At a Glance
- Tasks: Lead security engineering for cloud-native projects with top-tier pharmaceutical clients.
- Company: Join Newpage Solutions, a global leader in digital health innovation.
- Benefits: Enjoy flexible remote work, competitive pay, and opportunities for personal growth.
- Other info: Collaborative environment focused on creativity, inclusivity, and continuous learning.
- Why this job: Make a real impact on health tech while working with cutting-edge cloud technologies.
- Qualifications: 8+ years in security engineering with strong coding skills in Python, Go, or TypeScript.
The predicted salary is between 70000 - 90000 £ per year.
Location: Remote | Type: Contract
Newpage Solutions is a global digital health innovation company helping people live longer, healthier lives. We partner with life sciences organizations—including pharmaceutical, biotech, and healthcare leaders—to build transformative AI and data-driven technologies addressing real-world health challenges. From strategy and research to UX design and agile development, we deliver and validate impactful solutions using lean, human-centered practices.
As a remote-first company, we foster creativity, continuous learning, and inclusivity, creating an environment where bold ideas thrive and make a measurable difference in people’s lives. Newpage looks for candidates who are invested in long-term impact.
Newpage is hiring a Staff DevSecOps Engineer to lead the security engineering posture of a strategic engagement with a global top-tier pharmaceutical company. As the technical anchor for the account, you will define how secure software is built, shipped, and operated across the client's cloud estate — spanning AWS, Azure, and GCP workloads — from research and clinical data platforms through to commercial and supply-chain systems. The client's strategic direction leans on AWS, and depth there is a meaningful advantage.
You will partner closely with the client's CISO organization, cloud platform team, application teams, and quality and compliance functions to embed security as code into every pipeline. This is a hands-on principal-level role for someone who thrives at the intersection of cloud-native engineering, regulatory rigor, and developer experience.
- Define and own the DevSecOps reference architecture across the client's cloud estate — landing zones, account/subscription vending, identity, secrets, network segmentation, and workload isolation patterns — applied consistently whether on AWS (preferred), Azure, or GCP.
- Set the multi-year roadmap for shift-left security, supply-chain integrity, runtime protection, and continuous compliance evidence collection across regulated and non-regulated workloads.
- Translate regulatory intent into engineering requirements that teams can implement.
- Raise the bar on secure coding, threat modeling, and incident response across the account.
Engineer Security Into the Cloud Estate:
- Design and operate hardened, multi-account or multi-subscription landing zones — AWS Control Tower / Organizations / SCPs / Identity Center (preferred), Azure Landing Zones / Management Groups / Policy, or GCP Organization Policy / Folders — with guardrails enforced as code.
- Build paved-road CI/CD pipelines (GitHub Actions, GitLab CI, AWS CodePipeline, Azure DevOps, or Jenkins) with integrated SAST, DAST, SCA, secrets scanning, IaC scanning, container scanning, and SBOM generation.
- Implement policy-as-code using OPA/Rego, Checkov, and cloud-native equivalents (AWS Config Rules / CloudFormation Guard, Azure Policy, GCP Organization Policy).
- Operationalize cloud-native security services end-to-end — AWS GuardDuty / Security Hub / Macie / Inspector / IAM Access Analyzer / KMS / Secrets Manager / WAF (primary), with working knowledge of Microsoft Defender for Cloud / Sentinel and GCP Security Command Center.
- Engineer controls that satisfy GxP, 21 CFR Part 11, Annex 11, HIPAA, GDPR, and the client's global information security standards — without slowing delivery teams down.
- Design continuous compliance evidence pipelines that auto-generate audit artifacts for FDA, EMA, and internal QA inspections, replacing manual screenshotting and ticket-based attestations.
- Partner with Computer System Validation (CSV) and Computer Software Assurance (CSA) teams to align DevSecOps tooling with validated-state expectations for clinical, manufacturing, and pharmacovigilance systems.
- Champion data protection for sensitive scientific IP, clinical trial data, and patient-adjacent datasets — tokenization, encryption strategy, and least-privilege access across cloud data services (e.g., S3 / Redshift / RDS / Lake Formation on AWS, or equivalents on Azure and GCP).
Build trust with the client's senior security, platform, and quality leadership; 8+ years of professional experience in security engineering, platform engineering, or SRE, with at least 4 years leading DevSecOps initiatives at scale.
- Deep, current expertise with at least one major public cloud at production scale — AWS is strongly preferred (you have personally designed and operated multi-account environments with 50+ accounts).
