Senior Staff Information Security Engineer

NMI

Bristol

Hybrid

CAD 175,000 - 195,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Competitive salary + bonus
A remote first culture!
Flex PTO
Health, Dental and Vision Insurance
13 Paid Holidays
Company volunteer days

Job summary

NMI seeks a Senior Staff Information Security Engineer to shape security across a hybrid estate spanning AWS and on‑premises colocation facilities. You will lead security architecture, implement scalable controls, and partner with Engineering, Product, SRE, and Infrastructure to reduce risk while enabling delivery.

You will stay hands‑on while guiding complex security decisions, leading cross‑team initiatives, and elevating secure‑by‑design practices with reusable patterns and tooling.

Qualifications

  • Significant experience in security engineering, infrastructure security, cloud security, security architecture, or platform engineering.
  • Deep, hands‑on experience securing AWS environments.
  • Strong knowledge of AWS identity and access management, network architecture, account governance, encryption, logging, monitoring, secrets management, and workload protection.
  • Experience designing or securing on‑premises, data‑centre, or colocation‑hosted infrastructure.
  • Strong knowledge of enterprise networking, segmentation, firewalls, secure remote access, privileged administration, and hybrid connectivity.
  • Experience with infrastructure‑as‑code, CI/CD security, containerised environments, and cloud‑native platforms.
  • Demonstrated experience designing and implementing automated security controls and engineering solutions.
  • Proficiency with scripting or software development using Python, Go, or a comparable language.
  • Practical experience using AI‑assisted tooling to improve security engineering and operational workflows.
  • Experience leading complex initiatives across multiple engineering, infrastructure, or product teams.
  • Strong knowledge of security architecture, threat modelling, vulnerability management, detection, and incident response.

Responsibilities

  • Define and evolve security architecture across AWS and our colocation estate.
  • Establish secure reference architectures, engineering standards, and reusable control patterns.
  • Provide technical leadership for major infrastructure, platform, and product initiatives.
  • Identify systemic risks and lead practical, sustainable programmes to address them.
  • Engage early in the design of new products, platforms, services, and integrations.
  • Lead threat modelling, security architecture reviews, and technical risk assessments.
  • Translate security risks into clear, practical engineering recommendations.
  • Help teams adopt secure‑by‑design principles through reusable patterns, tooling, and documentation.
  • Design and implement security tooling, integrations, and automated controls.
  • Embed security capabilities into infrastructure provisioning, engineering workflows, and CI/CD pipelines.
  • Use AI-assisted tooling to improve scripting, detection development, alert analysis, vulnerability triage, threat modelling, and technical documentation.
  • Validate AI-generated outputs and ensure AI tools are used with appropriate controls for confidentiality, accuracy, access, and human oversight.
  • Provide technical direction for vulnerability and exposure management across AWS and on‑premises infrastructure.
  • Identify recurring patterns across incidents, penetration tests, vulnerabilities, and control assessments.
  • Act as a senior technical escalation point during significant security incidents.
  • Ensure investigations and lessons learned result in durable architectural and engineering improvements.
  • Lead complex security initiatives spanning multiple teams and planning cycles.
  • Mentor security engineers and provide guidance to engineers in adjacent teams.
  • Raise the standard of security architecture, automation, documentation, and technical decision‑making.
  • Communicate security risks and recommendations clearly to technical teams, product leaders, and senior stakeholders.

Skills

Security engineering
Cloud security
Security architecture
AWS security
Threat modelling
Platform engineering
Scripting (Python/Go)
CI/CD security
Automation & IaC
AI-assisted tooling

Tools

Kubernetes
CNAPP
CSPM
SIEM
EDR
WAF
Terraform
Policy-as-code

Job description

We are seeking a Senior Staff Information Security Engineer to help shape and advance security across our hybrid technology estate.


Our environment spans AWS and on-premises infrastructure hosted in colocation facilities. You will provide senior technical leadership across both environments, defining secure architecture patterns, building scalable controls, and partnering with Engineering, Product, SRE, and Infrastructure teams to reduce risk without creating unnecessary barriers to delivery.


This is a senior individual-contributor role. You will remain hands‑on while acting as a trusted technical authority for complex security architecture and engineering decisions. You will lead initiatives that cross teams and technologies, address systemic security challenges, and improve how security is designed and implemented across the organisation.


