
Senior Security Engineer
Capital Markets Gateway2 months ago
London, United KingdomSenior
Responsibilities
- Lead threat modeling across products, infrastructure, and new initiatives, identifying and prioritizing risks, attack surfaces, and vulnerabilities.
- Conduct security risk assessments and translate findings into risk-based remediation plans prioritized by impact and blast radius.
- Run security design and architecture reviews with Engineering and DevOps.
- Support customer due diligence and SOC 2 Type II evidence gathering.
- Develop security policies, standards, procedures, and repeatable workflows embedded in engineering processes.
- Implement supply-chain and vulnerability management controls, CI/CD enforcement, dependency hygiene, and vulnerability triage workflows.
- Harden the Azure cloud environment through secure configuration, identity and network controls, posture management, logging, and detection.
- Strengthen endpoint and identity controls, including least privilege, phishing-resistant MFA, and privileged access controls.
- Support detection and response activities and help mature the organization toward a proactive security posture.
- Address AI security risks including prompt injection, data poisoning, and model and agent governance.
- Own ambiguous cross-functional initiatives from problem framing through operationalization and communicate risk to technical teams and senior stakeholders.
Requirements
- 6+ years of hands-on security experience with depth in security risk management, threat modeling, risk assessments, and security design and architecture review.
- Practical governance, risk, and compliance experience, including audit and customer due-diligence support such as SOC 2 or similar.
- Experience owning large, ambiguous initiatives end-to-end in a startup or fast-paced environment.
- Working breadth across cloud security, supply-chain and vulnerability management, endpoint and identity, and detection and response.
- Technical comfort with Azure, CI/CD, Microsoft 365, and at least one scripting language such as Python, Bash, or PowerShell.
- Ability to influence without formal authority and communicate complex security concepts clearly to technical and non-technical audiences.
- Ability to work effectively in a remote-first, asynchronous environment.
- Preferred experience in banking, fintech, or another regulated industry.
- Preferred familiarity with AI and agentic security risks, security frameworks, detection and response, red-team or penetration testing, and automation of repeatable security work.
- Preferred experience with Entra ID, GitHub Enterprise Cloud, GHAS, GitHub Actions, Dependabot, Sentinel, Zscaler, Intune, Vanta, and the Atlassian suite.
- Relevant certifications such as CISSP, CRISC, or OSCP are valued but not required.
Benefits
- Equity.
- Unlimited PTO, including 28 days with bank holidays plus unlimited additional paid leave.
- Comprehensive benefits program managed by Globalization Partners.
- Premium life and income protection.
- Private medical and dental insurance.
- Employee Assistance Program.
- Pension contributions.
- Hybrid work environment in a primarily remote-first organization with a small London office presence.
- Education reimbursement and continuous learning opportunities.
- Employee referral bonus and parental leave.