Capital Markets Gateway

Senior Security Engineer

Capital Markets Gateway
Apply
2 months ago
London, United KingdomSenior

Responsibilities

  • Lead threat modeling across products, infrastructure, and new initiatives, identifying and prioritizing risks, attack surfaces, and vulnerabilities.
  • Conduct security risk assessments and translate findings into risk-based remediation plans prioritized by impact and blast radius.
  • Run security design and architecture reviews with Engineering and DevOps.
  • Support customer due diligence and SOC 2 Type II evidence gathering.
  • Develop security policies, standards, procedures, and repeatable workflows embedded in engineering processes.
  • Implement supply-chain and vulnerability management controls, CI/CD enforcement, dependency hygiene, and vulnerability triage workflows.
  • Harden the Azure cloud environment through secure configuration, identity and network controls, posture management, logging, and detection.
  • Strengthen endpoint and identity controls, including least privilege, phishing-resistant MFA, and privileged access controls.
  • Support detection and response activities and help mature the organization toward a proactive security posture.
  • Address AI security risks including prompt injection, data poisoning, and model and agent governance.
  • Own ambiguous cross-functional initiatives from problem framing through operationalization and communicate risk to technical teams and senior stakeholders.

Requirements

  • 6+ years of hands-on security experience with depth in security risk management, threat modeling, risk assessments, and security design and architecture review.
  • Practical governance, risk, and compliance experience, including audit and customer due-diligence support such as SOC 2 or similar.
  • Experience owning large, ambiguous initiatives end-to-end in a startup or fast-paced environment.
  • Working breadth across cloud security, supply-chain and vulnerability management, endpoint and identity, and detection and response.
  • Technical comfort with Azure, CI/CD, Microsoft 365, and at least one scripting language such as Python, Bash, or PowerShell.
  • Ability to influence without formal authority and communicate complex security concepts clearly to technical and non-technical audiences.
  • Ability to work effectively in a remote-first, asynchronous environment.
  • Preferred experience in banking, fintech, or another regulated industry.
  • Preferred familiarity with AI and agentic security risks, security frameworks, detection and response, red-team or penetration testing, and automation of repeatable security work.
  • Preferred experience with Entra ID, GitHub Enterprise Cloud, GHAS, GitHub Actions, Dependabot, Sentinel, Zscaler, Intune, Vanta, and the Atlassian suite.
  • Relevant certifications such as CISSP, CRISC, or OSCP are valued but not required.

Benefits

  • Equity.
  • Unlimited PTO, including 28 days with bank holidays plus unlimited additional paid leave.
  • Comprehensive benefits program managed by Globalization Partners.
  • Premium life and income protection.
  • Private medical and dental insurance.
  • Employee Assistance Program.
  • Pension contributions.
  • Hybrid work environment in a primarily remote-first organization with a small London office presence.
  • Education reimbursement and continuous learning opportunities.
  • Employee referral bonus and parental leave.

Tech Stack

AzureBashGitHub ActionsPowerShellPython

Categories

Capital Markets Gateway

About Capital Markets Gateway

51-200 employees
Contact me