Security Engineer

Bupa

Greater London

Hybrid

GBP 55,000 - 68,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

25 days holiday pro rata
Wellbeing services
Fixed term benefits allowance
Employee assistance programme
Workplace pension
Online discounts

Job summary

Bupa is seeking an experienced Security Engineer for a 12-month fixed-term contract at Cromwell Hospital, London. You will implement and refine security controls, monitor risk, and ensure compliance with NIST, ISO 27001, and CIS.

The role emphasizes collaboration with IT, HR, and compliance teams to embed security across projects and workflows. You will design and manage identity solutions (SSO, MFA, JML), maintain security policies, and drive remediation of vulnerabilities across systems while

Qualifications

  • Proven experience in a Security Engineer or similar role within enterprise/regulatory environment.
  • Hands-on experience implementing security controls per NIST, ISO 27001, and CIS standards.
  • Experience designing identity solutions (SSO, MFA, and JML).
  • Technical expertise across security technologies such as firewalls, IDS, anti-virus, authentication systems, log management, and content filtering.
  • Solid understanding of network security, segmentation, and monitoring; Windows/Linux security.
  • Experience identifying vulnerabilities and driving remediation in complex environments.
  • Ability to document security processes and procedures to a high standard.
  • CISSP/CISM or equivalent desirable.

Responsibilities

  • Support implementation, monitoring, and improvement of security frameworks aligned to NIST/ISO 27001/CIS.
  • Design, implement, and manage identity solutions (SSO/MFA/JML) with secure access.
  • Collaborate across IT, HR, compliance, and security teams to embed controls.
  • Identify and manage security risks and remediation plans across apps/infrastructure.
  • Ensure security is embedded across full project lifecycle and change processes.
  • Develop and document security policies and SOPs per best practice and regulation.
  • Monitor security posture, track risks, and report on metrics and risk appetite.
  • Coordinate security assessments and early engagement with internal SMEs.
  • Develop capabilities to detect, respond to, and manage security incidents.

Skills

Security frameworks
Identity & access
Security technologies
Network & OS security
Vulnerability management
Communication & stakeholders

Tools

Firewalls & IDS
Log management
Content filtering

Job description

Job Description

Security Engineer Salary: £55,100 - £68,000 (neg depending on experience) Location: Cromwell Hospital, London (SW5 0TU) Hybrid Working: Desired 2 days per week onsite Fixed Term Contract: 12 Months Scheduled weekly hours: 37.5 hours Benefits: Fixed Term benefits allowance

We make health happen. We are seeking an experienced Security Engineer to join Cromwell on a fixed-term contract. In this role, you will be responsible for ensuring the organisation adheres to industry security standards and best practices, including NIST, ISO 27001, and CIS controls. You will play a key role in implementing, maintaining, and continuously enhancing our security frameworks, processes, and technologies. This position is critical in safeguarding the company’s systems, data, and reputation, while also promoting a strong culture of security awareness across the business.

How you’ll help us make health happen
  • Support the implementation, monitoring, and continuous improvement of security frameworks and controls aligned to NIST, ISO 27001, and CIS standards
  • Design, implement, and manage security solutions, including SSO, MFA, and identity lifecycle processes (JML), ensuring secure and seamless user access
  • Collaborate with IT, HR, compliance, and security teams to embed and maintain security controls across systems, projects, and business workflows
  • Identify, assess, and manage security risks and vulnerabilities across applications and infrastructure, developing and driving remediation plans through to completion
  • Ensure security is embedded across the full project lifecycle, including participation in change management and design processes
  • Develop, maintain, and document security policies, procedures, and standard operating protocols in line with best practice and regulatory requirements
  • Monitor security posture, track risks, elevate overdue remediation, and ensure adherence to defined security metrics and organisational risk appetite
  • Support security assessments, pre-engagement activities, and coordination with internal SMEs and wider security teams
  • Implement and maintain capabilities for early detection, response, and management of security incidents
  • Test and assess systems and infrastructure to identify vulnerabilities and recommend improvements
  • Produce clear reporting on security posture, risk, and improvement initiatives, and represent the organisation in relevant security forums
  • Develop and implement technical solutions and tools to enhance security capability, automate processes, and protect organisational data and infrastructure
  • Promote security awareness across the organisation, providing guidance and training where required
Key Skills / Qualifications needed for this role
  • Proven experience in a Security Engineer, Application Security Engineer, or similar role within an enterprise or regulated environment
  • Strong working knowledge of security frameworks and standards, including NIST, ISO 27001, and CIS, with hands‑on experience implementing and maintaining controls
  • Practical experience designing, implementing, and managing identity and access solutions, including SSO, MFA, and joiner/mover/leaver (JML) processes
  • Solid technical expertise across security technologies such as firewalls, intrusion detection systems, anti‑virus, authentication systems, log management, and content filtering
  • Good understanding of network security, network segmentation, and monitoring tools, alongside infrastructure and operating system security (Windows/Linux)
  • Experience identifying and managing vulnerabilities, supporting remediation activities, and maintaining security systems within complex environments
  • Ability to design, document, and optimise security processes, policies, and technical procedures to a high standard
  • Strong understanding of infrastructure and application security principles, with the ability to secure enterprise environments end‑to‑end
  • Relevant professional certifications such as CISSP, CISM, or equivalent are highly desirable
  • Excellent problem solving skills with the ability to work effectively under pressure
  • Strong communication and stakeholder management skills, with the ability to translate technical security concepts into business context
Benefits

