KEYSTONE CYBER

Home Industries Healthcare

HEALTHCARE

Cyber security recruitment for healthcare

Healthcare security carries a constraint most sectors do not: the system you want to patch may be attached to a patient. Availability is a clinical concern, not an SLA, and candidates who cannot reason about that will not last.

What these teams hire

SECURITY RISK & GRC
Risk and compliance specialists working with POPIA and, in the UK, DSPT and UK GDPR expectations.
CLINICAL SYSTEMS
Security for electronic health records, imaging and integration platforms with long vendor lifecycles.
MEDICAL DEVICE & IOT
Connected device security — closer to OT and IoT work than to enterprise IT.
IDENTITY
Access management for high-turnover, shift-based clinical workforces with shared workstations.
SECURITY OPERATIONS
Detection and response across distributed sites, usually with a lean in-house team.
THIRD-PARTY RISK
Vendor and outsourced-provider assurance, which in healthcare covers most of the technology estate.

What is different about hiring here

We screen for judgement about clinical risk. The right candidate asks who the system serves and what happens if it stops, before proposing a control. Candidates arriving from banking often bring stronger governance discipline and need coaching on why a patch window can be measured in quarters.

Legacy is structural rather than accidental. Imaging and clinical systems run on vendor-supported stacks that cannot be modernised on the security team’s schedule, so compensating controls and segmentation matter more than remediation velocity. Candidates who see legacy as a failure to be fixed rather than a condition to be managed tend to struggle.

The market, honestly

In South Africa, demand comes mainly from private hospital groups, medical schemes, administrators and a growing health technology sector, with POPIA driving most of the governance hiring. Budgets are tighter than in financial services and the argument for candidates is scope and mission rather than package.

In the UK, provider and supplier-side hiring is steady and heavily governance-weighted, with the Data Security and Protection Toolkit and NHS supplier requirements shaping many briefs. Clinical systems and medical device security remain genuinely scarce specialisms in both markets.

Patient safety and availability constraints should be in the job advert. They attract the candidates who find this work interesting and deter the ones who would fight it for a year.

Where we recruit

Cape Town and Johannesburg across South Africa, and London and the wider United Kingdom.

Common questions

Which regulations apply to healthcare security hiring?

POPIA in South Africa, with sector guidance from professional bodies. In the UK, UK GDPR, the Data Security and Protection Toolkit and NHS supplier requirements. Candidates who have evidenced compliance rather than read about it are the useful ones.

Do you work with medical schemes and administrators as well as providers?

Yes, along with health technology and claims administration businesses. Their hiring looks closer to financial services governance than to hospital operations.

Is healthcare experience essential?

Not for engineering roles. For risk, GRC and clinical systems work, sector context shortens the ramp considerably and we weight it accordingly.

Can you recruit medical device and connected health security specialists?

Yes, and it is a small pool. The relevant experience is closer to product and IoT security than to enterprise IT, and we search it that way.

Explore further

Talk to us about your search

A short conversation is usually enough to tell you whether we can help.