HealthHero Services Ltd
Senior Cloud Security Engineer (London or Bristol) HealthHero is Europe's largest digital clinic. As a Senior Cloud Security Engineer on an initial 12 month fixed term contract, you will help shape security for our fast growing, AI driven digital healthcare platform. As the role is based in either our London or Bristol office, you will work onsite two days per week. About the role This role is a key member of the growing Platform Security team, covering application security, cloud security, security operations, culture and risk management. You will work closely with Infrastructure, Data Governance and Engineering leads, focusing on infrastructure and cloud networking to secure our AWS and Azure estates and drive cloud security with an international scope. Responsibilities DevSecOps & SDLC Champion integration of security testing into CI/CD pipelines across all development teams, using automated security gates such as SAST, DAST, dependency scanning and secrets detection. Enable self serve security tooling for development teams. Set up secure development environments. Cloud Security Own cloud security posture management using a CSPM solution (e.g., Wiz) and define enforceable cloud security baselines, guardrails, and policies in AWS. Implement and maintain IaC security scanning for Terraform. Manage IAM policies, network segmentation and secrets management. Configure and tune SIEM or similar for cloud focused detection. Establish logging, monitoring and alerting requirements based on threat modelling. Investigate and respond to cloud security events. Risk & Compliance Identify, articulate and escalates security risks to senior leadership with mitigation plans. Track and remediate vulnerabilities across the infrastructure. Manage customer due diligence initiatives when required. Support and develop an annual penetration testing programme and associated remediations. Stakeholder Engagement Partner with internal teams to support security related governance and accreditation requirements across different countries. Provide expertise on emerging threats and vulnerabilities. Support response to customer due diligence requests with timely and accurate information regarding vulnerability exposure. Qualifications Essential Proven experience in application security, DevSecOps or cloud security. Strong understanding of cloud networking. Experience securing cloud environments (AWS, Azure). Ability to read and write IaC (Terraform) code and understand IaC lifecycles. Familiarity with container security and Kubernetes. Understanding of secure coding, penetration testing techniques, SIEM and vulnerability management. Strong technical skills relevant to Information Security such as secure coding standards, ethical hacking techniques, network security and risk analysis. Experience managing secure development lifecycles and vulnerability management. Practical experience of ISO 27001:2022 controls and audit processes. Desirable AWS Security Specialty or equivalent certification. Experience in regulated environments (healthcare, financial services). Familiarity with NHS DSPT. Technical knowledge of GDPR and data protection requirements. Hands on experience with CI/CD security tooling and pipeline integration. Interest in learning other countries' health and security regulations (France, UK, IR, DE). Benefits A full induction training programme via Microsoft Teams. Opportunity to work with an experienced, diverse and supportive team. 25 days annual leave. Bank holidays and birthday off as leave. Regular one to one meetings with your line manager. 24/7 on call staff support. Auto enrolment pension scheme. Health scheme and access to an Employee Assistance Programme. Life insurance scheme. Equal Opportunity Statement HealthHero is a certified Disability Confident Employer and we are committed to offering equal opportunities to all candidates, irrespective of age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race, religion or belief, sex or sexual orientation. If you require any reasonable adjustments during the application process, please contact us.
