer on an initial 12 month fixed term contract, with a view to becoming permanent – based in either our London or Bristol office two days per week.

About the role

This role will form a fundamental part of a growing PlatformSecurity function, where the team covers application security, cloud security, security operations, culture and risk management. As a tech-centric organisation the Information Security team will play a critical part in embedding a security-first mindset into application development and continuous application monitoring. This role will co-own the cloud security posture and tooling across HealthHero’s AWS and Azure estates and have the opportunity to tackle cloud security with an international scope. The role will be supported by a multidisciplinary force of Infrastructure, Data Governance and Engineering team leads with a security focus as part of their remit. The role has a focus on infrastructure and cloud networking when it comes to security posture.

As an experienced Cloud Security Engineer, your working day will include but not be limited to:

DevSecOps & SDLC

  • Champion integration of security testing into CI/CD pipelines across all development teams and usage of automated security gates: SAST, DAST, dependency scanning, secrets detection
  • Enable self-serve security tooling for development teams
  • Ability to set up development environment

Cloud Security

  • Own cloud security posture management using Wiz (or similar CSPM) Define and enforce cloud security baselines, guardrails, and policies in AWS
  • Implement and maintain IaC security scanning for Terraform
  • Manage IAM policies, network segmentation, and secrets management
  • Configure and tune SIEM (or similar) for cloud-focused detection
  • Establish logging, monitoring, and alerting requirements based on threat modelling
  • Investigate and respond to cloud security events

Risk & Compliance

  • Identify, articulate, and escalate security risks to senior leadership with mitigation plans
  • Track and remediate vulnerabilities across infrastructure
  • Manage customer initiatives related to due diligence when required to
  • Support and develop annual programme of Penetration Testing and associated remediations

Stakeholder Engagement

  • Partner with internal and stakeholder management to support any requirements from the security function - particularly governance and accreditation requirements across different countries
  • Provide expertise on emerging threats and vulnerabilities
  • Support response to customer/client due diligence requests with timely and accurate information regarding vulnerability exposure

Key Skills and Experience

Essential

  • Proven experience in application security, DevSecOps, or cloud security
  • Strong understanding of cloud networking
  • Experience securing cloud environments (AWS, Azure)
  • Ability to read and write IAC (Terraform) code, comfortable with IAC lifecycles
  • Familiarity with container security and Kubernetes
  • Understanding of secure coding, penetration testing techniques, SIEM, and vulnerability management
  • Strong technical skills relevant to Information Security such as secure coding standards, ethical hacking techniques, network security and risk analysis
  • Understanding of managing Secure Development Lifecycle and Vulnerability Management.
  • Understanding and practical experience of ISO27001:2022 controls and audit processes

Desirable

  • AWS Security Specialty or similar certification
  • Experience in regulated environments (healthcare, financial services)
  • Familiarity with NHS DSPT
  • Technical knowledge of GDPR and data protection requirements
  • Hands-on with CI/CD security tooling and pipeline integration
  • Interest in learning other countries health and security regulations (France / UK / IR / DE)

About us

We exist to simplify healthcare and improve lives by making care feel instant, intelligent and human.

HealthHero is Europe’s largest digital health provider, delivering 4 million consultations per year. But we’re just getting started. We’ve built a seamless digital clinic that brings body and mind together — from GP appointments and mental health support to long-term condition management. By sitting behind the world’s leading insurers and employers and supporting public health systems, we make it easier for millions of people to get the care they need, exactly when they need it.

We are a high-growth, capital-backed business with a sophisticated scale strategy. Our team is a unique blend of those with strong digital experience, management consultants, creatives and industry-leading clinical experts.

We aren’t just digitising appointments; we’re building the next generation of healthcare. We’re creating an AI-powered, always-on ecosystem that learns from every interaction to shift the needle from reactive treatment to proactive, sustainable health. At HealthHero, we are digital when it should be and human where it counts.

Join us, and help build a next generation health system the world is waiting for.

