Senior Security Engineer (Developer)

Posted 17 hours 40 minutes ago by Our Future Health Limited

Permanent
Full Time
Other
England, United Kingdom
Job Description

We're looking for someone that is passionate about Security Engineering with a core software engineering background to do something that is the first of its kind at this scale. We're embedding a Security Engineer directly into a product squad where you'll be building a world-class security control (our own Airlock), written in Python and designed from the ground up.

You'll start fully embedded in our Research Enablement squad, acting as both Security SME and Software Engineer. Over time, your role will evolve into a roughly 50/50 split between hands-on coding and broader security engineering across the organisation.

We're looking for someone with a strong software engineering mindset, a love of automation, and the ability to balance technical ambition with pragmatic delivery. If you've built security tools in product-led environments, this is your chance to do it again, but in an environment that is striving to deliver a positive impact to millions of people.

At Our Future Health, our mission is to transform the prevention, detection and treatment of conditions such as dementia, cancer, diabetes, heart disease and stroke. We're looking for people to join us on our journey. If you're looking for a new challenge where you can contribute to helping future generations live in good health for longer, then we're keen to speak with you.

What you'll be doing
  • Developing our TRE airlock as part of a squad, specifically the 'airlock checks engine' and the security checks that will run within this.
  • Supporting our product managers with shaping our airlock roadmap, ensuring security items are included alongside non-security features.
  • Contributing to developing our airlock policy specifying how to handle the findings from airlock checks.
  • Leveraging in-house knowledge to enrich and enhance our SOC capabilities.
  • Overseeing and supporting the operation of our various security tools, including Microsoft Defender and Microsoft Purview suites and Entra ID (previously AAD) for IAM, Identity Governance and Privileged Identity Management.
  • Providing guidance and a level of oversight for vulnerability management and triage work.
  • Documenting security processes and security tool low-level design/configuration.
  • Contributing to the development of security service delivery and operation documentation.
  • Assisting tech teams with integrating their systems and services with security services and tools.
  • Supporting the cloud security and application security engineers and wider security team with their various responsibilities, including achieving and maintaining ISO 27001 certification and threat modelling activities.
What you won't be doing
  • Working in a siloed environment with no freedom to make decisions.
  • Working in a place where you can't see the impact your expertise makes.

To succeed in this role you will be able to demonstrate some of the following skills and experience:

  • Proficiency in writing Python and ideally KQL.
  • Comfortable working with Infrastructure as Code, ideally with knowledge of Terraform.
  • Significant experience developing Python scripts/systems
  • Experience working directly with software engineering best practices: source control, unit testing, code reviews, design documentation, excellent debugging, troubleshooting skills.
  • Experience with Azure (ideally), AWS or GCP, Docker, Kubernetes, and Helm.
  • Experience of operationally managing software components once live, including; observability, logging, metrics, error reporting, debugging and live incident management.
  • Experience with Microsoft Sentinel, Microsoft's Defender and Purview suites and Microsoft Entra.
  • Experience of SOAR tooling and automating security capabilities and operations.
  • Experience in Threat Modelling.
  • Ability to communicate with stakeholders and audiences outside your own team.
  • Exposure to Agile working.
  • Experience working in/with cross-functional teams consisting of engineers, product, UX and non-technical stakeholders.
  • Desire to be part of a small fast-paced security team.
  • Relevant certifications, such as: Microsoft certifications (MS-500, AZ-500, SC-200, SC-300, SC-400), CompTIA Security+, GIAC Security Operations Certified (GSOC), Cloud Security Alliance CCSK.
Benefits
  • Salary from £75,000 per annum.
  • Generous Pension Scheme - We invest in your future with employer contributions of up to 12%.
  • 30 Days Holiday + Bank Holidays - Enjoy a generous holiday allowance with the flexibility to take bank holidays when it suits you.
  • Enhanced Parental Leave - Supporting you during life's biggest moments.
  • Cycle to Work Scheme - Save 25-39% on a new bike and accessories through salary sacrifice.
  • Home & Tech Savings - Get up to 8% off on IKEA and Currys products, spreading the cost over 12 months through salary sacrifice
  • £1,000 Employee Referral Bonus - Know someone amazing? Get rewarded for bringing them on board!
  • Wellbeing Support - Access to Mental Health First Aiders, plus 24/7 online GP services and an Employee Assistance Programme for you and your family.
  • A Great Place to Work - We have a lovely Central London office in Holborn, and offer flexible and remote working arrangements.

Join us - let'sprevent disease together.

At Our Future Health, we recognise the importance of having a diverse workforce and ensuring that all candidates, regardless of their background, have equitable access to our application process. We proactively encourage applicants who identify as having a disability, neurodiversity, or long-term health conditions to let us know if they require any reasonable adjustments as part of their application process.

If you do require any reasonable adjustments, please email us at