14 hours ago
London, United KingdomStaff+
Responsibilities
- Design, implement, and operate automated security governance and controls across networks, devices, identity, and access systems.
- Architect reusable security services integrating governance, protection, detection, response, and recovery capabilities.
- Design and implement access controls for human and non-human identities, including service and agentic AI identities.
- Strengthen authentication, authorization, secrets management, audit, and privilege segmentation.
- Implement scalable role-based or attribute-based access models, automated policy enforcement, and access policy-as-code.
- Embed security governance and controls into code, cloud, and AI architectures, including network segmentation and identity controls.
- Diagnose and remediate identity, infrastructure, and access-control weaknesses and prevent recurrence.
- Lead cross-functional security design and threat-modeling activities and translate risks into engineering improvements.
- Automate security policies and guardrails across workflows and endpoints.
- Act as a technical authority advising technology teams on network, device, and identity security architecture.
Requirements
- Deep experience designing and engineering security across enterprise networks, devices, identity, and access.
- Strong understanding of network segmentation, identity controls, and security architecture across cloud systems.
- Hands-on experience implementing identity and access management and privileged-access controls across enterprise identity platforms.
- Strong knowledge of authentication, authorization, secrets management, audit, least privilege, and privilege segmentation.
- Experience designing access for human and non-human identities and addressing excessive permissions, exposed secrets, and access-governance weaknesses.
- Experience implementing role-based or attribute-based access control, automated policy enforcement, or access policy-as-code at scale.
- Ability to create effective security architectures and navigate trade-offs between security, accessibility, decentralization, and performance.
- Ability to automate controls through code, policy, and workflow automation.
- Strong technical judgment and ability to influence cross-functional technology teams through clear architectural reasoning.
Categories
About CFC
CFC is a London‑headquartered specialist insurer that builds technology‑driven products for businesses, with particular strength in cyber and other emerging risks. Founded in 1999, it underwrites lines including cyber, intellectual property, management liability, medical malpractice, product recall, and property & casualty, distributed primarily through brokers worldwide. CFC serves customers in over 90 countries and offers coordinated incident response to help clients manage cyber incidents from notification to resolution.
