Senior Application Security Engineer

McCabe & Barton

Greater London

On-site

GBP 90,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

McCabe & Barton seeks a Cyber Security Engineer to join the London office of a leading private equity-backed firm. You will strengthen cyber security controls across key platforms and infrastructure, driving triage, remediation governance, and threat detection in a fast-paced, regulated environment.

The role requires hands-on experience with SIEM, UEBA, EDR, and identity management technologies including Entra ID, Conditional Access, and FIDO2/WebAuthn, plus knowledge of software supply chain

Qualifications

  • Experience in Security Operations, Cyber Security Analysis, or Threat Analysis.
  • Experience in financial services, private equity, or another regulated environment.
  • Hands-on experience with SIEM, UEBA, EDR, and identity management technologies including Entra ID, Conditional Access, and FIDO2/WebAuthn.
  • Good understanding of application security vulnerabilities including deserialisation, IDOR, injection, and authorisation logic flaws.
  • Knowledge of SBOMs, Software Composition Analysis (SCA), and dependency management.
  • Understanding of DORA ICT risk obligations is desirable.
  • Self-motivated and capable of operating independently in a fast-paced, evolving environment.

Responsibilities

  • Drive triage and remediation governance for the AI-assisted code audit of proprietary products.
  • Support rollout of FIDO2/WebAuthn across all privileged accounts with access to proprietary systems and Entra admin roles.
  • Assist with third-party trust boundary reviews.
  • Maintain and enhance the emergency patching runbook for critical vulnerabilities (CVSS 9.0+).
  • Contribute to micro-segmentation of proprietary applications from general M365 workloads, including honeytoken deployment for early-warning threat detection.
  • Run continuous External Attack Surface Management (EASM) across the firm's external footprint and cross-reference findings weekly with the CMDB.
  • Support SIEM and UEBA enhancements, building detection logic around normal deal workflow behavioural baselines.

Skills

Security Operations
Cyber Security Analysis
Threat Analysis
Regulated environment
FIDO2/WebAuthn
Entra ID/Conditional Access
Identity management
SBOMs/SCA/Dependencies
DORA ICT risk

Tools

SIEM
UEBA
EDR
Entra ID

Job description

We are working with a leading private equity firm seeking a Cyber Security Engineer to join their London office. This is an exciting opportunity to join a fast-paced, highly regulated environment and play a key role in strengthening cyber security controls across critical business platforms and infrastructure.

Key Responsibilities
  • Drive triage and remediation governance for the AI-assisted code audit of proprietary products.
  • Support the rollout of FIDO2/WebAuthn across all privileged accounts with access to proprietary systems and Entra admin roles.
  • Assist with third-party trust boundary reviews.
  • Maintain and enhance the emergency patching runbook for critical vulnerabilities (CVSS 9.0+)
  • Contribute to the micro-segmentation of proprietary applications from general M365 workloads, including honeytoken deployment for early-warning threat detection.
  • Run continuous External Attack Surface Management (EASM) across the firm's external footprint and cross-reference findings weekly with the CMDB.
  • Support SIEM and UEBA enhancements, building detection logic around normal deal workflow behavioural baselines.
Skills & Experience
  • Previous experience within Security Operations, Cyber Security Analysis, or Threat Analysis.
  • Experience working within financial services, private equity, or another regulated environment
  • Hands-on experience with SIEM, UEBA, EDR, and identity management technologies including Entra ID, Conditional Access, and FIDO2/WebAuthn.
  • Good understanding of application security vulnerabilities including deserialisation, IDOR, injection, and authorisation logic flaws.
  • Working knowledge of software supply chain security practices, including SBOMs, Software Composition Analysis (SCA), and dependency management.
  • Understanding of DORA ICT risk obligations is desirable
  • Self-motivated and capable of operating independently within a fast-paced, evolving environment.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Operational Security Engineer
Senior Operational Security Engineer

Crown Agents Bank Ltd. • Greater London

On-site
GBP 70,000 - 90,000
Information Security Engineer - Boutique Hedge Fund - London
Information Security Engineer - Boutique Hedge Fund - London

Mondrian Alpha • Greater London

On-site
GBP 90,000 - 130,000
Senior Application Security Specialist
Senior Application Security Specialist

La Fosse • Greater London

Hybrid
Security Engineer
Security Engineer

Selby Jennings • City Of London

On-site
GBP 90,000 - 130,000
Application Security Engineer (Cyber)
Application Security Engineer (Cyber)

Source Technology Limited • Greater London

Hybrid
GBP 90,000 - 120,000
Senior Application Security Consultant
Senior Application Security Consultant

Salt • Greater London

Hybrid
GBP 90,000 - 120,000
Senior Security Engineer – Cloud-First Hedge Fund Scale-Up (London)
Senior Security Engineer – Cloud-First Hedge Fund Scale-Up (London)

Winston Fox • Greater London

On-site
GBP 90,000 - 140,000
Cyber Security Engineer for FinServ: EASM, SIEM, FIDO2
Cyber Security Engineer for FinServ: EASM, SIEM, FIDO2

McCabe & Barton • Greater London

On-site
GBP 90,000 - 120,000
Senior Application Security Engineer
Senior Application Security Engineer

Tec Partners Recruitment Ltd • City Of London

On-site
GBP 90,000 - 122,000
Senior Cyber Engineer
Senior Cyber Engineer

Cyber UK • Greater London

Hybrid
GBP 90,000 - 95,000
12% bonus
Private health insurance
Career progression plan
+1