
Flo Health · London
500M+ downloads. 80M+ monthly users. A decade of building – and we’re still accelerating. Flo is the world’s #1 health & fitness app worldwide on a mission to ...
500M+ downloads. 80M+ monthly users. A decade of building – and we’re still accelerating.
Flo is the world’s #1 health & fitness app worldwide on a mission to build a better future for female health. Backed by a $200M
investment led by General Atlantic, we became the first product of our kind to reach a $1B valuation in 2024 – and we’re not
slowing down.
With 7M paid subscribers and the highest-rated experience in the App Store’s health category, we’ve spent 10 years earning trust
at scale. Now, we’re building the next generation of digital health – AI-powered, privacy-first, clinically backed – to help our
users know their body better.
The job
At Flo we don't just have users, we have a global community. We are the #1 women's health app, in the last month alone, we saw
8.6M new installs and a 2.8M increase in active users.
When millions of people trust you with their most personal health data, security isn't a feature — it's a foundation. We are
looking for a Cloud Security Engineer to join Velocity, our Internal Platform team. Your mission is to ensure that every system,
pipeline, and tool our engineers rely on is secure by default — so they can ship fast without ever compromising trust.
The Velocity team exists to eliminate friction. We build and own the foundation everything else runs on: cloud infrastructure,
developers and impossible to skip.
gates a thing of the past.
Security Hub, and SSM Patch Manager.
Copacetic, sign and verify images with Cosign/Sigstore, and enforce policies at admission with Kyverno.
standards are enforced programmatically.
like Databricks Dashboards or Looker.
Mode."
collaboration.
it's done securely.
production infrastructure at massive scale.
How we work
We’re a mission-led, product-driven team. We move fast, stay focused and take ownership – from brief to build to impact. Debate is
encouraged. Decisions are shared. We care about craft, ship with purpose, and always raise the bar.
You’ll be working with people who take their work seriously, not themselves. It takes commitment, resilience, and the drive to
keep going when things get tough. Because better health outcomes are worth it.
What you'll get
We support impact with meaningful reward. Here’s what that looks like:
Diversity, equity and inclusion
Our strength is in our differences. At Flo, hiring is based on merit, skill and what you bring to the role – nothing else. We’re
proud to be an equal opportunity employer, and we welcome applicants from all backgrounds, communities and identities. Read our
privacy notice for job applicants.
Qube Research & Technologies (QRT) is a global quantitative and systematic investment manager, operating in all liquid asset classes across the world. We are a technology and data driven group implementing a scientific approach to investing. Combining data, research, technology, and trading expertise has shaped our collaborative mindset, which enables us to solve the most complex challenges. QRT’s culture of innovation continuously drives our ambition to deliver high quality returns for our investors. The Security Assurance team is responsible for identifying, assessing, and validating security risks across QRT’s technology environment. The team works closely with Security Engineers, Software Engineers, Infrastructure Engineers, Cloud Engineers, and Technology stakeholders to evaluate the effectiveness of security controls and strengthen the firm's overall security posture through adversarial testing and assurance activities. Your Future Role within QRT You will: * Conduct internal penetration testing across a wide range of systems, including trading infrastructure, cloud platforms, APIs, and business applications in both Windows and Linux environments. * Perform red team-style assessments and adversarial simulations to identify weaknesses in detection, response, and resilience capabilities. * Design and execute security assurance strategies to validate the effectiveness of security controls across applications, infrastructure, and cloud environments. * Coordinate external penetration testing engagements with third-party security vendors, including scoping, execution oversight, validation of findings, and remediation tracking across cloud, infrastructure, and application environments. * Identify, exploit, and clearly document vulnerabilities, providing actionable remediation guidance tailored to engineering teams. * Collaborate with product security and development teams to ensure vulnerabilities are properly remediated. * Support threat modelling exercises by providing an attacker’s perspective on system design and architecture. * Develop and maintain tooling, scripts, and frameworks to automate testing and improve coverage of security assessments. * Contribute to continuous security testing within CI/CD pipelines, including validation of SAST/DAST findings and runtime security controls. * Conduct security reviews of internal and third-party systems, validating real-world exploitability of identified risks. * Provide mentorship and training to engineers on common attack vectors, exploitation techniques, and secure design principles. * Stay current with emerging threats, vulnerabilities, and offensive security techniques relevant to financial systems and low-latency environments. Your present skillset: * 5+ years of experience in penetration testing, red teaming, or security