Our benefits are designed to make health happen for our people. Viva is our global wellbeing programme and includes all aspects of our health, from mental and physical, to financial, social and environmental wellbeing. We support flexible working and have a range of family friendly benefits. Joining Bupa in this role you will receive the following benefits and more:

  • 25 days holiday per year, pro rata to your contract.
  • Access to a range of services to support your physical and mental wellbeing
  • Fixed term benefits allowance
  • Access to our confidential employee assistance programme
  • Workplace pension
  • Online discounts covering your everyday shopping, entertainment, eating out and more.
Why Bupa

We’re a health insurer and provider. With no shareholders, our customers are our focus. Our people are all driven by the same purpose – helping people live longer, healthier, happier lives and making a better world. We make health happen by being brave, caring and responsible in everything we do. We encourage all our people to “Be you at Bupa”, we champion diversity, and we understand the importance of our people representing the communities and customers we serve. That’s why we especially encourage applications from people with diverse backgrounds and experiences.

Bupa is a Level 2 Disability Confident Employer. This means we aim to offer an interview/assessment to every disabled applicant who meets the minimum criteria for the role. We’ll make sure you are treated fairly and offer reasonable adjustments as part of our recruitment process to anyone that needs them.

Time Type: Full time Job Area: IT Locations: Cromwell Hospital London Be at the heart of helping people live longer healthier, happier lives and making a better world. We employ more than 80,000 people globally who are making this a reality. If you’ve got the belief, the drive and the talent to help us in our ambition then we’d like to hear from you. Wherever you work, one thing stands out about Bupa people. Our customers are our passion – they’re at the heart of our positively different culture of care. At Bupa you’ll be challenged, you’ll be encouraged to innovate, and collaborate with colleagues who are committed to delivering exceptional experiences. We trust, respect and consider everyone, knowing your difference will make the difference.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Engineer
Cyber Security Engineer

Bupa UK • Staines-upon-Thames, Manchester

Hybrid
GBP 50,000 - 70,000
25 days holiday
Bupa health insurance
Enhanced pension plan
+1
IT Service Support Manager
IT Service Support Manager

Bupa • Greater London

Hybrid
GBP 54,000 - 66,000
25 days holiday
Bupa health insurance
Enhanced pension plan
+2
Senior Data Platform Engineer
Senior Data Platform Engineer

Bupa • Staines-upon-Thames

On-site
GBP 110,000 - 140,000
Bupa health insurance
Enhanced pension plan
Annual performance bonus
+1
Helpdesk Assistant
Helpdesk Assistant

Bupa • Greater London

On-site
GBP 35,000 - 37,000
Viva wellbeing
Flexible working
Annual leave
+3
Compliance & Technical Scheduling Manager
Compliance & Technical Scheduling Manager

Bupa • Greater London

On-site
GBP 45,000 - 65,000
Annual leave accrual (paid)
Subsidised staff canteen & coffee shop
preferential rates on Bupa products
+1
Group Head of AI Security Architecture
Group Head of AI Security Architecture

BUPA • City Of London

Hybrid
GBP 150,000 - 190,000
25 days holiday
Car allowance
Management bonus
+5
Information Security and Compliance Risk Manager
Information Security and Compliance Risk Manager

Bupa • Leeds

On-site
GBP 58,000 - 70,000
10% Bonus
Information Security and Compliance Risk Manager
Information Security and Compliance Risk Manager

Bupa • Salford

On-site
GBP 54,000 - 74,000
Annual performance bonus
Private medical insurance
Generous pension contribution
+5
Senior Technical Product Manager (Health Data)
Senior Technical Product Manager (Health Data)

Bupa • Greater London

Hybrid
GBP 90,000 - 100,000
Health insurance
Pension & life insurance
Annual Health Services Bonus Scheme
+2
Head of Cyber Culture and Awareness
Head of Cyber Culture and Awareness

Cyber UK • Greater London

Hybrid
GBP 80,000 - 100,000
25 days’ holiday
Enhanced pension and life insurance
Private medical insurance
+2