Engineering Manager, Security

Insignis

Greater London

Hybrid

GBP 120,000 - 180,000

Full time

6 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

25 days holiday (exc. Bank holidays)
5% Pension contributions
Private medical insurance with Vitaliy
Health cash Plan offering dental/opt/?
Enhanced Parental Leave
Cycle to Work Scheme
Monthly team lunches

Job summary

Insignis is seeking a senior security-focused engineer to lead information security strategy and governance in a FinTech setting. You will report to the CTO, while partnering with Compliance, Risk, and engineering to embed a rigorous, pragmatic security culture.

You will architect security across Azure-native, Kubernetes platforms, oversee ISO27001, risk registers, and third-party security. This is a high-impact role with board exposure and hands-on responsibilities.

Qualifications

  • Demonstrated information security leadership in a regulated financial services or fintech environment.
  • Strong knowledge of FCA requirements (SYSC, operational resilience).
  • Hands-on Azure cloud security experience (Entra ID, Defender, Sentinel, Key Vault).
  • Proven delivery of ISO27001 certification or equivalent ISMS framework.
  • Ability to translate technical risk into clear board-level narratives.
  • Experience partnering with engineering teams in technical and risk discussions.
  • CISM or CISSP (or equivalent) certification.

Responsibilities

  • Own the information security strategy aligned to FCA requirements and risk appetite.
  • Chair Information Security Working Group and prepare board materials.
  • Lead ISO 27001 programme, audits, and continual improvement.
  • Maintain ISMS, risk register, and security policy suite.
  • Represent security in regulatory engagements and third-party due diligence.
  • Define and enforce security architecture across Azure-native, Kubernetes platform.
  • Lead threat modelling, penetration testing, and vulnerability management.
  • Own IAM strategy including Entra ID, Auth0, and federation.
  • Drive security engineering best practices within product and platform teams.
  • Govern AI/ML security and crypto- agile migration to PQC standards.
  • Incident response planning and major cyber-incident management.
  • Oversee security monitoring, SIEM, and staff awareness.

Skills

Security leadership
Regulated fintech
Azure security
DevSecOps
Risk management
Board communication

Education

CISM or CISSP certification

Tools

Azure
Entra ID
Defender
Sentinel
Key Vault

Job description

We are a fast-growing FinTech company looking for a talented and enthusiastic engineer to join our team. We are expanding, making this a perfect position if you would like to have a significant impact on our company’s growth and develop your role and career as the business evolves. You will join a team where your ideas will be welcomed and valued. This is a senior individual contributor and leadership role. You will report to the CTO, with a functional dotted line to the Head of Compliance. You will work closely with engineering, compliance, and risk functions, and represent security at board level. You will be the architect of a security culture that is rigorous, pragmatic, and commercially aware. The role will be hands on at the outset.

Role responsibilities
Security Strategy & Governance
  • Own the information security strategy, aligned to FCA requirements, ISO 27001, and the firm’s risk appetite.
  • Chair the Information Security Working Group; prepare materials for the board and Insignis Risk Committee.
  • Lead the ISO 27001 programme, including ongoing audit readiness and continual improvement.
  • Maintain and evolve the ISMS, risk register, and security policy suite.
  • Represent security in regulatory engagements, including FCA supervisory requests and third‑party due diligence.
Technical Security & Architecture
  • Define and enforce the security architecture across our Azure-native, Kubernetes-based platform.
  • Govern security controls across the full stack: Kafka, .NET/C#, Vue.js, Kong API Gateway, Auth0, and Salesforce.
  • Lead threat modelling, penetration testing, and vulnerability management programmes.
  • Own identity and access management strategy, including Entra ID, Auth0, and partner federation.
  • Drive security engineering best practices within product and platform teams.
  • Build and govern security for AI and machine‑learning systems — covering model and data governance, defences against prompt injection and model abuse, and safe adoption of generative‑AI tooling across the business.
  • Lead the firm’s quantum‑safe transition to post‑quantum cryptography — maintaining a cryptographic inventory, assessing exposure, and planning a crypto‑agile migration to NIST‑standardised PQC algorithms.
Compliance & Regulatory
  • Ensure security controls meet FCA SYSC obligations, SYSC 15A operational risk requirements and ISO27001 standard.
  • Work closely with the Head of Compliance on regulatory horizon scanning, security‑related policy obligations, and audit responses.
  • Partner with the DPO on data governance and breach notification obligations.
  • Manage third‑party and supply chain security risk, including critical outsourcing oversight.
Incident Management & Operations
  • Own the security incident response plan; lead major incident management for cyber events.
  • Operate and improve security monitoring, SIEM, and alerting across the Azure estate.
  • Run the security awareness and training programme for all ~180 staff.
  • Manage relationships with external SOC, MSSP, and specialist security partners.
Requirements
  • Demonstrable experience leading information security in a regulated financial services or fintech environment.
  • Strong working knowledge of FCA regulatory requirements (SYSC, operational resilience).
  • Hands‑on familiarity with cloud‑native security on Azure (Entra ID, Defender, Sentinel, Key Vault, Policy).
  • Proven delivery of ISO 27001 certification or equivalent ISMS framework.
  • Ability to translate technical risk into board‑level narrative clearly and credibly.
  • Experience partnering with engineering teams — you are comfortable in a technical conversation and a risk committee meeting.
  • CISM, CISSP, or equivalent professional qualification (or demonstrable equivalent experience).
Desirable
  • Familiarity with API security patterns (Kong, OAuth 2.0, OIDC) and modern identity architectures.
  • Background in or strong exposure to software engineering — understanding of SDLC security, threat modelling, and DevSecOps.
  • Experience managing a security team and developing talent toward senior positions.
  • Familiarity with Kafka‑backed event architectures and the security considerations they introduce.
  • Awareness of AI and machine‑learning security risks and emerging AI governance frameworks (e.g. NIST AI RMF, ISO/IEC 42001).
  • Understanding of post‑quantum cryptography and quantum‑safe migration and crypto‑agility planning.
Benefits
  • 25 days holiday (exc. Bank holidays)
  • 5% Pension contributions
  • Private medical insurance with Vitality
  • Health cash Plan offering contributions to dental, optical and much more
  • Enhanced Parental Leave
  • Cycle to Work Scheme
  • Monthly team lunches, quarterly company socials
Working pattern
  • Hybrid working pattern in London office, 3 days in the office (Tuesday to Thursday), 2 days remote.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Engineering Manager, Security
Engineering Manager, Security

Insignis Cash • Greater London

Hybrid
GBP 120,000 - 180,000
25 days holiday
5% Pension contributions
Private medical insurance with Vitaliy
+5
Principal Information Security Engineer
Principal Information Security Engineer

AJ Bell Business Solutions Limited • Salford

Hybrid
GBP 90,000 - 120,000
Competitive salary
Holidays 26–31 days
Pension matched 7%
+5
Information Security Manager - Fintech - Hybrid
Information Security Manager - Fintech - Hybrid

Wealth Dynamix • Greater London

Hybrid
GBP 90,000 - 110,000
Information Security Manager - Fintech - Hybrid
Information Security Manager - Fintech - Hybrid

Wealth Dynamix • Greater London

Hybrid
GBP 90,000 - 120,000
Senior Security Operations Engineer New London
Senior Security Operations Engineer New London

Risk Ledger • Greater London

Hybrid
GBP 90,000 - 135,000
EMI equity
Healthcare AXA
Hybrid working policy
+3
Information Security Manager
Information Security Manager

United States Digital Space LLC • Greater London

Hybrid
GBP 80,000 - 110,000
Unlimited Annual Leave Policy
Private healthcare and dental
Enhanced parental leave
+3
Principal Information Security Engineer
Principal Information Security Engineer

Manchester Digital • Manchester

On-site
GBP 70,000 - 95,000
26 days holiday
Pension 7% matched
Discretionary bonus
+6
Principal Information Security Engineer
Principal Information Security Engineer

AJ Bell Management Limited • United Kingdom

On-site
GBP 70,000 - 90,000
26 days holiday, increasing with service
7% Pension with matched contributions
Discretionary bonus scheme
+2
Senior Security Operations Engineer
Senior Security Operations Engineer

Risk Ledger • Greater London

Hybrid
GBP 90,000 - 100,000
Competitive salary
Equity package
Private pension
+5
Senior Security & Compliance Engineer
Senior Security & Compliance Engineer

XYZ Reality • Greater London

Hybrid
GBP 90,000 - 130,000
Hybrid work from London office
Private healthcare
25 days annual leave
+1