Job Search and Career Advice Platform

Enable job alerts via email!

SecOps Engineer

Skin Analytics

Greater London

Hybrid

GBP 80,000 - 100,000

Full time

Today
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A healthcare software company based in London is seeking a DevOps Engineer to lead security initiatives and the development of CI/CD pipelines for regulated clinical software. The role requires in-office presence three days a week. The ideal candidate will have extensive AWS expertise, experience with CI/CD tooling, and deep knowledge of security practices essential for Software as a Medical Device. Candidates passionate about automation and security in healthcare are encouraged to apply.

Benefits

Competitive salary
Share options package
Private healthcare
25 days annual leave
Enhanced parental leave
Bike to work scheme
Training budget
Social activities including company offsite

Qualifications

  • Deep expertise in AWS services such as EC2, S3, RDS, IAM, and VPC.
  • Experience with CI / CD tooling and gated deployments.
  • Proficiency in security tooling, including Snyk and SonarQube.
  • Experience in coordinating pen testing and vulnerability management.
  • Knowledge of Terraform and Ansible for infrastructure as code.
  • Strong understanding of the ELK stack and SIEM solutions.
  • Familiarity with compliance standards relevant to medical software.
  • Depth in networking principles and security measures.

Responsibilities

  • Lead AWS infrastructure security initiatives.
  • Build and maintain secure CI / CD pipelines.
  • Coordinate penetration testing efforts.
  • Deploy runtime threat detection systems.
  • Manage secrets detection and scanning.
  • Implement observability with the ELK stack.

Skills

AWS (EC2, S3, RDS, IAM, VPC, CloudTrail, GuardDuty, Lambda)
CI / CD (Bitbucket Pipelines or similar)
Security tooling (Snyk, SonarQube, OWASP ZAP, Burp Suite)
Pen testing coordination
Terraform
Ansible
Docker
ELK stack / SIEM
Compliance (IEC 62304, ISO 27001, HIPAA, MDR)
Networking (VPCs, security groups, NACLs, load balancers)
Job description

In this role you will lead the charge in securing and scaling our infrastructure and CI / CD pipelines for regulated clinical software. Working cross-functionally with engineering, QA, product, and regulatory teams, you’ll design, implement, and monitor secure, traceable DevOps workflows. You enable rapid, compliant delivery of Software as a Medical Device (SaMD) products.

Please note: this role requires in office presence for 3 days a week . Our office is in Farringdon, London. If you can't commit to this, please don't apply.

Responsibilities
  • Own AWS infrastructure security using least-privilege and zero-trust principles
  • Build and maintain secure CI / CD pipelines with automated security gates (Snyk, SonarQube, OWASP ZAP)
  • Conduct and coordinate penetration testing (internal and third-party); triage and drive remediation
  • Deploy runtime threat detection (GuardDuty, Falco, Wazuh)
  • Manage secrets detection and scanning (GitLeaks, Vault)
  • Build observability with ELK stack, Elastic agents, and anomaly alerting
What success looks like
3 months
  • Deploy SAST tooling (SonarQube) across all repositories with automated PR scanning
  • Implement DAST scanning (OWASP ZAP) for staging environments with scheduled scans
  • Deploy secrets detection tooling (e.g., GitLeaks, TruffleHog) across all repositories
  • Establish a baseline security posture through initial penetration test; document and prioritise remediation backlog
6 months
  • Complete remediation of all critical / high findings from initial pen test
  • Achieve automated security gate coverage (SAST, DAST, dependency scanning) across 100% of production services
12 months
  • Implement full-stack observability using the ELK stack with Elastic agents deployed across all infrastructure for centralised security and performance monitoring
  • Configure anomaly detection dashboards and real-time alerting for security events and reliability metrics
  • Establish cadence of quarterly pen tests with trend reporting to leadership
Requirements
Have deep expertise in:
  • AWS (EC2, S3, RDS, IAM, VPC, CloudTrail, GuardDuty, Lambda)
  • CI / CD (Bitbucket Pipelines or similar), gated deployments
  • Security tooling : Snyk, SonarQube, OWASP ZAP, Burp Suite, Kali Linux
  • Pen testing coordination and vulnerability management
  • Terraform, Ansible, Docker
  • ELK stack / SIEM
  • Compliance : IEC 62304, ISO 27001, HIPAA, MDR
  • Strong networking : VPCs, security groups, NACLs, load balancers
Behaviours required
  • Takes ownership : full accountability for infra, tooling, and controls; sees it through to completion.
  • Bias for automation : believes manual work should be temporary, builds repeatable pipelines and workflows.
  • Detail obsessed : doesn't miss the small stuff. Every commit, config, and policy matters in regulated software.
  • Clear communicator : explains risks, trade-offs, and technical plans to both engineers and non-tech stakeholders.
  • Collaborative & pragmatic : works well across disciplines and adapts to real-world constraints.
Benefits

💰Competitive salary

Share options package - all our employees have ownership in the company

🏥Private healthcare

🌴25 days annual leave (5 day company shutdown in August + bank holidays)

👪Enhanced parental leave - includes adoption & foster

🚲 Bike to work scheme

Training budget

Weekly catch-ups, monthly meetings to talk about you, your ambitions and make plans

🎊Lots of fun social activities including company offsite!

Our Values

🌱 Building a Strong Foundation

🎓 Always Learning

🏅 Lead from the Front

💪 Tough and Resilient

The Real Stuff

Skin Analytics embraces and is committed to diversity and equal opportunities. We are dedicated to building a team that represents a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better our work will be.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.