Lead Cybersecurity Engineer

Fundment
Greater London, UK
19 days ago
Apply on www.collegerecruiter.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Kubernetes Security Microsoft Windows Bash Shell Cloud Computing Cloud Computing Security Cyber Security Identity and Access Management Python (Programming Language) Windows PowerShell Systems Development Life Cycle Phishing Zero Trust Network Access
+10 more
Software Engineering Software Vulnerability Management Google Cloud Cloud Monitoring Amazon Virtual Private Cloud (VPC) Microsoft InTune Information Technology Terraform Network Server Vulnerability Analysis

Job description

We are looking for a Lead Cybersecurity Engineer to play a critical role in designing, implementing, and continuously improving the security of our cloud and IT infrastructure across a fast-growing fintech platform.

This is a hands-on technical role focused on securing our cloud infrastructure and user endpoints. Working closely with the Head of IT Infrastructure, you will translate security strategy and policies into scalable, automated technical controls that support secure-by-design principles and regulatory compliance.

You will be responsible for strengthening our cybersecurity posture, implementing security automation, securing identity and access management, and embedding security throughout our infrastructure and software delivery lifecycle., * Implement and maintain cloud security controls across our Google Cloud Platform (GCP) environment, ensuring services are secure, resilient, and aligned with security best practices.

  • Design, implement, and continuously improve cloud security architecture, including identity, networking, data protection, and workload security.
  • Implement and manage GCP security capabilities including IAM, VPC Service Controls, Identity-Aware Proxy (IAP), and Security Command Center.
  • Implement and maintain security controls within CI/CD pipelines, including IaC validation, vulnerability scanning, secret detection, and compliance checks.
  • Develop and maintain Infrastructure as Code using Terraform.
  • Work with engineering teams to embed security by design into application development.
  • Perform security architecture reviews, threat modelling, and technical risk assessments.
  • Continuously improve cloud and infrastructure security monitoring, detection, and automation.

Identity & Endpoint Security

  • Secure and manage Microsoft 365, Entra ID, and Intune environments using MFA, Conditional Access, PIM, device compliance, and least-privilege access.
  • Drive the implementation of Zero Trust security principles across cloud infrastructure, corporate systems, endpoints, and identity platforms.
  • Support and optimise MDR/EDR technologies.

Security Operations & Incident Response

  • Support vulnerability management and remediation.
  • Maintain vulnerability management processes.
  • Act as a technical escalation point during security incidents.

Compliance & Governance

  • Support cybersecurity certification, compliance, and audit requirements, including SOC 2 and ISO 27001.
  • Support audits by providing technical evidence.
  • Ensure controls align with regulatory and organisational requirements.

Requirements

  • 5-8+ years in cloud security engineering or infrastructure security.
  • Email security, phishing protection, and user security awareness.
  • Experience implementing and managing identity and access management solutions, including SSO, MFA, and privileged access controls.
  • Vulnerability management across cloud infrastructure, servers, and endpoints.
  • Understanding of SOC 2 and/or ISO 27001 controls, audits, and compliance processes.
  • Networking, cloud, and IT infrastructure security.
  • Zero Trust and cloud security architecture knowledge.
  • MDR/EDR and cloud monitoring.
  • FinTech or Financial Services experience.Strong hands-on GCP security experience.
  • Strong Microsoft 365, Entra ID and Intune security experience.
  • Exposure Container security, GKE and Cloud Run.
  • Python, PowerShell or Bash automation., * A degree in Cybersecurity, Computer Science, Information Technology, or a related discipline is advantageous.
  • Relevant industry certifications (desirable), such as CISSP, CISM, Google Professional Cloud Security Engineer, or equivalent cloud security certifications.

Benefits & conditions

  • Be part of a modern, inclusive, high-trust engineering culture
  • Take ownership and ship code that directly improves client outcomes
  • Work with a smart, friendly team that values balance, growth, and support
  • Pension 6% employer contribution, minimum 2% employee contribution.
  • BUPA Private Health Insurance - fully paid for by the company, for you and your immediate family.
  • Medicash Cashplan - fully paid for by the company, for you and your immediate family.
  • Travel insurance - fully paid for by the company, for you and your immediate family.
  • Life Assurance - 4 x base salary.
  • Employee Assistance Programme
  • 28 days annual leave plus bank holidays.
  • Paid compassionate leave - up to 5 days per year.
  • Enhanced paternity/maternity/adoption leave - 16 weeks at full pay after 12 months of service.
  • Jury service - 10 days at full pay.
  • Hybrid working arrangements - 3 days per week in the Fitzrovia office.

About the company

Fundment is a fast-growing wealth infrastructure company, building on our success in transforming the £3 trillion UK wealth management market with our cutting-edge digital investment system. We are passionate about revolutionising the investment experience for financial advisers and their clients by combining innovative proprietary technology with exceptional customer service.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.collegerecruiter.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker · World Congress 2022

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

54 sec

Interpreting complex terminal commands safely using external explanation utilities

Dan Cranney Dan Cranney +2 · LIVE

2:32 min

Overview of Terraform and Terraform Cloud features

Devlin Duldulao · LIVE

Videos

See all

Related articles

See all