assurance roles, with hands-on experience testing complex, large-scale systems. * Strong practical knowledge of offensive security techniques, including web application, API, network, and cloud exploitation. * Solid understanding of system internals, networking, and common vulnerability classes, including OWASP Top 10, logic flaws, authentication and authorisation issues, and race conditions. * Familiarity with both Windows and Linux environments from an attacker’s perspective. * Experience using standard penetration testing tools such as Burp Suite, Metasploit, Nmap, BloodHound, and similar offensive security tooling. * Ability to assess the real-world impact of vulnerabilities and prioritise risks in a high-stakes environment. * Ability to clearly document findings, explain exploitability, and provide practical remediation guidance to engineering and infrastructure teams. * Strong communication skills, with the ability to clearly articulate technical risks and remediation strategies to engineering stakeholders. * Ability to operate independently, manage multiple assessments, and provide senior-level technical judgement during security assurance activities. * Preferred: * Experience testing applications and services developed in languages such as Python, C++, Rust, Go, and Kotlin/Java. * Experience with cloud security testing across AWS or Azure, including IAM, network configuration, storage, managed services, and common cloud misconfigurations. * Experience developing custom penetration testing tools, automation, scripts, exploits, or fuzzers. * Experience integrating security testing into CI/CD pipelines or supporting continuous assurance practices. * Understanding of detection and response mechanisms, with the ability to evaluate or bypass them during controlled testing. * Experience conducting red team exercises, adversary simulations, or purple team engagements. * Experience with containerised environments, Kubernetes, infrastructure-as-code, or hybrid cloud infrastructure. * Knowledge of low-latency systems, financial trading environments, or high-performance distributed systems. * Relevant certifications such as OSCP, OSEP, OSCE, CRTO, CCT APP, CCT INF, or equivalent practical experience. QRT is an equal opportunity employer. We value diversity as essential to our success and are committed to creating an environment where employees can work openly, respectfully, and collaboratively. In addition to supporting professional achievement, QRT offers initiatives and programmes designed to help employees maintain a healthy work-life balance.
ABOUT BARINGA Baringa is a global consulting firm that partners with leaders to drive change and create value. With deep industry expertise, and enabled by advanced technology, the firm helps clients to deliver with greater confidence and certainty. With over 2,000 people across the UK, Europe, North America, Asia and Australia, the firm combines global insight with local understanding. The firm works across energy and resources, financial services, government and public sector, consumer products and retail, pharmaceuticals and life sciences, manufacturing, and technology, media and telecoms, with capabilities spanning strategy, transformation and operational excellence – all powered by advanced technology, data, AI and digital innovation. Clients value Baringa’s collaborative approach and the way its teams integrate seamlessly – all working with a shared understanding of what matters most. The firm is known for its kind, curious experts who listen closely and care deeply about client success as they help clients transform energy markets, modernise financial platforms, expand telecoms and digital networks through advanced data analytics, enable digital services in government, and unlock growth in consumer sectors. Certified as a Great Place to Work around the world, Baringa has been recognised by the Financial Times in 22 categories of its UK Leading Management Consultants rankings, and by Forbes for four consecutive years as one of the World’s Best Management Consulting Firms. OUR TECHNOLOGY AND CYBER TEAM ARE LOOKING FOR AN EXPERIENCED SENIOR CYBER SECURITY ENGINEER TO JOIN THE TEAM. Baringa has grown so fast, and it continues to grow rapidly. Those new joiners keep on coming! We are a global function supporting the firm as it enters new markets. We are re-architecting and evolving our cloud-based business systems and infrastructure. We are on a mission to develop great technology products, deliver great services, and protect the trust our people and clients place in us. We have installed a new operating system for ourselves, and rebooted what was a corporate IT department into a corporate technology company, transforming the way we work. Now we are building for the next era of work. AI is becoming part of the fabric of how Baringa operates, and we are developing the products and platforms that will help colleagues find knowledge, act on insight, navigate complexity, and get work done with greater speed, quality, and confidence. Some of this will be visible through intelligent experiences and agentic systems. Some of it will sit beneath the surface: data products, workflow platforms, integrations, automations, cyber security, governance, and the architecture that makes all of it safe, scalable, resilient, and useful. So much to build on, so much to progress. So much to deliver. So much to play for! Do you know what though? We are going to do it. All of it and more. We have the support to drive change. We have the belief. We are going