← Back to job listings
IH
Cybersecurity Engineer
Iterative Health · Cambridge, United Kingdom
About The Role
Join Iterative Health as the first dedicated cybersecurity engineer. You'll build and lead the company's cybersecurity strategy, protecting our people, technology, data, and business as we scale. You'll own the end-to-end security landscape, work cross-functionally with various teams, and create a scalable, modern security program. Benefits include vision/dental/medical insurance, life/disability insurance, parental leave, stock options, flexible work hours, and unlimited paid time off.
- Establish and lead the company's cybersecurity strategy, creating the foundation that will protect our people, technology, data, and business.
- Own the end-to-end security landscape, including our AWS cloud infrastructure, identity and access management, SaaS ecosystem, endpoint security, sensitive clinical and patient data.
- Work cross-functionally with IT, Engineering, Compliance, Legal, and business leaders to strengthen our security posture, reduce organizational risk, and embed security into every aspect of the company.
- Strong working knowledge of HIPAA, HITECH, SOC 2, and HITRUST frameworks
- Ability to communicate effectively with non-technical business partners
- Experience with vulnerability management, penetration test remediation, phishing simulation programs, or third-party risk reviews
- Strong documentation skills, including policy and procedure writing
- Experience with Bitdefender, Microsoft Defender, Intune, Entra ID, Microsoft Purview, Google Workspace security, Okta, or SIEM/logging tools
- Experience with PowerShell, Python, APIs, or security workflow automation
- 5+ years of experience in cybersecurity, security engineering, cloud security, IT security, or a related technical security role
- Bachelor's degree in IT, engineering, mathematics, or a related field; candidates with extensive cybersecurity certification in lieu of a degree will be considered
- Hands-on experience with AWS, Microsoft 365, and Google Workspace security tooling
- Knowledge of EU General Data Protection Regulation (GDPR)
- One or more relevant certifications, including but not limited to: CompTIA Security+, CySA+, or Pen Test+; GCIH; ISC2 CCSP; AWS Certified Security Specialty (SCS-C03); Microsoft SC-200, SC-300, SC-401, SC-100, or SC-900; Google Cybersecurity Professional or Cloud Cybersecurity Certificate
- Experience building or maturing a security program in a high-growth or startup environment
- Background in healthcare technology, clinical research, or other highly regulated industries
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring