Lead Security Engineer
Winston Fox · London Area, United Kingdom
قدّم وتابع مع أبلاي إيدجWe are looking to recruit an exceptional Security Engineer and are willing to pay an annual compensation of £250k-£300k and a loaded benefits package for a great candidate! Please read the advert before applyingSecurity shouldn't slow engineering down. It should enable it. We're looking for an exceptional Security Engineer to help secure the technology platform behind one of the world's leading investment firms. This is a hands-on engineering role where you'll work across cloud, identity, endpoints and infrastructure to build security that is automated, scalable and secure by design.You'll work at the heart of our Infrastructure Engineering team—not hidden away in a traditional security function—partnering with Platform, Network and Cloud Engineers to embed security into everything we build. This role is fully hands-on, and we expect a prolific engineer who is dedicated to engineering excellence to fill this position.This is a chance to shape the future of security in a modern, cloud-first environment where engineering excellence matters, automation is expected, and continuous improvement is part of the culture.What You'll OwnThis isn't a ticket-driven SOC role.You'll become one of the firm's lead specialists, helping protect a global technology platform spanning:Hybrid cloud infrastructure across AWS and AzureEnterprise identity and access managementEndpoint securityNetwork securityModern cloud platformsCorporate technologyCritical trading infrastructureYou'll improve the platform every day—not simply respond when something goes wrong.Your MissionBuild systems that are:Secure by designHighly automatedCloud nativeObservablePracticalScalableFrictionless for engineersResilient against modern threatsYou'll automate repetitive work.You'll reduce operational risk.You'll improve detection.You'll harden infrastructure.You'll raise the security maturity of the entire engineering organisation.What You'll Be DoingYou'll work across the full security engineering lifecycle, including:Designing and continuously improving detection, monitoring and response capabilities across modern SIEM and EDR platformsLeading the investigation and technical response to complex security incidents alongside our managed service providerOwning vulnerability management—from discovery and risk assessment through to remediation and verificationSecuring endpoints, identities and privileged access using Entra ID, Active Directory, Conditional Access and modern identity controlsDesigning secure cloud environments across AWS and Azure, including IAM, guardrails, logging and secure-by-default architecturesHardening endpoints, servers and cloud infrastructure using industry best practices and security baselinesBuilding automation using Python, PowerShell and Infrastructure-as-Code to eliminate manual operational workPartnering with Infrastructure, Cloud and Network Engineering teams to embed security into every architectural decisionLeading the charge on complex troubleshooting and technical problem-solvingEvaluating new security technologies and continuously improving the firm's defensive capabilitiesDeveloping incident response playbooks, technical documentation and operational standardsHelping engineers and users alike understand security through practical advice—not fear, uncertainty or bureaucracyWhat Great Looks LikeYou're an engineer first. Demonstrably passionate about technology and securitySecurity is your specialism. Deep expertise, both high and low levelYou enjoy building things. Dedicated to engineering excellence You automate anything. Ideally you code and script yourself and don't rely on vendor productsYou understand risk but avoid unnecessary complexity.You care about and have genuine experience creating secure platforms, rather than simply enforcing policy.You'll bring experience in:Deep Security Engineering expertise (Infrastructure, Cyber, Info, Cloud)SIEM and EDR platformsIdentity security including Entra ID, Active Directory and Conditional AccessAWS and/or Azure security architectureIAM, logging, guardrails and cloud-native security controlsVulnerability management and risk-based remediationFirewalls, segmentation and Zero Trust networkingPython or PowerShell automationInfrastructure-as-CodeExperience within financial services, in particular the buy-side, is highly beneficial, but outstanding engineers from firms renowned for technology innovation and engineering excellence are also interesting. If you've built sophisticated secure platforms where reliability and resilience genuinely mattered, we'd like to hear from you.Why Join?Ground-floor opportunity to build security into every layer of a world-class technology platform.You'll work alongside exceptional Infrastructure, Cloud and Platform Engineers solving complex technical challenges where resilience, security and engineering quality have direct business impact.You'll have real influence over architecture, tooling and security strategy—not simply operate someone else's platform.If you're excited by modern cloud security, automation, infrastructure engineering and solving genuinely difficult technical problems, we'd love to talk.