Senior Security Engineer
HybridLondon, England, United Kingdom
Job Summary
Lead threat modeling, conduct security risk assessments, and drive design reviews to prioritize risks and enable pragmatic remediation across products and infrastructure. Partner with engineering to embed repeatable security workflows into existing processes, hardening cloud environments, supply chains, and identity controls while strengthening detection and response capabilities. Manage customer due-diligence and SOC 2 evidence gathering to keep compliance sustainable, and address AI security risks including prompt injection and data governance. Own large, ambiguous initiatives from problem framing to operationalized programs, surfacing early risks and communicating clearly to technical teams and senior stakeholders in a remote-first, highly regulated setting.
Required Qualifications
- 6+ years of hands-on security experience
- real depth in security risk management: threat modeling, risk assessments, and security design and architecture review
- governance, risk, and compliance work in practice, including audit and customer due-diligence support (SOC 2 or similar), and made it operational rather than just documented
- thrived in a startup or other small, fast-paced environment, owning large, ambiguous initiatives end-to-end with little scaffolding and shipping them
- working breadth across the control landscape: cloud security, supply-chain and vulnerability management, endpoint and identity, and detection and response
- comfortable in cloud environments (Azure preferred)
- CI/CD
- at least one scripting language (e.g. Python, Bash, PowerShell)
Desired Qualifications
- Have banking, fintech, or other regulated industry experience
- Use AI tooling fluently in your own day-to-day work and are eager to integrate it into security workflows as a force multiplier
- Have a bias toward automating repeatable security work — scripting, tooling, and process — to scale your impact
- Be familiar with AI and agentic security risks (prompt injection, data poisoning, model and agent governance)
- Have experience mapping security frameworks (NIST CSF, ISO 27001, OWASP, NIST AI RMF)
- Have hands-on exposure to detection and response, red-team, or pen-test work
- Have experience with our stack: Azure / Entra ID, GitHub Enterprise Cloud (GHAS, Actions, Dependabot), Sentinel, Zscaler, Intune, Vanta, and the Atlassian suite
- Hold relevant certifications (e.g. CISSP, CRISC, OSCP)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.