- Страна
- Великобритания
Откликайтесь
на вакансии с ИИ

Cloud Security Engineer
Исключительная вакансия в компании-единороге с высокой социальной значимостью. Предлагает работу с современным стеком технологий, сильную инженерную культуру и отличный социальный пакет, включая саббатикал.
Сложность вакансии
Высокая сложность обусловлена требованием к опыту более 7 лет и глубоким знанием специфического стека (AWS, Kubernetes, Terraform, Kyverno). Работа в компании с 80 млн пользователей накладывает огромную ответственность за безопасность данных.
Анализ зарплаты
Зарплата в вакансии не указана, но для позиции Cloud Security Engineer с опытом 7+ лет в Лондоне рыночные показатели весьма высоки. Оценка основана на данных для Senior/Lead специалистов в финтех и хелс-тех секторах Великобритании.
Сопроводительное письмо
I am writing to express my strong interest in the Cloud Security Engineer position at Flo Health. With over 7 years of experience in infrastructure and cloud security, I have developed a deep expertise in securing large-scale AWS environments and implementing robust security-as-code practices. My background in automating container security with tools like Kyverno and Cosign, combined with a proficiency in Terraform, aligns perfectly with the mission of your Velocity team to build a secure-by-default platform.
Throughout my career, I have focused on embedding security into the CI/CD pipeline to eliminate friction for developers while maintaining the highest standards of data privacy. I am particularly impressed by Flo's commitment to privacy, such as the 'Anonymous Mode,' and I am eager to contribute my skills in policy-as-code and security observability to protect the sensitive health data of your 80 million users. I look forward to the possibility of discussing how my technical leadership can support Flo's continued growth and security excellence.
Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в flohealth уже сейчас
Присоединяйтесь к Flo, чтобы защищать данные 80 миллионов пользователей и строить будущее женского здоровья с использованием передовых технологий безопасности!
Описание вакансии
500M+ downloads. 80M+ monthly users. A decade of building – and we’re still accelerating.
Flo is the world’s #1 health & fitness app worldwide on a mission to build a better future for female health. Backed by a $200M investment led by General Atlantic, we became the first product of our kind to reach a $1B valuation in 2024 – and we’re not slowing down.
With 7M paid subscribers and the highest-rated experience in the App Store’s health category, we’ve spent 10 years earning trust at scale. Now, we’re building the next generation of digital health – AI-powered, privacy-first, clinically backed – to help our users know their body better.
The job
The Scale of the Challenge
At Flo we don't just have users, we have a global community. We are the #1 women's health app, in the last month alone, we saw 8.6M new installs and a 2.8M increase in active users.
When millions of people trust you with their most personal health data, security isn't a feature — it's a foundation. We are looking for a Cloud Security Engineer to join Velocity, our Internal Platform team. Your mission is to ensure that every system, pipeline, and tool our engineers rely on is secure by default — so they can ship fast without ever compromising trust.
The Mission: Velocity
The Velocity team exists to eliminate friction. We build and own the foundation everything else runs on: cloud infrastructure, developer tooling, and SRE practices. You will:
- Embed Security Into the Platform: Bake security, compliance, and best practices into the core stack so they're invisible to developers and impossible to skip.
- Automate Everything: Drive security-as-code across infrastructure, CI/CD pipelines, and container lifecycles — making manual gates a thing of the past.
What You Will Do
- Cloud Security Posture: Own and continuously strengthen Flo's AWS security posture using tools like GuardDuty, Inspector, Security Hub, and SSM Patch Manager.
- Container & Supply Chain Security: Harden container image security end-to-end — patch vulnerabilities automatically with Copacetic, sign and verify images with Cosign/Sigstore, and enforce policies at admission with Kyverno.
- Policy as Code: Manage CI/CD security across the organisation using policy-as-code tooling (Kyverno, Checkov), ensuring standards are enforced programmatically.
- Security Observability: Build visibility into security performance by measuring and visualising actionable metrics using tools like Databricks Dashboards or Looker.
- High-Scale Privacy: Support the infrastructure for industry-leading privacy features, such as our TIME-recognised "Anonymous Mode."
- Culture & Thought Leadership: Shape Flo's broader security culture through proactive engagement, documentation, and cross-team collaboration.
What You Bring
- Experience: 7+ years in Infrastructure Security, Cloud Security, or Security Engineering roles.