Senior Cloud Security Engineer (London or Bristol) HealthHero is Europe's largest digital clinic. As a Senior Cloud Security Engineer on an initial 12 month fixed term contract, you will help shape security for our fast growing, AI driven digital healthcare platform. As the role is based in either our London or Bristol office, you will work onsite two days per week. About the role This role is a key member of the growing Platform Security team, covering application security, cloud security, security operations, culture and risk management. You will work closely with Infrastructure, Data Governance and Engineering leads, focusing on infrastructure and cloud networking to secure our AWS and Azure estates and drive cloud security with an international scope. Responsibilities DevSecOps & SDLC Champion integration of security testing into CI/CD pipelines across all development teams, using automated security gates such as SAST, DAST, dependency scanning and secrets detection. Enable self serve security tooling for development teams. Set up secure development environments. Cloud Security Own cloud security posture management using a CSPM solution (e.g., Wiz) and define enforceable cloud security baselines, guardrails, and policies in AWS. Implement and maintain IaC security scanning for Terraform. Manage IAM policies, network segmentation and secrets management. Configure and tune SIEM or similar for cloud focused detection. Establish logging, monitoring and alerting requirements based on threat modelling. Investigate and respond to cloud security events. Risk & Compliance Identify, articulate and escalates security risks to senior leadership with mitigation plans. Track and remediate vulnerabilities across the infrastructure. Manage customer due diligence initiatives when required. Support and develop an annual penetration testing programme and associated remediations. Stakeholder Engagement Partner with internal teams to support security related governance and accreditation requirements across different countries. Provide expertise on emerging threats and vulnerabilities. Support response to customer due diligence requests with timely and accurate information regarding vulnerability exposure. Qualifications Essential Proven experience in application security, DevSecOps or cloud security. Strong understanding of cloud networking. Experience securing cloud environments (AWS, Azure). Ability to read and write IaC (Terraform) code and understand IaC lifecycles. Familiarity with container security and Kubernetes. Understanding of secure coding, penetration testing techniques, SIEM and vulnerability management. Strong technical skills relevant to Information Security such as secure coding standards, ethical hacking techniques, network security and risk analysis. Experience managing secure development lifecycles and vulnerability management. Practical experience of ISO 27001:2022 controls and audit processes. Desirable AWS Security Specialty or equivalent certification. Experience in regulated environments (healthcare, financial services). Familiarity with NHS DSPT. Technical knowledge of GDPR and data protection requirements. Hands on experience with CI/CD security tooling and pipeline integration. Interest in learning other countries' health and security regulations (France, UK, IR, DE). Benefits A full induction training programme via Microsoft Teams. Opportunity to work with an experienced, diverse and supportive team. 25 days annual leave. Bank holidays and birthday off as leave. Regular one to one meetings with your line manager. 24/7 on call staff support. Auto enrolment pension scheme. Health scheme and access to an Employee Assistance Programme. Life insurance scheme. Equal Opportunity Statement HealthHero is a certified Disability Confident Employer and we are committed to offering equal opportunities to all candidates, irrespective of age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race, religion or belief, sex or sexual orientation. If you require any reasonable adjustments during the application process, please contact us.
HealthHero Services Ltd
Application Security Engineer (London or Bristol) We are HealthHero, Europe's largest digital clinic. Join us at a pivotal moment as we scale our digital healthcare platform across Europe - giving you the chance to shape security at the heart of a fast-growing, AI driven business. We are recruiting an exciting Application Security Engineer on an initial 12 month fixed term contract, with a view to becoming permanent - based in either our London or Bristol office two days per week. About the role You will own security across the software development lifecycle, embedding automated security testing into CI/CD pipelines and enabling development teams to ship secure code quickly. This role works closely with UK and France engineering teams. As an experienced Application Security Engineer, your working day will include but not be limited to: DevSecOps & Pipeline Security Implement and maintain security testing in GitLab CI pipelines Configure and tune SAST, DAST, dependency scanning, and secrets detection Build automated security gates that balance rigour with delivery velocity Enable self serve security tooling for development teams Contribute code and patches to security tooling and configurations Secure Development Define and enforce secure coding standards Conduct security focused