Lead Cybersecurity Engineer (39B9D58)
Referment · London, England, United Kingdom
Apply & track with Apply EdgeReferment is working with a fast-growing UK wealth technology company whose digital investment platform serves financial advisers and their clients in a regulated financial services environment. Security is central to how the business operates, and it is now investing further in the people who keep its cloud and IT infrastructure secure.As Lead Cybersecurity Engineer, you'll play a critical role in designing, implementing and continuously improving the security of the company's cloud and IT estate. This is a hands-on technical role focused on securing cloud infrastructure and user endpoints. Working closely with the Head of IT Infrastructure, you'll translate security strategy and policies into scalable, automated technical controls that support secure-by-design principles and regulatory compliance.The RoleYou'll implement and maintain cloud security controls across the Google Cloud Platform environment, covering identity, networking, data protection and workload security — including capabilities such as IAM, VPC Service Controls, Identity-Aware Proxy and Security Command Center. You'll embed security into CI/CD pipelines through IaC validation, vulnerability scanning, secret detection and compliance checks, and develop Infrastructure as Code using Terraform.You'll also secure and manage Microsoft 365, Entra ID and Intune environments using MFA, Conditional Access, PIM, device compliance and least-privilege access, and drive Zero Trust principles across cloud infrastructure, corporate systems, endpoints and identity platforms. Supporting and optimising MDR/EDR technologies, maintaining vulnerability management processes and acting as a technical escalation point during security incidents are all part of the remit.You'll work with engineering teams to embed security by design into application development, perform security architecture reviews, threat modelling and technical risk assessments, and support cybersecurity certification, compliance and audit requirements including SOC 2 and ISO 27001.What We're Looking For5-8+ years in cloud security engineering or infrastructure securityExperience implementing and managing identity and access management solutions, including SSO, MFA and privileged access controlsVulnerability management across cloud infrastructure, servers and endpointsUnderstanding of SOC 2 and/or ISO 27001 controls, audits and compliance processesNetworking, cloud and IT infrastructure security knowledge, including Zero Trust and cloud security architectureMDR/EDR and cloud monitoring experienceEmail security, phishing protection and user security awarenessAlso ValuableFinTech or financial services experienceStrong hands-on GCP security experience, and Microsoft 365, Entra ID and Intune securityExposure to container security, GKE and Cloud RunAutomation with Python, PowerShell or BashCertifications such as CISSP, CISM or Google Professional Cloud Security EngineerThis is a permanent, hybrid role with up to two remote days per week; the remainder of the week is spent in the central London office. The company is unable to offer visa sponsorship for this position.This Could SuitA hands-on cloud security engineer who is ready to own the security posture of a growing platform — someone who enjoys building automated controls rather than only operating them, and who wants to work closely with infrastructure and engineering teams in a regulated fintech setting.#Referment