The role is primarily remote, with occasional in‑person responsibilities at our Bristol, UK office and, where necessary, our colocation facilities.


What You’ll Do


  • Define and evolve security architecture across AWS and our colocation estate.

  • Establish secure reference architectures, engineering standards, and reusable control patterns.

  • Provide technical leadership for major infrastructure, platform, and product initiatives.

  • Identify systemic risks and lead practical, sustainable programmes to address them.


Strengthen Cloud and Hybrid Security


  • Design and improve security across cloud accounts, networks, identities, workloads, and shared services.

  • Establish effective controls for identity and access management, segmentation, encryption, secrets, logging, monitoring, and workload protection.

  • Develop preventative guardrails through infrastructure-as-code, policy-as-code, automation, and cloud-native security services.

  • Improve consistency across the enterprise including cloud, on‑premises infrastructure, and the connectivity between them.


Partner with Engineering and Product


  • Engage early in the design of new products, platforms, services, and integrations.

  • Lead threat modelling, security architecture reviews, and technical risk assessments.

  • Translate security risks into clear, practical engineering recommendations.

  • Help teams adopt secure‑by‑design principles through reusable patterns, tooling, and documentation.


Build, Automate, and Apply AI


  • Design and implement security tooling, integrations, and automated controls.

  • Embed security capabilities into infrastructure provisioning, engineering workflows, and CI/CD pipelines.

  • Use AI-assisted tooling to improve scripting, detection development, alert analysis, vulnerability triage, threat modelling, and technical documentation.

  • Validate AI-generated outputs and ensure AI tools are used with appropriate controls for confidentiality, accuracy, access, and human oversight.


Improve Risk Reduction and Resilience


  • Provide technical direction for vulnerability and exposure management across AWS and on‑premises infrastructure.

  • Identify recurring patterns across incidents, penetration tests, vulnerabilities, and control assessments.

  • Act as a senior technical escalation point during significant security incidents.

  • Ensure investigations and lessons learned result in durable architectural and engineering improvements.


Provide Senior Technical Leadership


  • Lead complex security initiatives spanning multiple teams and planning cycles.

  • Mentor security engineers and provide guidance to engineers in adjacent teams.

  • Raise the standard of security architecture, automation, documentation, and technical decision‑making.

  • Communicate security risks and recommendations clearly to technical teams, product leaders, and senior stakeholders.


What You’ll Bring


  • Significant experience in security engineering, infrastructure security, cloud security, security architecture, or platform engineering.

  • Deep, hands‑on experience securing AWS environments.

  • Strong knowledge of AWS identity and access management, network architecture, account governance, encryption, logging, monitoring, secrets management, and workload protection.

  • Experience designing or securing on‑premises, data‑centre, or colocation‑hosted infrastructure.

  • Strong knowledge of enterprise networking, segmentation, firewalls, secure remote access, privileged administration, and hybrid connectivity.

  • Experience with infrastructure‑as‑code, CI/CD security, containerised environments, and cloud‑native platforms.

  • Demonstrated experience designing and implementing automated security controls and engineering solutions.

  • Proficiency with scripting or software development using Python, Go, or a comparable language.

  • Practical experience using AI‑assisted tooling to improve security engineering and operational workflows.

  • Experience leading complex initiatives across multiple engineering, infrastructure, or product teams.

  • Strong knowledge of security architecture, threat modelling, vulnerability management, detection, and incident response.

  • The ability to operate independently, navigate ambiguity, and influence decisions across technical and leadership audiences.


Desirable Experience


  • An advanced AWS certification in security, architecture, networking, or cloud engineering.

  • Experience in fintech, payments, SaaS, or another regulated technology environment.

  • Experience securing large or complex AWS multi‑account estates.

  • Experience with Kubernetes, container security, software supply‑chain security, and policy‑as‑code.

  • Experience with technologies such as CNAPP, CSPM, SIEM, EDR, DLP, WAF, vulnerability‑management, network‑security, or secrets‑management platforms.

  • Familiarity with PCI DSS, SOC 2, GDPR, NIST, or ISO 27001.

  • Experience supporting significant security incidents, penetration tests, audits, or customer security assessments.


As well as being a part of something exciting everyday, you will also receive the following benefits:


  • Competitive salary + bonus

  • A remote first culture!