- Strong hands-on coding skills in at least one of Python, Go, or TypeScript, and fluency in infrastructure-as-code with Terraform (cloud-agnostic mastery preferred; AKS or GKE accepted) — including network policy, admission control, and supply-chain controls.
- Track record of operating in a regulated industry — pharma, healthcare, financial services, or critical infrastructure — and translating compliance frameworks into engineering controls.
- Comfortable presenting to a client CISO one day and pairing with a junior engineer the next.
Nice to have:
- Experience with policy-as-code (OPA/Rego, Cedar) and continuous compliance platforms (Wiz, Prisma Cloud, Orca, Drata, Vanta) at enterprise scale.
- Hands-on with secret management (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, or GCP Secret Manager) and zero-trust networking patterns.
- Relevant certifications such as AWS Security Specialty (preferred), Azure Security Engineer Associate, Google Professional Cloud Security Engineer, CISSP, CCSP, OSCP, or GIAC GCSA — credentials are a signal, not a substitute for evidence.
- Familiarity with AI/ML pipeline security and the emerging risks around generative AI in regulated environments.
At Newpage, we’re building a company that works smart and grows with agility—where driven individuals come together to do work that matters.
- Flexible, remote-first work – Choose where you work best while staying connected to a global, collaborative team.
- Room to grow – Opportunities for learning, leadership, and career development, shaped around you.
- Meaningful rewards – Competitive compensation that recognizes both contribution and potential.
Cloud/DevSecOps Engineer employer: Newpage Solutions
Newpage Solutions is an exceptional employer, offering a remote-first work environment that fosters creativity, inclusivity, and continuous learning. As a global leader in digital health innovation, we provide our employees with meaningful opportunities for growth and development while working on transformative projects that make a real difference in people's lives. With competitive compensation and a focus on collaboration, Newpage is the ideal place for driven individuals looking to thrive in a dynamic and impactful role.
StudySmarter Expert Advice🤫
We think this is how you could land Cloud/DevSecOps Engineer
✨Tip Number 1
Network like a pro! Reach out to folks in the industry on LinkedIn or at meetups. A personal connection can often get your foot in the door faster than any application.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those related to cloud and DevSecOps. This gives potential employers a taste of what you can do.
✨Tip Number 3
Prepare for interviews by practising common questions and scenarios specific to DevSecOps. Think about how you’d tackle security challenges in cloud environments and be ready to discuss your thought process.
✨Tip Number 4
Don’t forget to apply through our website! We love seeing candidates who are genuinely interested in joining us at StudySmarter. It shows initiative and helps us get to know you better.
We think you need these skills to ace Cloud/DevSecOps Engineer
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter for the Cloud/DevSecOps Engineer role. Highlight your relevant experience with AWS, Azure, or GCP, and showcase how your skills align with our mission at Newpage Solutions.
Showcase Your Technical Skills:We want to see your hands-on experience! Include specific examples of projects where you've implemented security as code, built CI/CD pipelines, or worked with policy-as-code. This will help us understand your technical prowess.
Be Authentic:Let your personality shine through in your application. We value creativity and inclusivity, so don’t hesitate to share your unique perspective and how you can contribute to our team culture at Newpage.
Apply Through Our Website:For the best chance of getting noticed, apply directly through our website. It’s the quickest way for us to receive your application and start the conversation about how you can make a difference with us!
How to prepare for a job interview at Newpage Solutions
✨Know Your Cloud Inside Out
Make sure you brush up on your knowledge of AWS, Azure, and GCP. Be ready to discuss specific projects where you've implemented cloud-native security practices. Highlight your experience with multi-account environments and how you've designed secure architectures.
✨Showcase Your Coding Skills
Prepare to demonstrate your coding abilities in Python, Go, or TypeScript. Bring examples of your work, especially around infrastructure-as-code with Terraform. Being able to talk through your code and the thought process behind it will impress the interviewers.
✨Understand Compliance Like a Pro
Familiarise yourself with compliance frameworks like GxP, HIPAA, and GDPR. Be ready to explain how you've translated these regulations into engineering controls in past roles. This shows that you can bridge the gap between security and development effectively.
✨Be Ready for Technical Discussions
Expect to engage in deep technical conversations, possibly with senior security leaders. Prepare to discuss your approach to threat modelling, incident response, and how you would implement policy-as-code. Confidence in these discussions will demonstrate your expertise.