At a Glance
- Tasks: Lead security and scaling of infrastructure for clinical software, ensuring compliance and rapid delivery.
- Company: Join Skin Analytics, a pioneering company in medical device manufacturing with a commitment to quality and security.
- Benefits: Enjoy competitive salary, share options, private healthcare, 25 days leave, and fun social activities.
- Other info: This role requires in-office presence three days a week in Farringdon, London.
- Why this job: Be part of a collaborative team making a real impact in healthcare technology while developing your skills.
- Qualifications: Experience with AWS, CI/CD pipelines, and security operations is essential; detail-oriented and proactive mindset required.
The predicted salary is between 43200 - 72000 £ per year.
In this role you will lead the charge in securing and scaling our infrastructure and CI/CD pipelines for regulated clinical software. Working cross-functionally with engineering, QA, product, and regulatory teams, you’ll design, implement, and monitor secure, traceable DevOps workflows. You enable rapid, compliant delivery of Software as a Medical Device (SaMD) products. Please note: this role requires in office presence for 3 days a week. Our office is in Farringdon, London. If you can't commit to this, please don’t apply.
Responsibilities
- Own SecOps across our stack by managing secure AWS infrastructure, CI/CD pipelines, and developer environments using least-privilege and zero-trust principles.
- Integrate automated security scans (Snyk, Docker, IaC) into all stages of the SDLC.
- Design, implement, and maintain AWS infrastructure as code using Terraform and Ansible.
- Deliver threat models and drive remediations across cloud services (EC2, S3, RDS, etc.).
- Build Docker-first workflows with image scanning, tagging, and artifact management.
- Write and own SOPs for secure deployment and incident response aligned to ISO 27001 and IEC 62304.
- Extend observability through CloudWatch/ELK stack dashboards, anomaly detection, and alerting for security and performance monitoring.
- Support Transformation team by resolving any security queries that clients might have in their onboarding & deployment.
What success looks like:
- 3 months: Complete access audits and enforce secure MFA + least-privilege access across AWS, Bitbucket, and key tools. Identify and remediate top 5 security risks in CI/CD pipelines and cloud architecture. Fully integrate Snyk into all pipelines with automated alerts and reporting.
- 6 months: Mature pipelines to support automated tests, security gates, and gated deploys across all services.
- 12 months: Implement full-stack observability with anomaly alerts and dashboards for security and reliability using the ELK stack.
Have deep expertise in:
- Cloud Infrastructure (AWS): EC2, S3, RDS, IAM, VPC, CloudWatch, CloudTrail, Lambda, SQS/SNS.
- CI/CD Pipelines: Bitbucket Pipelines (or similar), multi-stage pipeline management, gated deployments.
- Security Operations: Snyk, IAM policies, threat modeling, zero-trust access, MFA, secrets management.
- Implementing and automating compliance requirements (IEC 62304, ISO 27001, HIPAA, MDR).
- Delivering secure software pipelines for Node.js, React, and Docker-based services.
- Writing secure deployment ansible playbooks and participating in internal audits or regulatory submissions.
- Production workloads supported by Terraform and Ansible, hosted on AWS.
- Strong networking knowledge, including VPCs, subnets, routing tables, security groups, and NACLs, route53, load balancers.
Behaviours required:
- Takes ownership: full accountability for infra, tooling, and controls; sees it through to completion.
- Bias for automation: believes manual work should be temporary, builds repeatable pipelines and workflows.
- Detail obsessed: doesn’t miss the small stuff. Every commit, config, and policy matters in regulated software.
- Clear communicator: explains risks, trade-offs, and technical plans to both engineers and non-tech stakeholders.
- Collaborative & pragmatic: works well across disciplines and adapts to real-world constraints.
Benefits:
- Competitive salary.
- Share options package - all our employees have ownership in the company.
- Private healthcare.
- 25 days annual leave (+ company shut down in August + bank holidays).
- Enhanced parental leave - includes adoption & foster.
- Training budget.
- Besides weekly catch-ups, monthly meetings to talk about you, your ambitions and make plans.
- Lots of fun social activities including company offsite!
The Real Stuff Skin Analytics embraces and is committed to diversity and equal opportunities. We are dedicated to building a team that represents a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better our work will be. Skin Analytics manufactures medical devices and complies with ISO standards 13485 and 27001. As part of your employment, you will be assigned Quality Management System (QMS) and Information Security Management System (ISMS). We require that our employees agree to complete their assigned training and diligently follow all company quality management and information security processes.
DevOps Engineer (Security Operations) in London employer: Skin Analytics Ltd
At Skin Analytics, we pride ourselves on being an exceptional employer, offering a dynamic work environment in the heart of Farringdon, London. Our commitment to employee growth is evident through our training budget and regular one-on-one meetings to discuss ambitions and career paths. With competitive salaries, private healthcare, and a strong focus on diversity and inclusion, we ensure that our team members feel valued and empowered while contributing to the development of innovative medical devices.
StudySmarter Expert Advice🤫
We think this is how you could land DevOps Engineer (Security Operations) in London
✨Tip Number 1
Familiarise yourself with the specific tools and technologies mentioned in the job description, such as AWS, Terraform, and Snyk. Having hands-on experience or relevant projects to discuss can set you apart during interviews.
✨Tip Number 2
Showcase your understanding of security principles like least-privilege and zero-trust. Be prepared to discuss how you've implemented these concepts in past roles or projects, as this is crucial for the position.
✨Tip Number 3
Highlight your collaborative skills by preparing examples of how you've worked cross-functionally with different teams. This role requires working closely with engineering, QA, and product teams, so demonstrating your teamwork abilities will be beneficial.
✨Tip Number 4
Since the role requires in-office presence, emphasise your willingness and ability to work on-site in Farringdon. Mention any previous experiences where you thrived in a collaborative office environment to reinforce your commitment.
We think you need these skills to ace DevOps Engineer (Security Operations) in London
Some tips for your application 🫡
Tailor Your CV:Make sure your CV highlights relevant experience in DevOps, particularly with AWS, CI/CD pipelines, and security operations. Use keywords from the job description to demonstrate your fit for the role.
Craft a Strong Cover Letter:In your cover letter, explain why you are passionate about securing infrastructure and how your skills align with the responsibilities outlined in the job description. Mention specific tools and methodologies you have used, such as Terraform, Ansible, or Snyk.
Showcase Relevant Projects:If you have worked on projects that involved secure software delivery or compliance with ISO standards, be sure to include these in your application. Describe your role and the impact of your contributions.
Highlight Soft Skills:The job requires clear communication and collaboration across teams. Provide examples in your application that showcase your ability to work with both technical and non-technical stakeholders, as well as your attention to detail.
How to prepare for a job interview at Skin Analytics Ltd
✨Showcase Your Security Knowledge
Be prepared to discuss your experience with security operations, particularly in AWS environments. Highlight any specific projects where you implemented security measures or automated security scans, as this role heavily focuses on securing CI/CD pipelines.
✨Demonstrate Your DevOps Expertise
Familiarise yourself with the tools and technologies mentioned in the job description, such as Terraform, Ansible, and Snyk. Be ready to explain how you've used these tools in past roles to enhance DevOps workflows and ensure compliance.
✨Prepare for Cross-Functional Collaboration
Since this role involves working with various teams, think of examples where you've successfully collaborated with engineering, QA, or product teams. Emphasise your communication skills and ability to explain technical concepts to non-technical stakeholders.
✨Understand Compliance Standards
Brush up on ISO 27001 and IEC 62304 standards, as they are crucial for this position. Be ready to discuss how you've ensured compliance in previous roles and how you would approach compliance in a regulated environment.