- Cloud Native Mastery: Deep expertise in AWS security services and best practices is essential.
- Infrastructure as Code: Proficient in Terraform and Terragrunt — you run everything as code.
- Container Security: Strong knowledge of Kubernetes security, image hardening, and admission control.
- Identity & Access: Solid understanding of identity management principles — SSO, OAuth, JWT, SAML.
- Automation Mindset: Comfortable scripting in Python, Bash, or similar to automate security workflows.
- Network Security: Understanding of modern network security principles and their practical application.
- SSDLC: Experience building Secure Software Development Lifecycle phases into engineering workflows.
Bonus Points
- Experience with security monitoring and event correlation systems (IDS/IPS, SIEM, AWS-native tooling).
- Knowledge of Zero Trust Architecture and its implementations (e.g., Cloudflare).
- Familiarity with secret management processes and tools.
- Experience in multi-cloud environments (AWS and preferably GCP).
- Understanding of business continuity principles (BIA, DRP).
- Professional accreditations such as AWS Security Specialty, CKS, or CISSP.
Why Join Flo?
- High Impact: Your work directly protects the health data of millions - Flo is rewriting women's health, and you'll make sure it's done securely.
- Autonomy: We hire experts and empower you to deliver.
- Cutting-Edge Stack: Work with modern security tooling (GuardDuty, Kyverno, Cosign, Elastic Cloud Security) deployed on real production infrastructure at massive scale.
How we work
We’re a mission-led, product-driven team. We move fast, stay focused and take ownership – from brief to build to impact. Debate is encouraged. Decisions are shared. We care about craft, ship with purpose, and always raise the bar.
You’ll be working with people who take their work seriously, not themselves. It takes commitment, resilience, and the drive to keep going when things get tough. Because better health outcomes are worth it.
What you'll get
We support impact with meaningful reward. Here’s what that looks like:
- Competitive salary and annual reviews
- Opportunity to participate in Flo’s performance incentive scheme
- Paid holiday, sick leave, and female health leave
- Enhanced parental leave and pay for maternity, paternity, same-sex and adoptive parents
- Accelerated professional growth through world-changing work and learning support
- In-person collaboration and work in a hybrid model, with 3 days per week spent in the office
- 5-week fully paid sabbatical at 5-year Floversary
- Flo Premium for friends & family, plus more health, pension and wellbeing perks
Diversity, equity and inclusion
Our strength is in our differences. At Flo, hiring is based on merit, skill and what you bring to the role – nothing else. We’re proud to be an equal opportunity employer, and we welcome applicants from all backgrounds, communities and identities. Read our privacy notice for job applicants.
Создайте идеальное резюме с помощью ИИ-агента

Навыки
- AWS
- Terraform
- Kubernetes
- Python
- Bash
- Terragrunt
- Kyverno
- Checkov
- GuardDuty
- OAuth
- JWT
- SAML
- SSO
- Cloudflare
- Databricks
- Looker
Возможные вопросы на собеседовании
Проверка практического опыта работы с Policy-as-Code, упомянутого в вакансии.
Расскажите о вашем опыте внедрения Kyverno или Checkov в CI/CD пайплайны: с какими основными сложностями вы столкнулись при масштабировании политик на всю организацию?
Вакансия делает упор на безопасность контейнеров и цепочки поставок.
Как бы вы организовали процесс автоматического патчинга уязвимостей в образах контейнеров, используя Copacetic, чтобы не нарушить стабильность продакшена?
Flo работает с чувствительными медицинскими данными.
Какие стратегии ограничения привилегий (Least Privilege) в AWS вы считаете наиболее эффективными для платформенной команды, работающей в масштабах Flo?
Проверка навыков реагирования и мониторинга.
Опишите ваш подход к настройке алертинга в AWS Security Hub и GuardDuty: как вы минимизируете количество ложноположительных срабатываний (false positives)?
Оценка архитектурного мышления и понимания Zero Trust.
Как бы вы спроектировали архитектуру доступа к внутренним инструментам разработки, следуя принципам Zero Trust, учитывая гибридный формат работы сотрудников?
Похожие вакансии
Security Engineer, Monitoring and Response
Associate - Technology & Data Protection
Front of House Security Concierge
Network Security Specialist – L2
Network Security Specialist – L1
Cloud Security Engineer (AWS)
1000+ офферов получено
Устали искать работу? Мы найдём её за вас
Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!
- Страна
- Великобритания