Lead Cybersecurity Engineer

Fundment

Greater London

Hybrid

GBP 110,000 - 150,000

Full time

23 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Pension 6% employer contribution
Private Health Insurance
Life Assurance – 4x base salary
28 days annual leave
Hybrid work – 3 days in office
Employee Assistance Programme
Jury service pay

Job summary

Fundment is seeking a Lead Cybersecurity Engineer to design, implement, and continuously improve security for our cloud and IT infrastructure in a fast-growing fintech platform.

This hands-on role focuses on securing cloud infrastructure and endpoints, translating strategy into scalable controls that align with secure-by-design principles and regulatory requirements.

Qualifications

  • 5–8+ years in cloud security engineering or infrastructure security.
  • Experience with email security, phishing protection and user security awareness.
  • Experience implementing IAM, SSO, MFA and privileged access controls.
  • Vulnerability management across cloud, servers and endpoints.
  • Understanding of SOC 2 / ISO 27001 controls and audits.
  • Strong networking, cloud and IT infrastructure security knowledge.
  • Zero Trust and cloud security architecture experience.
  • MDR/EDR and cloud monitoring experience.

Responsibilities

  • Implement and maintain cloud security controls across GCP environment.
  • Design and improve cloud security architecture: identity, networking, data protection.
  • Manage IAM, VPC Service Controls, IAP, and Security Command Center.
  • Maintain security controls in CI/CD pipelines (IaC validation, scans, secrets).
  • Develop Infrastructure as Code using Terraform.
  • Embed security by design into application development with engineering teams.
  • Conduct threat modelling, architecture reviews and risk assessments.
  • Improve cloud security monitoring, detection and automation.

Skills

Cloud security
GCP security
IAM
Vulnerability management
Zero Trust
MDR/EDR
Security automation
Compliance

Education

Bachelor's degree in Cybersecurity or related field

Tools

Terraform
Security Command Center
IAP
VPC Service Controls
CI/CD security tooling
GKE / Kubernetes security

Job description

Fundment is a fast-growing wealth infrastructure company, building on our success in transforming the £3 trillion UK wealth management market with our cutting-edge digital investment system. We are passionate about revolutionising the investment experience for financial advisers and their clients by combining innovative proprietary technology with exceptional customer service.

About the Role

We are looking for a Lead Cybersecurity Engineer to play a critical role in designing, implementing, and continuously improving the security of our cloud and IT infrastructure across a fast-growing fintech platform.

This is a hands‑on technical role focused on securing our cloud infrastructure and user endpoints. Working closely with the Head of IT Infrastructure, you will translate security strategy and policies into scalable, automated technical controls that support secure‑by‑design principles and regulatory compliance.

You will be responsible for strengthening our cybersecurity posture, implementing security automation, securing identity and access management, and embedding security throughout our infrastructure and software delivery lifecycle.

