About this role
Salary: £85,000 - 100,000 per year
Requirements: 5+ years of experience in information security, cybersecurity, or product securityStrong experience with ISO 27001 and recognised frameworks such as NIST and OWASPExperience conducting risk assessments, threat modelling, and vulnerability managementExperience integrating security into software development lifecyclesStrong cloud security knowledge, ideally AWSExperience supporting audits, regulatory reviews, or compliance activitiesExcellent stakeholder management and communication skillsAbility to work independently and deliver pragmatic, risk-based solutionsExperience in Medical Devices, HealthTech, or Software as a Medical Device (SaMD) is highly desirableProduct cybersecurity experience is highly desirableKnowledge of ISO 13485, ISO 14971, GDPR, HIPAA, and FDA cybersecurity guidance is highly desirableExperience with connected devices, mobile applications, or cloud-hosted healthcare platforms is highly desirableProfessional certifications such as CISSP, CISM, CRISC, CSSLP, ISO 27001 Lead Auditor, or Lead Implementer are advantageous Responsibilities: Maintain and improve our Information Security Management System (ISMS), policies, procedures, and controlsLead cybersecurity risk assessments, threat modelling, and security reviewsOversee penetration testing, vulnerability management, and remediation activitiesAdvise on secure design, cloud security, mobile security, authentication, encryption, and access controlEmbed cybersecurity requirements within our software and product development processesSupport regulatory submissions, audits, inspections, and customer security assessmentsMonitor emerging threats affecting our applications, cloud services, and connected technologiesManage incident response, business continuity, and cyber resilience activitiesReview third-party suppliers and technology partners from a security perspectiveProvide security awareness training and guidance across our organisationPresent security risks and recommendations to our senior leadership Technologies: AWSCloudSupportMobileOWASPSecurity More:
We are an innovative digital health organisation developing market-leading healthcare technology used across international markets. We are growing within a highly regulated technology environment and are seeking a security subject matter expert to lead and mature our cybersecurity capability, working closely with our Software Development, Quality, Regulatory, Clinical, IT, and Operations teams. This is a 12-month fixed-term role with a hybrid arrangement requiring attendance in Cambridge once a week. The full-time equivalent salary is £85,000–£100,000.
last updated 40 week of 2026