Senior Cloud Security Engineer

Company: Vitality
Apply for the Senior Cloud Security Engineer
Location: Bournemouth
Job Description:

Overview

Senior Cloud Security Engineer at Vitality, responsible for safeguarding technology and member data through expert guidance and hands-on security work. You will collaborate with cross-functional teams to embed secure practices, reinforce controls, and drive proactive risk management. This role focuses on strengthening cloud security tooling, incident response, and supporting SOC capabilities to protect critical assets. You’ll engage with vendors and internal stakeholders to improve security posture and resilience.

Pay / Benefits

  • Bonus schemes
  • Pension up to 12% with 6% matched
  • Health insurance with Vitality rewards
  • Life Assurance—four times annual salary

Responsibilities

  • Own and champion Vitality’s Cloud Security toolsets as SME and provide second-line support
  • Strengthen and evolve security tooling configurations across cloud environments
  • Act as liaison between internal teams, third-party suppliers, and product vendors for support and performance
  • Proactively monitor security systems, lead incident response, and participate in on-call rota when required
  • Provide expert advice on security apps and tooling to enable training and capability uplift
  • Communicate complex security topics to technical and non-technical audiences to influence decisions
  • Create and maintain technical documentation for configurations and processes
  • Partner with architecture teams to design and deliver SOC capabilities
  • Support planning and delivery of penetration testing, coordinating findings remediation
  • Contribute to continuous improvement of information security posture by staying current with threats and industry best practices

Key requirements

  • Strong knowledge of cloud security across modern environments
  • Advanced knowledge of attack methodologies and security testing
  • Experience in penetration testing (application and network), AppSec, and vulnerability management
  • Experience implementing and managing security controls (DLP, patching, RBAC, PAM, AV, DDoS mitigation, web proxy)
  • Understanding of information security principles, frameworks and regulatory requirements (ISO27001, FCA, PRA, ICO)
  • Working knowledge of OWASP Top 10 and build/integration tools (Maven, Jenkins, Chef, TFS)
  • Effective communication skills to explain technical concepts to non-technical stakeholders
  • Ability to quickly learn new technologies and support others
  • Ability to work both independently and in a team
  • Clear communication
  • Collaborative mindset
  • Adaptability
  • Cloud security expertise
  • Security operations & controls
  • Threat & vulnerability management

Posted: September 17th, 2026