Key Responsibilities
  • Implement and maintain cloud security controls across our Google Cloud Platform (GCP) environment, ensuring services are secure, resilient, and aligned with security best practices.
  • Design, implement, and continuously improve cloud security architecture, including identity, networking, data protection, and workload security.
  • Implement and manage GCP security capabilities including IAM, VPC Service Controls, Identity‑Aware Proxy (IAP), and Security Command Center.
  • Implement and maintain security controls within CI/CD pipelines, including IaC validation, vulnerability scanning, secret detection, and compliance checks.
  • Develop and maintain Infrastructure as Code using Terraform.
  • Work with engineering teams to embed security by design into application development.
  • Perform security architecture reviews, threat modelling, and technical risk assessments.
  • Continuously improve cloud and infrastructure security monitoring, detection, and automation.
Identity & Endpoint Security
  • Secure and manage Microsoft 365, Entra ID, and Intune environments using MFA, Conditional Access, PIM, device compliance, and least‑privilege access.
  • Drive the implementation of Zero Trust security principles across cloud infrastructure, corporate systems, endpoints, and identity platforms.
  • Support and optimise MDR/EDR technologies.
Security Operations & Incident Response
  • Support vulnerability management and remediation.
  • Maintain vulnerability management processes.
  • Act as a technical escalation point during security incidents.
Compliance & Governance
  • Support cybersecurity certification, compliance, and audit requirements, including SOC 2 and ISO 27001.
  • Support audits by providing technical evidence.
  • Ensure controls align with regulatory and organisational requirements.
Skills & Experience
  • 5–8+ years in cloud security engineering or infrastructure security.
  • Email security, phishing protection, and user security awareness.
  • Experience implementing and managing identity and access management solutions, including SSO, MFA, and privileged access controls.
  • Vulnerability management across cloud infrastructure, servers, and endpoints.
  • Understanding of SOC 2 and/or ISO 27001 controls, audits, and compliance processes.
  • Networking, cloud, and IT infrastructure security.
  • Zero Trust and cloud security architecture knowledge.
  • MDR/EDR and cloud monitoring.
  • FinTech or Financial Services experience.
  • Strong hands‑on GCP security experience.
  • Strong Microsoft 365, Entra ID and Intune security experience.
  • Exposure Container security, GKE and Cloud Run.
  • Python, PowerShell or Bash automation.
Qualifications & Certifications
  • A degree in Cybersecurity, Computer Science, Information Technology, or a related discipline is advantageous.
  • Relevant industry certifications (desirable), such as CISSP, CISM, Google Professional Cloud Security Engineer, or equivalent cloud security certifications.
Company Benefits
  • Be part of a modern, inclusive, high-trust engineering culture
  • Take ownership and ship code that directly improves client outcomes
  • Work with a smart, friendly team that values balance, growth, and support
  • Pension 6% employer contribution, minimum 2% employee contribution.
  • BUPA Private Health Insurance – fully paid for by the company, for you and your immediate family.
  • Medicash Cashplan – fully paid for by the company, for you and your immediate family.
  • Travel insurance – fully paid for by the company, for you and your immediate family.
  • Life Assurance – 4 x base salary.
  • Employee Assistance Programme
  • 28 days annual leave plus bank holidays.
  • Paid compassionate leave – up to 5 days per year.
  • Enhanced paternity/maternity/adoption leave – 16 weeks at full pay after 12 months of service.
  • Jury service – 10 days at full pay.
  • Hybrid working arrangements – 3 days per week in the Fitzrovia office.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Security Engineer
Lead Security Engineer

Eeze • Greater London

Hybrid
GBP 80,000 - 100,000
26 days paid holiday
Hybrid Working
Pension and Life Assurance
+2
Engineering Manager, Security
Engineering Manager, Security

Insignis • Greater London

Hybrid
GBP 120,000 - 180,000
25 days holiday
Pension 5%
Private medical insurance
+4
Bio-Cybersecurity Specialist
Bio-Cybersecurity Specialist

Yugal Tech Academy • Greater London

Hybrid
GBP 60,000 - 80,000
Company discretionary bonus
Pension contributions
Staff share scheme
+3
Cybersecurity Engineer
Cybersecurity Engineer

Atlantic Talent Recruitment • Greater London

Hybrid
GBP 70,000 - 100,000
Hybrid working
Annual leave 26 days + public holidays
Birthday day off
+3
Lead Cyber Security Engineer
Lead Cyber Security Engineer

SThree • Glasgow

Hybrid
GBP 60,000 - 85,000
Hybrid working model
28 days holiday allowance
Private healthcare
Engineering Manager, Security
Engineering Manager, Security

Insignis Cash • Greater London

Hybrid
GBP 120,000 - 180,000
25 days holiday
5% Pension contributions
Private medical insurance with Vitaliy
+5
Head of Cyber Security and Productivity Solutions
Head of Cyber Security and Productivity Solutions

M+C Saatchi UK • Greater London

On-site
GBP 120,000 - 180,000
Cultural stimulation allowance – £250 per person per year
Half days off before bank holidays
Emergency care days for dependants
+5
Senior Security Operations Engineer New London
Senior Security Operations Engineer New London

Risk Ledger • Greater London

On-site
GBP 90,000 - 135,000
EMI equity
Healthcare AXA
Hybrid working policy
+3
Cloud Security
Cloud Security

PA Consulting • City of Westminster

Hybrid
GBP 60,000 - 85,000
Health and lifestyle perks
25 days annual leave
Generous pension scheme
+2
Managing Consultant - FS - Digital Trust and Cyber Security
Managing Consultant - FS - Digital Trust and Cyber Security

PA Consulting • City of Westminster

On-site
GBP 70,000 - 100,000
Health and lifestyle perks
25 days annual leave
Generous pension scheme
+2