code reviews and threat modelling for new features Provide remediation guidance for application vulnerabilities Train and support developers on secure coding practices Vulnerability Management Triage, patch and track application vulnerabilities through to remediation Manage dependency vulnerabilities and upgrade cycles Report on application security posture to senior leadership Risk & Compliance Embed GDPR and healthcare regulatory requirements into development processes Support DCB0129 clinical safety compliance for software changes Support customer security due diligence and audits Support ISO27001:2022 ISMS controls and audit process Key Skills and Experience Essential 3+ years in application security, DevSecOps, and secure software development Hands on experience with CI/CD security integration (GitLab CI or similar) Familiarity with SAST/DAST tooling and dependency scanning Understanding of common vulnerabilities (OWASP Top 10) and remediation Previous experience working as a back end or full stack developer Knowledge of GDPR and data protection legislation Strong communicator; able to translate security requirements for developers Desirable Development background with security focus Familiarity with SIEM platforms (Snowbit, Splunk, Sentinel) Experience with CSPM tooling (Wiz, Prisma Cloud, or similar) Penetration testing or bug bounty experience Experience in regulated environments (healthcare, financial services) Familiarity with threat modelling frameworks (STRIDE, PASTA) About us We exist to simplify healthcare and improve lives by making care feel instant, intelligent and human. HealthHero is Europe's largest digital health provider, delivering 4 million consultations per year. But we're just getting started. We've built a seamless digital clinic that brings body and mind together - from GP appointments and mental health support to long term condition management. By sitting behind the world's leading insurers and employers and supporting public health systems, we make it easier for millions of people to get the care they need, exactly when they need it. We are a high growth, capital backed business with a sophisticated scale strategy. Our team is a unique blend of digital native pioneers, management consultants, creatives and industry leading clinical experts. We aren't just digitising appointments; we're building the next generation of healthcare. We're creating an AI powered, always on ecosystem that learns from every interaction to shift the needle from reactive treatment to proactive, sustainable health. At HealthHero, we are digital when it should be and human where it counts. Join us, and help build a next generation health system the world is waiting for. We're proud to be recognised as a Great Place to Work, which reflects our commitment to creating a supportive and engaging culture. We have also been featured as the fastest growing digital healthcare company of scale in the first Sunday Times 100 Tech list. This recognition shows our impact in the digital health sector and our dedication to innovation and excellence. Committed to achieving excellence in the delivery of person centred care, we invest in people, resources and technology to continuously improve the quality of its services and organisational culture. Why us? Our values guide us, every day we strive to Simplify, Own, Aspire and Respect (SOAR). and we're rewarded when we do. What we offer A full induction training programme, which will be undertaken via Microsoft Teams. An opportunity to work as part of an experienced team who are passionate in their field, supportive, diverse and dynamic. 25 days leave. Bank Holidays and your birthday off as leave. Regular 1 2 1s with your line Manager. 24/7 on call staff support. Auto enrolment pension scheme. Health Scheme and access to our Employee Assistance Programme. Life Insurance Scheme. Apply If you are interested in making a difference and believe this role is a good fit for you, we would love to hear from you. If you have any questions, please contact our Recruitment Team at Hybrid: London or Bristol (There is a requirement to work in the office for a minimum of two days per week) Closing date for applications: Friday 29 May (5pm) Additional information We reserve the right to close this job in the event we receive a sufficient number of applications. Please note that we are unfortunately unable to offer a sponsor licence to candidates who require sponsorship from their employer. Equality, Inclusivity and Diversity In line with our commitment to Equality, Inclusivity and Diversity, we welcome and encourage applications from all suitably qualified candidates from all backgrounds. We are committed to supporting and promoting equality and diversity and aim to establish an inclusive working environment. As such, we welcome diverse applications from candidates irrespective of age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race (including colour, nationality, ethnic and national origin), religion or belief, sex, or sexual orientation. We are a certified Disability Confident Employer and is committed to affording equal opportunities for candidates with disabilities or special needs. Should you require any reasonable adjustments to be made at any part of your application process, please let us know by contacting us at Safeguarding Please see for information relating to our commitment to safeguarding.
