Senior Cloud Security Engineer @Psychiatry UK
All Others
Salary competitive, de..
Remote Location
remote UK
Employment Type full-time
Posted 1wk ago

[Hiring] Senior Cloud Security Engineer @Psychiatry UK

1wk ago - Psychiatry UK is hiring a remote Senior Cloud Security Engineer. 💸 Salary: competitive, dependent upon experience plus £1000 working from home allowance 📍Location: UK

Role Description

The Senior Cloud Security Engineer is a senior, technically hands-on role with responsibility across cloud security engineering, platform assurance, DevSecOps, threat detection and continuous control improvement. The post holder will translate security policies, risk requirements and best practice into practical security guardrails, reusable patterns, automation and clear assurance evidence.

Working collaboratively across the organisation, the role will partner closely with Cyber Security, Platform Engineering, Software Engineering, Digital Workplace/IT, Data Science, Information Governance and Service Management teams, as well as selected managed-service partners, to embed effective security controls and secure-by-design principles across our technology environment.

This is a home-based role (applicants must reside in the UK), though occasional travel may be required for face-to-face meetings at various locations within the UK.

As our Senior Cloud Security Engineer, you will:

  • Cloud Security Architecture & Engineering
    • Own and evolve security guardrails, reference architectures and technical standards across AWS, Azure and Microsoft 365.
    • Design and assure security controls across identity, networking, compute, containers, storage, databases, encryption, secrets management, backup and recovery.
    • Provide senior technical review and challenge of cloud designs, threat models, Architecture Decision Records and significant changes.
    • Lead remediation of control gaps, ensuring security controls are practical, measurable and proportionate to risk and service criticality.
  • AWS Platform Security
    • Support and strengthen the AWS security operating model, including landing zones, account boundaries, access controls, permission models and break-glass arrangements.
    • Engineer and assure cloud-native security capabilities including IAM, KMS, CloudTrail, Config, GuardDuty, Inspector, Security Hub, CloudWatch and AWS Backup.
    • Drive security improvements across AWS workloads, including EC2, RDS, S3, ECS/Fargate, Lambda, ECR and internet-facing services.
  • Microsoft Cloud & Identity Security
    • Support and improve security across Microsoft 365 E5, Azure, Defender, Intune, Azure Virtual Desktop, Purview and SIEM capabilities.
    • Work with Digital Workplace teams and managed-service partners to validate controls, evidence their effectiveness and drive remediation.
  • DevSecOps, Application Security & Assurance
    • Embed Secure-by-Design principles across key projects through PUK’s Security and Technology Assurance Framework, maintaining proportionate and effective assurance criteria.
    • Integrate security into engineering workflows, CI/CD pipelines and cloud deployment patterns while minimising unnecessary delivery friction.
    • Implement and improve security testing, including SAST, SCA, secrets scanning, infrastructure-as-code, container and application security testing.
    • Partner with engineering teams on threat modelling, vulnerability remediation, dependency management and release assurance, promoting secure-by-default patterns and reusable solutions.
  • Detection, Vulnerability Management & Incident Response
    • Ensure security telemetry across cloud, identity, network, workloads and applications is complete, protected and effectively monitored.
    • Lead technical assessment of complex vulnerabilities and misconfigurations, driving proportionate, risk-based remediation.
    • Act as a senior technical responder for cloud security incidents, supporting containment, investigation, recovery and lessons learned.
    • Work closely with PUK’s 24/7 SOC, digital forensics and incident response partners.
  • Governance, Compliance & Assurance
    • Translate regulatory, industry and organisational requirements—including ISO/IEC 27001, Cyber Essentials Plus, DSPT, NCSC frameworks and UK GDPR—into effective technical controls and evidence.
    • Maintain security engineering evidence to support audits, control testing, risk treatment and continuous improvement.
    • Provide security assurance for new systems, suppliers and material changes, covering areas such as access, encryption, logging, resilience, data residency and exit arrangements.
    • Contribute to security standards, hardening guidance, runbooks, architecture documentation and control reporting.
  • Technical Leadership & Collaboration
    • Provide senior technical leadership, coaching and constructive challenge across Cyber, Platform, Engineering and Digital Workplace teams.
    • Lead technical investigations and security improvement initiatives, communicating clear recommendations to technical and non-technical stakeholders.
    • Work effectively with cloud, security and managed-service partners while retaining PUK ownership of security risk and control outcomes.
    • Manage priorities independently, escalating risks early and maintaining clear technical and assurance documentation.

