Skin Analytics Logo

Skin Analytics

SecOps Engineer

Reposted 12 Days Ago
Be an Early Applicant
In-Office
London, Greater London, England
Senior level
In-Office
London, Greater London, England
Senior level
This role involves securing AWS infrastructure and CI/CD pipelines for regulated software, integrating security scans, and ensuring compliance with standards like ISO 27001.
The summary above was generated by AI

In this role you will lead the charge in securing and scaling our infrastructure and CI/CD pipelines for regulated clinical software. Working cross-functionally with engineering, QA, product, and regulatory teams, you’ll design, implement, and monitor secure, traceable DevOps workflows. You enable rapid, compliant delivery of Software as a Medical Device (SaMD) products.

Please note: this role requires in office presence for 3 days a week. Our office is in Farringdon, London. If you can't commit to this, please don't apply.
Responsibilities

  • Own AWS infrastructure security using least-privilege and zero-trust principles
  • Build and maintain secure CI/CD pipelines with automated security gates (Snyk, SonarQube, OWASP ZAP)
  • Conduct and coordinate penetration testing (internal and third-party); triage and drive remediation
  • Deploy runtime threat detection (GuardDuty, Falco, Wazuh)
  • Manage secrets detection and scanning (GitLeaks, Vault)
  • Build observability with ELK stack, Elastic agents, and anomaly alerting

What success looks like:
3 months

  • Deploy SAST tooling (SonarQube) across all repositories with automated PR scanning
  • Implement DAST scanning (OWASP ZAP) for staging environments with scheduled scans
  • Deploy secrets detection tooling (e.g., GitLeaks, TruffleHog) across all repositories
  • Establish a baseline security posture through initial penetration test; document and prioritise remediation backlog

6 months

  • Complete remediation of all critical/high findings from initial pen test
  • Achieve automated security gate coverage (SAST, DAST, dependency scanning) across 100% of production services

12 months

  • Implement full-stack observability using the ELK stack with Elastic agents deployed across all infrastructure for centralised security and performance monitoring
  • Configure anomaly detection dashboards and real-time alerting for security events and reliability metrics
  • Establish cadence of quarterly pen tests with trend reporting to leadership

Requirements

Have deep expertise in:

  • AWS (EC2, S3, RDS, IAM, VPC, CloudTrail, GuardDuty, Lambda)
  • CI/CD (Bitbucket Pipelines or similar), gated deployments
  • Security tooling: Snyk, SonarQube, OWASP ZAP, Burp Suite, Kali Linux
  • Pen testing coordination and vulnerability management
  • Terraform, Ansible, Docker
  • ELK stack / SIEM
  • Compliance: IEC 62304, ISO 27001, HIPAA, MDR
  • Strong networking: VPCs, security groups, NACLs, load balancers

Behaviours required:

  • Takes ownership: full accountability for infra, tooling, and controls; sees it through to completion.
  • Bias for automation: believes manual work should be temporary, builds repeatable pipelines and workflows.
  • Detail obsessed: doesn't miss the small stuff. Every commit, config, and policy matters in regulated software.
  • Clear communicator: explains risks, trade-offs, and technical plans to both engineers and non-tech stakeholders.
  • Collaborative & pragmatic: works well across disciplines and adapts to real-world constraints.

Benefits

💰Competitive salary

     Share options package - all our employees have ownership in the company

🏥Private healthcare

🌴25 days annual leave (5 day company shutdown in August + bank holidays)

👪Enhanced parental leave - includes adoption & foster

🚲Bike to work scheme

💻Training budget

     Weekly catch-ups, monthly meetings to talk about you, your ambitions and make plans

🎊Lots of fun social activities including company offsite!

Our Values

🌱 Building a Strong Foundation 

🎓 Always Learning 

🏅 Lead from the Front 

💪 Tough and Resilient 

The Real Stuff

Skin Analytics embraces and is committed to diversity and equal opportunities. We are dedicated to building a team that represents a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better our work will be.

Top Skills

Ansible
AWS
Bitbucket
Ci/Cd
Docker
Elk Stack
Snyk
Terraform

Skin Analytics London, England Office

2.04 The Frames, 1 Phipp Street, London, United Kingdom, EC2A 4PS

Similar Jobs

11 Days Ago
In-Office
London, Greater London, England, GBR
Senior level
Senior level
Design
The SecOps Engineer will optimize security and cloud systems, manage threat detection, and implement security technologies within the Office of Technology.
Top Skills: Cloud FrameworksGitPowershellPythonRapid7SIEM
2 Days Ago
In-Office
Manchester, Greater Manchester, England, GBR
Mid level
Mid level
Software
The SecOps Engineer will enhance security measures across infrastructure and applications, manage compliance with PCI DSS, monitor threats, and coordinate incident responses.
Top Skills: AWSBashEndpoint ProtectionIds/IpsLinuxPowershellPythonSIEMVulnerability ScannersWindows
24 Days Ago
In-Office
Shoreditch, Somerset, England, GBR
Senior level
Senior level
Healthtech • Software
As a Senior Security Engineer, you will enhance Accurx's security operations by managing vulnerabilities, incident response, and security architecture, while enabling secure healthcare communications.
Top Skills: Application Security ToolsCloud TechnologiesNetworking TechnologiesVulnerability Management Tools

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account