Application Security Engineer (London or Bristol) We are HealthHero, Europe's largest digital clinic. Join us at a pivotal moment as we scale our digital healthcare platform across Europe - giving you the chance to shape security at the heart of a fast-growing, AI driven business. We are recruiting an exciting Application Security Engineer on an initial 12 month fixed term contract, with a view to becoming permanent - based in either our London or Bristol office two days per week. About the role You will own security across the software development lifecycle, embedding automated security testing into CI/CD pipelines and enabling development teams to ship secure code quickly. This role works closely with UK and France engineering teams. As an experienced Application Security Engineer, your working day will include but not be limited to: DevSecOps & Pipeline Security Implement and maintain security testing in GitLab CI pipelines Configure and tune SAST, DAST, dependency scanning, and secrets detection Build automated security gates that balance rigour with delivery velocity Enable self serve security tooling for development teams Contribute code and patches to security tooling and configurations Secure Development Define and enforce secure coding standards Conduct security focused code reviews and threat modelling for new features Provide remediation guidance for application vulnerabilities Train and support developers on secure coding practices Vulnerability Management Triage, patch and track application vulnerabilities through to remediation Manage dependency vulnerabilities and upgrade cycles Report on application security posture to senior leadership Risk & Compliance Embed GDPR and healthcare regulatory requirements into development processes Support DCB0129 clinical safety compliance for software changes Support customer security due diligence and audits Support ISO27001:2022 ISMS controls and audit process Key Skills and Experience Essential 3+ years in application security, DevSecOps, and secure software development Hands on experience with CI/CD security integration (GitLab CI or similar) Familiarity with SAST/DAST tooling and dependency scanning Understanding of common vulnerabilities (OWASP Top 10) and remediation Previous experience working as a back end or full stack developer Knowledge of GDPR and data protection legislation Strong communicator; able to translate security requirements for developers Desirable Development background with security focus Familiarity with SIEM platforms (Snowbit, Splunk, Sentinel) Experience with CSPM tooling (Wiz, Prisma Cloud, or similar) Penetration testing or bug bounty experience Experience in regulated environments (healthcare, financial services) Familiarity with threat modelling frameworks (STRIDE, PASTA) About us We exist to simplify healthcare and improve lives by making care feel instant, intelligent and human. HealthHero is Europe's largest digital health provider, delivering 4 million consultations per year. But we're just getting started. We've built a seamless digital clinic that brings body and mind together - from GP appointments and mental health support to long term condition management. By sitting behind the world's leading insurers and employers and supporting public health systems, we make it easier for millions of people to get the care they need, exactly when they need it. We are a high growth, capital backed business with a sophisticated scale strategy. Our team is a unique blend of digital native pioneers, management consultants, creatives and industry leading clinical experts. We aren't just digitising appointments; we're building the next generation of healthcare. We're creating an AI powered, always on ecosystem that learns from every interaction to shift the needle from reactive treatment to proactive, sustainable health. At HealthHero, we are digital when it should be and human where it counts. Join us, and help build a next generation health system the world is waiting for. We're proud to be recognised as a Great Place to Work, which reflects our commitment to creating a supportive and engaging culture. We have also been featured as the fastest growing digital healthcare company of scale in the first Sunday Times 100 Tech list. This recognition shows our impact in the digital health sector and our dedication to innovation and excellence. Committed to achieving excellence in the delivery of person centred care, we invest in people, resources and technology to continuously improve the quality of its services and organisational culture. Why us? Our values guide us, every day we strive to Simplify, Own, Aspire and Respect (SOAR). and we're rewarded when we do. What we offer A full induction training programme, which will be undertaken via Microsoft Teams. An opportunity to work as part of an experienced team who are passionate in their field, supportive, diverse and dynamic. 25 days leave. Bank Holidays and your birthday off as leave. Regular 1 2 1s with your line Manager. 24/7 on call staff support. Auto enrolment pension scheme. Health Scheme and access to our Employee Assistance Programme. Life Insurance Scheme. Apply If you are interested in making a difference and believe this role is a good fit for you, we would love to hear from you. If you have any questions, please contact our Recruitment Team at Hybrid: London or Bristol (There is a requirement to work in the office for a minimum of two days per week) Closing date for applications: Friday 29 May (5pm) Additional information We reserve the right to close this job in the event we receive a sufficient number of applications. Please note that we are unfortunately unable to offer a sponsor licence to candidates who require sponsorship from their employer. Equality, Inclusivity and Diversity In line with our commitment to Equality, Inclusivity and Diversity, we welcome and encourage applications from all suitably qualified candidates from all backgrounds. We are committed to supporting and promoting equality and diversity and aim to establish an inclusive working environment. As such, we welcome diverse applications from candidates irrespective of age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race (including colour, nationality, ethnic and national origin), religion or belief, sex, or sexual orientation. We are a certified Disability Confident Employer and is committed to affording equal opportunities for candidates with disabilities or special needs. Should you require any reasonable adjustments to be made at any part of your application process, please let us know by contacting us at Safeguarding Please see for information relating to our commitment to safeguarding.