Senior Cloud Security Engineer
Senior DevSecOps Engineer - SaaS / Cloud Security - Biopharma Remote - Europe / UK based We are supporting a search for a Senior DevSecOps Engineer within a specialist life sciences software company building a SaaS platform for biopharma and scientific teams. This is a hands-on security role, not just advisory work. The platform handles sensitive scientific data, so security, reliability, traceability and compliance all matter. You would work closely with DevOps, backend, data and platform engineers to build security into the way software is delivered. That means secure CI/CD, cloud and Kubernetes hardening, automated checks, monitoring, incident response and practical security guardrails that engineers can actually use. It should suit someone who likes ownership, still enjoys being hands-on, and wants to shape security early as a SaaS platform grows. Role focusEmbedding security into CI/CD pipelines and engineering workflowsImplementing SAST, DAST, SCA, secret scanning and IaC scanningSecuring cloud infrastructure across Azure, AWS or GCPHardening Kubernetes, containers, images and runtime environmentsBuilding automated guardrails with Terraform and policy-as-codeImproving vulnerability management and software supply-chain securityDesigning logging, monitoring, threat detection and alertingWorking with SIEM/SOAR, CSPM and runtime security toolingDefining incident response runbooks and supporting remediationPartnering with engineering teams to make security practical What we are looking for6+ years in DevSecOps, cloud security, security engineering, DevOps or SREStrong experience securing production SaaS or cloud platformsExperience working in regulated or compliance-heavy environments, such as healthcare, pharma, biotech, fintech, payments or enterprise SaaSHands-on CI/CD security tooling experienceStrong cloud security experience with Azure, AWS or GCPKubernetes and container security experienceTerraform / Infrastructure-as-Code experiencePolicy-as-code exposure, ideally OPA/Rego, Kyverno or similarPython, Bash or Go scriptingSIEM/SOAR, CSPM, logging, alerting and incident response experienceGood understanding of secure SDLC, threat modelling and vulnerability managementComfortable working directly with engineers Useful extrasGxP, GAMP 5, HIPAA, GDPR, SOC 2 or ISO 27001 exposureAzure security tools such as Defender for Cloud, Sentinel, Key Vault or Entra IDSBOM, SLSA, Sigstore/cosign, Syft, Grype or TrivyHashiCorp Vault, cloud KMS, OIDC/SAML, Zero Trust or mTLSPen testing, purple teaming or vulnerability management programmes This is not a generic DevOps role with security added to the title. The company needs someone who can own the security foundation of a SaaS product used in a regulated scientific environment. Apply here, or if you know someone strong across DevSecOps, cloud security, secure CI/CD or Kubernetes security, please let me know.
