Senior/Lead Cloud Security Engineer
Flo · London, United Kingdom
About The Role
Join Flo, a leading women's health app, as a Senior/Lead Cloud Security Engineer. In this role, you will be responsible for embedding security into the platform, automating security processes, and continuously strengthening Flo's AWS security posture. You will also focus on container and supply chain security, manage CI/CD security, build security observability, support high-scale privacy features, and shape Flo's broader security culture. Enjoy benefits such as participation in the Employee Share Ownership Plan, generous parental leave, access to learning resources, paid holiday and sick leave, and a flexible workplace.
- Embed security, compliance, and best practices into the core stack of the platform, making them invisible to developers and impossible to skip.
- Drive security-as-code across infrastructure, CI/CD pipelines, and container lifecycles, automating security workflows and making manual gates a thing of the past.
- Own and continuously strengthen the organization's cloud security posture, using various tools and practices to ensure robust security measures are in place.
- SSDLC: Experience building Secure Software Development Lifecycle phases into engineering workflows
- Automation Mindset: Comfortable scripting in Python, Bash, or similar to automate security workflows
- Network Security: Understanding of modern network security principles and their practical application
- Container Security: Strong knowledge of Kubernetes security, image hardening, and admission control
- Experience: 7+ years in Infrastructure Security, Cloud Security, or Security Engineering roles
- Identity & Access: Solid understanding of identity management principles — SSO, OAuth, JWT, SAML
- Cloud Native Mastery: Deep expertise in AWS security services and best practices is essential
- Infrastructure as Code: Proficient in Terraform and Terragrunt — you run everything as code
- Experience with security monitoring and event correlation systems (IDS/IPS, SIEM, AWS-native tooling)
- Knowledge of Zero Trust Architecture and its implementations (e.g., Cloudflare)
- Familiarity with secret management processes and tools
- Experience in multi-cloud environments (AWS and preferably GCP)
- Understanding of business continuity principles (BIA, DRP)
- Professional accreditations such as AWS Security Specialty, CKS, or CISSP
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