to do great things. Come and join us! WHAT YOU WILL BE DOING The Senior Cyber Security Engineer (Cyber Security) will be responsible for designing, implementing, reviewing and managing security measures to protect our Azure and M365 environments. The ideal candidate will have extensive Cloud Security experience and a proven track record in managing security measures to protect our Azure & M365 cloud infrastructure and data. This role requires a deep understanding of Azure and M365 security services, best practices, and will work closely with various stakeholders to ensure the security of our cloud infrastructure. * Design, implement and review security solutions for Azure and M365 environments. * Design, develop, maintain and assess security architecture artifacts (e.g., models, templates, standards, and procedures). * Oversee the development and implementation of security engineering best practices and standards. * Identify & implement automation opportunities, particularly across cloud provisioning, CI/CD pipelines, and policy enforcement. * Coordinate and manage Cyber engineering projects, ensuring timely delivery and quality. * Manage and prioritise an engineering backlog using Agile methodologies. * Maintain accurate documentation and team processes. WHAT ARE WE LOOKING FOR? We recruit individuals at all levels based on merit. Some of the key skills we are looking for: * Minimum of 5 years of experience in cyber security, with at least 3 years focused on cloud security. * Experience integrating security-as-code controls (e.g. policy-as-code, guardrails, or security scanning) into CI/CD pipelines using platforms such as Azure DevOps, GitHub, and Azure Policy, or equivalent technologies. * Proven experience designing and implementing security solutions with Azure and M365 security tools and technologies. * Strong understanding of security frameworks and standards (e.g., NIST, CIS, ISO 27001). * Familiarity with scripting and automation tools (e.g., PowerShell, Azure CLI, Azure Logic Apps). * Bachelor's degree in Computer Science, Information Technology, Cyber Security, or a related field. (Or equivalent experience) * Strong analytical and problem-solving skills. * Excellent communication and teamwork abilities. Relevant certifications such as: * Microsoft 365 Certified: Security Administrator Associate * Microsoft Certified: Cybersecurity Architect Expert certification * Certified Information Systems Security Professional (CISSP) * Certified Cloud Security Professional (CCSP) WHAT A CAREER AT BARINGA WILL GIVE YOU PUTTING PEOPLE FIRST. BARINGA IS A PEOPLE FIRST COMPANY AND WELLBEING IS AT THE FOREFRONT OF OUR CULTURE. WE RECOGNISE THE IMPORTANCE OF WORK-LIFE BALANCE AND FLEXIBLE WORKING AND PROVIDE OUR STAFF AMAZING BENEFITS. SOME OF THESE BENEFITS INCLUDE: * Generous Annual Leave Policy: We recognise everyone needs a well-deserved break. We provide our employees with 5 weeks of annual leave, fully available at the start of each year. In addition to this, we have introduced our 5-Year Recharge benefit which allows all employees an additional 2 weeks of paid leave after 5 years continuous service. * Flexible Working: We know that the ‘ideal’ work-life balance will vary from person to person and change at different stages of our working lives. To accommodate this, we have implemented a hybrid working policy and introduced more flexibility around taking unpaid leave. * Corporate Responsibility Days: Our world is important to us, so all our employees get 3 every year to help social and environmental causes and increase our impact on the communities that mean the most to us. * Wellbeing Fund: We want to encourage all employees to take charge and prioritise their own wellbeing. We’ve introduced our annual People Fund to support this by offering every individual a fund to support and manage their wellbeing through an activity of their choice. * Profit Share Scheme: All employees participate in the Baringa Group Profit Share Scheme so everyone has a stake in the company’s success. DIVERSITY AND INCLUSION We are proud to be an Equal Opportunity Employer. We believe that creating an environment where everyone feels a sense of belonging is central to our culture and that diversity is paramount to driving creativity, innovation, and value for our clients and for our people. AN AWARD-WINNING WORKPLACE You can be a part of our ‘Great Place to Work’ – with our commitment to women and well-being in the workplace for all. Click here to see some of our recent awards and how we’ve achieved this. USING BUSINESS AS A FORCE FOR GOOD. We maintain high standards of environmental performance and transparency, which can be seen through our commitment to Net Zero with our SBTI-verified Scope 1, 2 and 3 emissions reduction targets and our support of the Better Business Act. We report our progress publicly and ensure that we are also externally assessed and scored through organisations like CDP and EcoVadis - helping us to continually identify where we can improve. We have a long legacy of supporting the communities in which we work, and offer a variety of ways to contribute, by putting people first and creating impact that lasts. Our Corporate Social Responsibility (CSR) agenda is about giving back to the communities in which we live and work by sharing our skills, talent and time. In essence, we aim to empower and encourage everyone in the firm to contribute to the things we care about, and support registered charities and organisations with a clear social or environmental purpose to increase