Qualifications

  • Substantial hands-on experience in cloud or platform security, including designing, implementing and operating production security controls.
  • Strong AWS security engineering experience, including multi-account governance, IAM, logging, threat detection, vulnerability management, encryption, network controls and workload hardening.
  • Experience securing cloud-native applications, APIs, containers and CI/CD pipelines, with a strong understanding of DevSecOps and shared-responsibility models.
  • Experience building or reviewing infrastructure as code and security automation using technologies such as Terraform, CloudFormation, Python, PowerShell, AWS CLI or equivalent.
  • Experience of security monitoring, investigation and incident response using SIEM, cloud-native telemetry and relevant query languages.
  • Strong knowledge of network security, encryption, key and secrets management, resilience, vulnerability management and secure configuration.
  • Experience translating security risk, policy and compliance requirements into proportionate technical controls and auditable evidence.
  • Experience providing technical leadership, coaching or developing capability within security or engineering teams.
  • Strong understanding of security governance, risk management and the application of security controls within complex technology environments.

Requirements

  • Practical experience of Microsoft Entra ID and Microsoft cloud security, including Conditional Access, MFA, PIM, RBAC and Defender capabilities.
  • Experience within healthcare, regulated digital services or environments processing sensitive or special category data.
  • Knowledge of relevant security and regulatory frameworks, including ISO/IEC 27001, Cyber Essentials Plus, DSPT, NCSC CAF, NCSC Cloud Security Principles, NIST CSF and UK GDPR.
  • Experience with security tooling such as Datadog, Cloudflare, Rapid7, GitHub security capabilities, CSPM/CNAPP platforms or managed SOC services.
  • Experience of penetration testing, red teaming, threat modelling, MITRE ATT&CK mapping or cloud forensic investigation.
  • Understanding of service management, change control, supplier assurance, business continuity and disaster recovery.
  • Degree or equivalent practical experience in cyber security, computer science, cloud engineering or a related discipline.
  • Relevant professional certifications, such as AWS Certified Security – Specialty, AWS Solutions Architect, Microsoft security certifications, CCSP, CISSP, CISM, GIAC or Terraform Associate.

Benefits

  • Health Cash Plan
  • Well Hub Subscription
  • Access to an Employee Assistance Programme
  • Annual Volunteering Day
  • Enhanced Sickness and Family Leave pay
  • Length of Service Bonus
  • Work from Home allowance
  • Pension options

Company Description

Psychiatry UK is the UK’s leading provider of digital psychiatry services, working both privately and with the NHS to support children, teenagers and adults with expert, patient-centred care.

A career with Psychiatry UK allows you to expand your knowledge, enhance your skills, and gain valuable life experience—all while enjoying the flexibility of a remote full-time role. As part of a leading online mental health service, you'll collaborate with innovative, forward-thinking professionals in a dynamic, multidisciplinary team committed to making a real difference.

Before You Apply
️
remote Be aware of the location restriction for this remote position: UK
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior Cloud Security Engineer @Psychiatry UK
All Others
Salary competitive, de..
Remote Location
remote UK
Employment Type full-time
Posted 1wk ago
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: UK
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
×
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews

⚡ 126,763+ remote jobs, refreshed hourly

🔔 Real-time alerts: Apply first, direct to employer

🛡️ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later