Overview
In this role you will drive secure software development within a health research charity, partnering with engineering, architecture and cloud teams to embed security across the SDLC. You will design and implement security testing, automate controls in CI/CD, and strengthen cloud security with Azure and AKS. The position is hands-on and focused on secure design, testing, and enabling development teams to build safer applications at scale. A meaningful opportunity to shape security practices for impactful medical research.
Pay / Benefits
- remote / hybrid working
- London office
- 80,000 DOE, negotiable
- excellent benefits package
Responsibilities
- Promote secure development with engineering and architecture teams
- Implement and maintain application security testing solutions
- Integrate security controls into CI/CD pipelines
- Strengthen security of GitHub Actions and similar CI/CD platforms
- Provide guidance on secure API design and externally accessible systems
- Support Azure cloud infrastructure including AKS
- Develop security-as-code and policy-as-code
- Automate security processes via IaC and scripting
- Maintain technical and security documentation
- Support development teams with security tooling and best practices
- Contribute to threat modeling and compliance activities
Key requirements
- Hands-on experience embedding application security into the SDLC
- Experience with Microsoft Azure security controls and cloud security governance
- Experience with KQL
- Experience securing APIs, internet-facing services, Kubernetes (prefer AKS) and containerised environments
- Experience with SAST, DAST, IAST and SCA
- Knowledge of security automation, security-/policy-as-code and secure engineering practices
- Familiarity with GitHub and GitHub Actions
- Experience with Terraform and Python
- Understanding of cloud security governance
- Experience with threat modeling in software engineering contexts
- Knowledge of ISO 27001 relevance to secure engineering
- Exposure to Agile working environments and DevSecOps practices
- Ideally experience securing data platforms such as Databricks, Dagster or Snowflake
- Eligible to work in the UK
- Collaborative and cross-functional mindset
- Strong communication and guidance skills
- Proactive problem-solver and adapter to fast-changing environments
- Azure
- AKS
- KQL
…
