Cloud Security Engineer
at Flohealth
- Location
- Vilnius
- Posted
- 5d ago
at Flohealth
<div class="content-intro"><p><strong>500M+ downloads. 80M+ monthly users. A decade of building – and we’re still accelerating.</strong></p> <p>Flo is the world’s #1 health & fitness app worldwide on a mission to build a better future for female health. Backed by a $200M investment led by General Atlantic, we became the first product of our kind to reach a $1B valuation in 2024 – and we’re not slowing down.</p> <p>With 7M paid subscribers and the highest-rated experience in the App Store’s health category, we’ve spent 10 years earning trust at scale. Now, we’re building the next generation of digital health – AI-powered, privacy-first, clinically backed – to help our users know their body better.</p> <p><strong>The job</strong></p></div><h3><strong>The Scale of the Challenge</strong></h3> <p>At Flo we don't just have users, we have a global community. We are the #1 women's health app, in the last month alone, we saw 8.6M new installs and a 2.8M increase in active users.</p> <p>When millions of people trust you with their most personal health data, security isn't a feature — it's a foundation. We are looking for a <strong>Cloud Security Engineer</strong> to join <strong>Velocity</strong>, our Internal Platform team. Your mission is to ensure that every system, pipeline, and tool our engineers rely on is secure by default — so they can ship fast without ever compromising trust.</p> <h3><strong>The Mission: Velocity</strong></h3> <p>The Velocity team exists to eliminate friction. We build and own the foundation everything else runs on: cloud infrastructure, developer tooling, and SRE practices. You will:</p> <ul> <li><strong>Embed Security Into the Platform:</strong> Bake security, compliance, and best practices into the core stack so they're invisible to developers and impossible to skip.</li> <li><strong>Automate Everything:</strong> Drive security-as-code across infrastructure, CI/CD pipelines, and container lifecycles — making manual gates a thing of the past.</li> </ul> <h3><strong>What You Will Do</strong></h3> <ul> <li><strong>Cloud Security Posture:</strong> Own and continuously strengthen Flo's AWS security posture using tools like GuardDuty, Inspector, Security Hub, and SSM Patch Manager.</li> <li><strong>Container & Supply Chain Security:</strong> Harden container image security end-to-end — patch vulnerabilities automatically with Copacetic, sign and verify images with Cosign/Sigstore, and enforce policies at admission with Kyverno.</li> <li><strong>Policy as Code:</strong> Manage CI/CD security across the organisation using policy-as-code tooling (Kyverno, Checkov), ensuring standards are enforced programmatically.</li> <li><strong>Security Observability:</strong> Build visibility into security performance by measuring and visualising actionable metrics using tools like Databricks Dashboards or Looker.</li> <li><strong>High-Scale Privacy:</strong> Support the infrastructure for industry-leading privacy features, such as our TIME-recognised "Anonymous Mode."</li> <li><strong>Culture & Thought Leadership:</strong> Shape Flo's broader security culture through proactive engagement, documentation, and cross-team collaboration.</li> </ul> <h3><strong>What You Bring</strong></h3> <ul> <li><strong>Experience:</strong> 7+ years in Infrastructure Security, Cloud Security, or Security Engineering roles.</li> <li><strong>Cloud Native Mastery:</strong> Deep expertise in AWS security services and best practices is essential.</li> <li><strong>Infrastructure as Code:</strong> Proficient in Terraform and Terragrunt — you run everything as code.</li> <li><strong>Container Security:</strong> Strong knowledge of Kubernetes security, image hardening, and admission control.</li> <li><strong>Identity & Access:</strong> Solid understanding of identity management principles — SSO, OAuth, JWT, SAML.</li> <li><strong>Automation Mindset:</strong> Comfortable scripting in Python, Bash, or similar to automate security workflows.</li> <li><strong>Network Security:</strong> Understanding of modern network security principles and their practical application.</li> <li><strong>SSDLC:</strong> Experience building Secure Software Development Lifecycle phases into engineering workflows.</li> </ul> <h3><strong>Bonus Points</strong></h3> <ul> <li>Experience with security monitoring and event correlation systems (IDS/IPS, SIEM, AWS-native tooling).</li> <li>Knowledge of Zero Trust Architecture and its implementations (e.g., Cloudflare).</li> <li>Familiarity with secret management processes and tools.</li> <li>Experience in multi-cloud environments (AWS and preferably GCP).</li> <li>Understanding of business continuity principles (BIA, DRP).</li> <li>Professional accreditations such as AWS Security Specialty, CKS, or CISSP.</li> </ul> <h3><strong>Why Join Flo?</strong></h3> <ul> <li><strong>High Impact:</strong> Your work directly protects the health data of millions - Flo is rewriting women's health, and you'll make sure it's done securely.</li> <li><strong>Autonomy:</strong> We hire experts and empower you to deliver.</li> <li><strong>Cutting-Edge Stack:</strong> Work with modern security tooling (GuardDuty, Kyverno, Cosign, Elastic Cloud Security) deployed on real production infrastructure at massive scale.</li> </ul><div class="content-pay-transparency"><div class="pay-input"><div class="title">Salary Range - gross per month (ranges may vary based on skills and experience)</div><div class="pay-range"><span>€6.000</span><span class="divider">—</span><span>€8.000 EUR</span></div></div></div><div class="content-conclusion"><p><strong>How we work</strong></p> <p>We’re a mission-led, product-driven team. We move fast, stay focused and take ownership – from brief to build to impact. Debate is encouraged. Decisions are shared. We care about craft, ship with purpose, and always raise the bar.</p> <p>You’ll be working with people who take their work seriously, not themselves. It takes commitment, resilience,