  • Flex PTO

  • Health, Dental and Vision Insurance

  • 13 Paid Holidays
  • Company volunteer days


What we do!

NMI enables our partners with choice, and challenges the one-size-fits-all approach to payments. You've probably used NMI in the last 24 hours without even realizing it. We’re the platform that powers success for innovative tech created by SMBs, entrepreneurs and fintech startups. We’re creative problem solvers who help visionaries smash through boundaries and think beyond what’s possible so they can think about what’s next. But we’re not just built for the tech savvy. We democratize the latest payments technology so that everyone can realize the benefits of easy payments across the full spectrum of commerce. We’re all about enabling more payments in more ways and more places.


We believe that having a diverse group of employees strengthens both our work and our workplace. We’re focused on making NMI more diverse and welcoming with initiatives like having a dedicated Diversity, Equity & Inclusion action group, diversity goals for hiring, anonymized resume screening, affinity groups such as our Women’s network and LGBTQ+ Network, open forums for discussions on diversity and social justice, and measuring inclusion and belonging as part of our regular employee engagement surveys.


Equal Opportunity

NMI is committed to providing equal employment opportunity for all persons regardless of race, color, religion, sex, age, marital status, national origin, sexual orientation or sexual identity, genetic information, citizen status (except those that do not have the legal right to be employed in the United States), disability, military service, service member, veteran status, or any other basis protected by applicable law.


Please be aware that all offers of employment are made subject to receipt of satisfactory background and financial checks.


Attention job applicants: Please note that in compliance with the data protection regulations within your jurisdiction, any personal information submitted with your job application may be collected and used by NMI for the purpose of recruitment and employment‑related activities. By submitting your application, you acknowledge and provide explicit consent to the processing of your personal information as described in our privacy policy found on our website. For more information on how we process your information, please read our privacy policy here: https://www.nmi.com/legal/privacy-policy/


Salary Range, Depending On Experience

$175,000—$195,000 CAD

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Manager - Regulatory Compliance & Deputy MLRO, Canada
Senior Manager - Regulatory Compliance & Deputy MLRO, Canada

Nium • Montreal (administrative region)

Hybrid
CAD 90,000 - 130,000
Intermediate Full Stack Developer, Innovation Development
Intermediate Full Stack Developer, Innovation Development

Mnp • Calgary

On-site
CAD 90,000 - 130,000
Vacation time
4 paid personal days
Group pension plan 4% match
+1
Qualified Security Assessor (PCI-DSS)
Qualified Security Assessor (PCI-DSS)

MNP • Ottawa

On-site
CAD 95,000 - 120,000
Base pay
4 paid personal days
Group pension with 4% matching
+5
Qualified Security Assessor (PCI-DSS)
Qualified Security Assessor (PCI-DSS)

MNP • Toronto

On-site
CAD 95,000 - 120,000
Generous base pay
Vacation time
4 paid personal days
+7
Senior Manager - Regulatory Compliance & Deputy MLRO, Canada
Senior Manager - Regulatory Compliance & Deputy MLRO, Canada

Nium • Canada

Hybrid
CAD 140,000 - 200,000
Medical coverage
Employee assistance program
Flexible hybrid work (3 days in-office
+1
Information Security Engineer (Cloud Security Engineer) - 1 Year Contract
Information Security Engineer (Cloud Security Engineer) - 1 Year Contract

Numeris • Toronto

On-site
CAD 85,000 - 90,000
Health, Dental, Vision and Personal
Perkopolis discounts
Intermediate Full Stack Developer, Innovation Development
Intermediate Full Stack Developer, Innovation Development

Mnp Llp • Calgary

Hybrid
CAD 90,000 - 130,000
MyRewards@MNP
Diversity@MNP
Systems Engineer
Systems Engineer

Moneris • Toronto

Hybrid
CAD 100,000 - 142,000
Wellness Fridays
RRSP match
Flexible benefits
+5
Microsoft Defender Lead
Microsoft Defender Lead

MNP • Calgary

On-site
CAD 120,000 - 170,000
Senior Manager, Advanced Analytics
Senior Manager, Advanced Analytics

MNP • Ottawa

On-site
CAD 116,000 - 150,000
4 personal days
Group pension plan with 4% matching
Health and dental benefits
+1