> Markdown version of [/jobs/ext/1313762-senior-security-engineer](https://www.wearedevelopers.com/jobs/ext/1313762-senior-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - **Company:** Capital Markets Gateway LLC - **Location:** London, OH, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Microsoft Azure, Bash Shell, Cloud Computing, Cloud Computing Security, Continuous Integration, DevOps, Python (Programming Language), Open Web Application Security, Windows PowerShell, Phishing, Software Vulnerability Management, Data Logging, Scripting, Microsoft InTune, Atlassian Tools, Github Enterprise - **Published:** July 17, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=087d5bed0744eade ## About the Role * Have 6+ years of hands-on security experience, with real depth in security risk management: threat modeling, risk assessments, and security design and architecture review. * Have run governance, risk, and compliance work in practice, including audit and customer due-diligence support (SOC 2 or similar), and made it operational rather than just documented. * Have thrived in a startup or other small, fast-paced environment, owning large, ambiguous initiatives end-to-end with little scaffolding and shipping them. * Have working breadth across the control landscape: cloud security, supply-chain and vulnerability management, endpoint and identity, and detection and response. * Are genuinely technical: comfortable in cloud environments (Azure preferred), CI/CD, and at least one scripting language (e.g. Python, Bash, PowerShell), so your controls hold up in engineering reality. * Lead with empathy and influence, and distill complex security concepts into clear, actionable guidance for technical and non-technical audiences alike. * Thrive navigating ambiguity and make sound, risk-based calls with incomplete information. * Work effectively in a remote-first setup: most of the team is remote, with a small London in-office presence, so you communicate crisply and operate well asynchronously. * Navigate an organization to get things done you know who to pull in for information or alignment, and you drive that alignment without formal authority., * Have banking, fintech, or other regulated industry experience. * Use AI tooling fluently in your own day-to-day work and are eager to integrate it into security workflows as a force multiplier. * Have a bias toward automating repeatable security work - scripting, tooling, and process - to scale your impact. * Be familiar with AI and agentic security risks (prompt injection, data poisoning, model and agent governance). * Have experience mapping security frameworks (NIST CSF, ISO 27001, OWASP, NIST AI RMF). * Have hands-on exposure to detection and response, red-team, or pen-test work. * Have experience with our stack: Azure / Entra ID, GitHub Enterprise Cloud (GHAS, Actions, Dependabot), Sentinel, Zscaler, Intune, Vanta, and the Atlassian suite. * Hold relevant certifications (e.g. CISSP, CRISC, OSCP) - valued but not required. ## Description We are hiring a Senior Security Engineer to lead our security risk management and governance work. This is a senior individual-contributor role for someone who thrives on owning large, ambiguous initiatives end-to-end and turning them into shipped, operationalized programs. You will report directly to the CISO, own cross-program initiatives, and collaborate closely with senior leadership across the firm. The core of the role is hands-on security risk management, threat modeling, security risk assessments, and security design and architecture reviews, paired with the governance and process work that scales the program. You will partner on customer due-diligence and SOC 2 evidence and turn security controls into repeatable workflows that fit how the business already works. You will apply that lens across the full control landscape: cloud security, supply-chain and vulnerability management, endpoint and identity, detection and response, and AI security. CMG operates in a highly regulated, client-facing market, so scope and impact here are unusually large for the level. We value strong collaboration and a deep sense of ownership: you will be trusted to take initiatives and run with them, often without an established process or a big team behind you. The defining shift for the program is moving from reactive to proactive, and this role is central to it. This is a high-growth-potential role: we expect the right person to start as a senior individual-contributor and grow into broader leadership, including people's leadership, as the function scales., Security Risk Management * Lead threat modeling across products, infrastructure, and new initiatives, identifying and prioritizing risks, attack surfaces, and vulnerabilities. * Conduct security risk assessments and translate findings into pragmatic, risk-based remediation prioritized by impact and blast radius. * Run security design and architecture reviews, partnering with Engineering and DevOps to reduce risk through secure design and simplicity, not just added controls. Governance, Risk & Compliance * Partner on customer due-diligence (DDQ) and SOC 2 Type II evidence gathering, keeping compliance sustainable rather than fire-drilled. * Build repeatable security workflows that embed controls into existing engineering processes instead of creating parallel ones. * Develop and maintain clear, role-relevant security policies, standards, and procedures, and drive consensus without direct authority. Security Controls and Technical Program Execution * Understand and implement controls for supply-chain risk and vulnerability management, including CI/CD enforcement and dependency hygiene, and build vulnerability triage workflows that score real risk by exploitability, reachability, and compensating controls rather than raw CVSS. * Harden and secure our cloud environment (Azure), partnering with platform engineering on secure configuration, reviewing and remediating vulnerabilities, identity and network controls, posture management, and logging and detection. * Strengthen endpoint and identity controls across a global, remote workforce: least privilege, phishing-resistant MFA, and privileged access controls. * Support detection and response, partnering with our DFIR and MDR relationships and helping mature toward a proactive posture. * Address AI security risks (prompt injection, data poisoning, model and agent governance) and help keep AI controls ahead of adoption. Cross-functional Leadership and Program Ownership * Take ownership of large, loosely defined initiatives and drive them from problem framing to operationalized program. * Work closely with senior leadership across the firm, bringing structure to ambiguity and sequencing work against risk. * Surface risk early, challenge assumptions, and communicate clearly to both technical teams and senior stakeholders. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)