At a Glance
- Tasks: Join our Security team to protect user data and enhance security measures.
- Company: Flo is the leading health app dedicated to improving female health with over 75M monthly users.
- Benefits: Enjoy competitive salary, flexible working, and a 5-week paid sabbatical after 5 years.
- Why this job: Be part of a mission-driven team making a real impact in digital health.
- Qualifications: 7+ years in information security, hands-on AWS experience, and coding skills required.
- Other info: Diversity and inclusion are core values; we welcome applicants from all backgrounds.
The predicted salary is between 48000 - 84000 £ per year.
Flo is the world’s #1 health app on a mission to build a better future for female health. Your role as the Security Engineer will be pivotal in supporting Flo Health’s overall security posture. Working alongside our small but powerful Security team, you will help protect our applications and infrastructure by managing vulnerabilities, responding to incidents, and implementing security measures at scale. You’ll also contribute to developing custom tooling and embedding security best practices into our product lifecycle to ensure we stay ahead of emerging threats.
What you will do:
- Developing regular touchpoints with key stakeholders.
- Manage Vulnerabilities: Triage newly discovered vulnerabilities, investigate potential risks, verify that fixes are effective, and drive remediation efforts across teams.
- Implement Security Measures: Support teams by configuring WAF rules, setting rate limits, and deploying additional controls to protect our environment.
- Develop Custom Security Tooling: Contribute to the creation and maintenance of in-house tools that enhance our security capabilities and automation.
- Product Security Support: Assist in security assessments, threat modeling, and penetration testing, working closely with the Product Security team.
- Secure Development Lifecycle: Help implement and improve security gates within the SDLC.
- Adapt & Collaborate: Be prepared to dive into any emerging security challenges.
- Investigate and triage security alerts, manage security incidents.
- Gather, curate and communicate threat intelligence.
- Support and advise business stakeholders in relation to cyber security issues.
- Generate reports for both technical and non-technical staff and stakeholders.
What you bring:
- At least 7 years of experience in the information security field.
- Hands-on experience with AWS (or similar cloud platforms) and Cloudflare.
- Infrastructure as Code: Proficiency with Terraform or similar IaC tools.
- Vulnerability Knowledge: Solid understanding of common vulnerability classes and the OWASP Top 10.
- Coding & Scripting: Proficient in reading code (e.g., Python, Scala) and using Git for version control of code and configuration changes.
- Familiarity with iOS or Android security.
- Experience of industry-standard SIEM and vulnerability scanning tools.
Nice to have:
- Experience of supporting audits such as ISO27001.
- Experience of working with security risk management frameworks such as ISO31000.
- Knowledge of security control frameworks such as CIS, NIST800-53 and ISO27001.
How we work:
We’re a mission-led, product-driven team. We move fast, stay focused and take ownership – from brief to build to impact. Debate is encouraged. Decisions are shared. We care about craft, ship with purpose, and always raise the bar.
You’ll be working with people who take their work seriously, not themselves. It takes commitment, resilience, and the drive to keep going when things get tough. Because better health outcomes are worth it.
What you’ll get:
- Competitive salary and annual reviews.
- Opportunity to participate in Flo’s performance incentive scheme.
- Paid holiday, sick leave, and female health leave.
- Enhanced parental leave and pay for maternity, paternity, same-sex and adoptive parents.
- Accelerated professional growth through world-changing work and learning support.
- Flexible office + home working, up to 2 months a year working abroad.
- 5-week fully paid sabbatical at 5-year Floversary.
- Flo Premium for friends & family, plus more health, pension and wellbeing perks.
Diversity, equity and inclusion:
Our strength is in our differences. At Flo, hiring is based on merit, skill and what you bring to the role – nothing else. We’re proud to be an equal opportunity employer, and we welcome applicants from all backgrounds, communities and identities.
Senior Security Engineer (London) employer: Flo Health Inc.
Contact Detail:
Flo Health Inc. Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Security Engineer (London)
✨Tip Number 1
Familiarise yourself with the latest trends in cybersecurity, especially those related to cloud security and mobile app protection. Being well-versed in current threats and solutions will help you stand out during discussions with our team.
✨Tip Number 2
Network with professionals in the cybersecurity field, particularly those who have experience with AWS and Cloudflare. Engaging in conversations about best practices and challenges can provide valuable insights that you can bring to your interview.
✨Tip Number 3
Prepare to discuss your hands-on experience with vulnerability management and incident response. Be ready to share specific examples of how you've triaged vulnerabilities and implemented security measures in previous roles.
✨Tip Number 4
Showcase your coding skills by being prepared to discuss your experience with scripting languages like Python or Scala. Highlight any projects where you've used these skills to enhance security measures or automate processes.
We think you need these skills to ace Senior Security Engineer (London)
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in information security, particularly with AWS, Cloudflare, and vulnerability management. Use keywords from the job description to demonstrate your fit for the role.
Craft a Compelling Cover Letter: In your cover letter, express your passion for female health and how your skills align with Flo's mission. Mention specific experiences that showcase your ability to manage vulnerabilities and implement security measures.
Showcase Technical Skills: Clearly outline your hands-on experience with coding and scripting languages like Python or Scala. Include any relevant projects or tools you've developed that relate to security tooling or incident response.
Highlight Collaboration Experience: Since the role involves working closely with various teams, emphasise your experience in collaborating with stakeholders on security issues. Provide examples of how you've successfully communicated complex security concepts to both technical and non-technical audiences.
How to prepare for a job interview at Flo Health Inc.
✨Showcase Your Experience
With at least 7 years in the information security field, be ready to discuss specific projects or challenges you've faced. Highlight your hands-on experience with AWS and Cloudflare, as well as any relevant tools you've used.
✨Demonstrate Your Problem-Solving Skills
Prepare to discuss how you've triaged vulnerabilities and managed security incidents in the past. Use examples that showcase your ability to think critically and adapt to emerging security challenges.
✨Familiarise Yourself with Security Frameworks
Understand the security control frameworks mentioned in the job description, such as CIS and NIST800-53. Be prepared to explain how you've applied these frameworks in your previous roles.
✨Communicate Effectively
Since you'll be generating reports for both technical and non-technical staff, practice explaining complex security concepts in simple terms. This will demonstrate your ability to communicate with diverse stakeholders.