We’re proud to be recognised as a which reflects our commitment to creating a supportive and engaging culture. We have also been featured as the fastest growing digital healthcare company of scale in the first Sunday Times 100 Tech list. This recognition shows our impact in the digital health sector and our dedication to innovation and excellence. Committed to achieving excellence in the delivery of person-centred care, we invest in people, resources and technology to continuously improve the quality of its services and organisational culture.

Related Jobs

View all jobs
Spotlight

Lead Development Engineer

Corin Group Cirencester, gloucestershire, United Kingdom
On-site

Agentic Software Engineer

Adria Solutions Sheffield, United Kingdom
£60,000 – £70,000 pa Hybrid

Agentic Software Engineer

Adria Solutions Newcastle upon Tyne, United Kingdom
£60,000 – £70,000 pa Hybrid

Application Security Engineer

Health Hero W1T1Af, W1T 1AF, United Kingdom
Hybrid

Director, MedTech Surgery Data Analytics & AI

Johnson & Johnson MedTech High Wycombe, United Kingdom
On-site

Product Manager (AI / Workflow) - Near Edinburgh

Lorien Stockbridge, City Of Edinburgh, Edinburgh, United Kingdom
£80,000 – £90,000 pa Hybrid

Product Manager (AI / Workflow) - Near Edinburgh

SRG Eh24Qz, Alba / Scotland, EH2 4QZ, United Kingdom
£80,000 – £90,000 pa Hybrid

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Where to Advertise Medical Technology Jobs in the UK (2026 Guide)

Where to advertise medical technology jobs UK in 2026: the specialist boards and MDR/IEC 62304-aware channels that reach biomedical and medtech talent. The medtech candidate pool spans biomedical engineers, regulatory affairs specialists, clinical scientists, software engineers working within IEC 62304 and MDR frameworks, imaging scientists and commercial professionals with deep healthcare sector knowledge. General job boards consistently conflate medical technology with broader healthcare, pharmaceutical and IT roles — producing high application volumes but low candidate quality for specialist medtech positions. This guide, published by MedicalTechnologyJobs.co.uk, covers where to advertise medical technology roles in the UK in 2026, how the main platforms compare, what employers should expect to pay, and what the data says about hiring across different role types.

Medical Technology Jobs UK 2026: What to Expect Over the Next 3 Years

Medical Technology Jobs UK 2026: roles, salaries and the trends shaping UK medtech hiring over the next three years — devices, diagnostics and digital health. Medical technology is one of those rare sectors where commercial ambition and genuine human impact point in exactly the same direction. The devices, diagnostics, digital health platforms, and AI-powered clinical tools that medical technology companies develop do not just generate revenue — they extend lives, reduce suffering, and change what is possible inside the clinical encounter. That combination of purpose and commercial scale makes the medical technology jobs market one of the most compelling in the entire UK life sciences and technology landscape. And that market is changing faster than at any previous point in the sector's history. The integration of artificial intelligence into diagnostic imaging, pathology, and clinical decision support has moved from research demonstration to regulatory approval and NHS deployment. Wearable and implantable devices are generating continuous patient data at a scale that is transforming how chronic conditions are monitored and managed. Digital therapeutics — software that delivers clinically validated therapeutic interventions — have emerged as a recognised product category with its own regulatory pathway. Surgical robotics has moved from a premium offering at a handful of specialist centres to a mainstream surgical platform whose capabilities are expanding with each generation. For job seekers, the medical technology jobs market of 2026 represents an opportunity that is both broader and more technically demanding than it was three years ago. The roles being created now span a wider range of disciplines, require a more sophisticated understanding of the intersection between technology and clinical practice, and carry higher regulatory expectations than the medtech jobs of even a short time ago. This article breaks down what the UK medical technology jobs market is likely to look like through to 2028 — covering the titles emerging right now, the technologies driving employer demand, the skills that will matter most, and how to position your career ahead of the curve in one of the most consequential sectors in the UK economy.