the positive impact they can have. JOIN US All applications received will be reviewed by a member of our Talent Acquisition team. We never rely solely on automated screening or AI tools to make hiring decisions. Your application will be considered for employment without regard to race, ethnicity, religion, gender, gender identity or expression, sexual orientation, nationality, disability, age, faith or social background. We do not filter applications by university background and encourage those who have taken alternative educational and career paths to apply. We would like to actively encourage applications from those who identify with less represented and minority groups. We operate an inclusive recruitment process, ensuring reasonable adjustments where needed. Please contact a member of our Recruitment Team to discuss further. BARINGA PRIVACY NOTICES For UK & EU Your personal data will be retained by Baringa for up to two years, in accordance with our UK Recruitment Privacy Notice / EU Recruitment Privacy Notice, to evaluate your application and meet our legal and reporting obligations. In line with the General Data Protection Regulation (GDPR), you have the right to request access to, rectification, or erasure (subject to legal limitations) of your personal data. For more information, please contact us at privacy@baringa.com For the USA Your personal data may be retained by Baringa for up to two years, as outlined in our Recruitment Privacy Notice (AMER & APAC), to support the recruitment process and internal reporting requirements. Where applicable, and in accordance with relevant federal and state laws, you may have the right to request access to or correction of your personal information. For further details, please contact privacy@baringa.com For Australia & Singapore Your personal data will be retained by Baringa for up to two years, in accordance with our Recruitment Privacy Notice (AMER & APAC), to assess your application and meet applicable reporting and legal obligations. In line with the Australian Privacy Act and Singapore’s Personal Data Protection Act (PDPA), you may have rights to access, correct, or request limited deletion of your personal data. For more information, please contact us at privacy@baringa.com
Qube Research & Technologies (QRT) is a global quantitative and systematic investment manager, operating in all liquid asset classes across the world. We are a technology- and data-driven group implementing a scientific approach to investing. Combining data, research, technology, and trading expertise has shaped our collaborative mindset, which enables us to solve the most complex challenges. QRT’s culture of innovation continuously drives our ambition to deliver high-quality returns for our investors. You will join the Security team, working closely with Software Engineers and Infrastructure teams to embed security into the design, development, and operation of systems across cloud services, business applications, and core infrastructure. Your Future Role within QRT You will: * Support the implementation and operation of product security controls across cloud services, core infrastructure, and business applications on Windows and Linux platforms * Work with engineering teams to integrate security into system design and development, applying practical approaches suitable for fast-moving environments * Contribute to secure software development practices, including supporting security reviews across languages such as Python, C++, Rust, Go, and Kotlin/Java * Perform threat modelling, vulnerability assessments, and security code reviews with guidance from senior team members * Assist with integrating and operating security tooling (e.g., SAST, DAST, dependency scanning) within CI/CD pipelines and runtime environments * Identify security risks and contribute to remediation and mitigation plans with engineering teams * Perform vendor security reviews to assess third-party security practices against internal standards * Build your product security knowledge and share learnings with peers across engineering teams Your Present Skillset * 3–5 years of experience in product security, application security, software engineering, or a related role * Hands-on experience with secure coding practices and at least one of: Python, C++, Rust, Go, Kotlin/Java * Solid technical foundation in software development, system architecture, or infrastructure, with a strong interest in security * Working knowledge of security principles and common vulnerabilities affecting software, cloud platforms, and business applications * Experience securing Windows and/or Linux-based systems * Practical experience with at least one cloud platform (AWS or Microsoft Azure), ideally in hybrid environments * Familiarity with threat modelling, vulnerability management, and risk assessment concepts * Experience using or integrating security scanning tools into development workflows and/or CI/CD pipelines * Strong problem-solving skills, clear communication, and willingness to learn in a fast-paced environment * Exposure to low-latency or performance-sensitive systems * Experience in financial services and/or regulated environments * Interest in automation and security tooling development QRT is an equal opportunity employer. We welcome diversity as essential to our success. QRT empowers employees to work openly and respectfully to achieve collective success. In addition to professional achievement, we are offering initiatives and programs to enable employees achieve a healthy work-life balance.