Enable job alerts via email!

Lead Cybersecurity Engineer

Ardanis

United Kingdom

On-site

GBP 80,000 - 120,000

Full time

Today
Be an early applicant

Job summary

A leading finance technology firm seeks a Lead Security Engineer to define and oversee enterprise security strategies. The role involves compliance with frameworks like ISO 27001, executing security initiatives, and mentoring teams. The ideal candidate has extensive cloud security experience and strong leadership skills, aiming to enhance security posture globally.

Benefits

Continuous learning opportunities
Travel expenses covered

Qualifications

  • Extensive experience leading enterprise security programs, including various compliance frameworks.
  • Proven track record in planning, executing, and delivering compliance projects end-to-end.
  • Expertise in cloud security operations including IAM, network security, and encryption.

Responsibilities

  • Define and implement security strategies aligned with compliance frameworks.
  • Lead projects for ISO 27001 and other regulatory compliance.
  • Conduct threat modeling and risk assessments.

Skills

Cloud security architecture
ISO 27001
Risk assessment
Mentoring
Threat modeling
Vulnerability management
CI/CD security integration

Education

CISSP, CISM, CISA or cloud security certifications

Tools

AWS
Azure
GCP
SIEM
SOAR
Job description

At Ardanis we are seeking a Lead Security Engineer to define, implement, and oversee the enterprise security strategy across platforms, cloud infrastructure, and products. This is a hands-on leadership role with accountability for driving ISO 27001 and equivalent compliance programs, embedding secure-by-design principles, and ensuring resilience against advanced threats. You will lead complex security initiatives across engineering, DevOps, and product teams, providing technical guidance, threat intelligence, and strategic advice. Your work will encompass security architecture, operational security, incident response, DevSecOps practices, and compliance, impacting the security posture of the organization globally.

Responsibilities
  • Define and implement enterprise-wide security strategies and frameworks aligned with ISO 27001, SOC 2, NIST CSF, PCI DSS, GDPR, and CIS Controls.
  • Lead ISO 27001 and other regulatory compliance projects end-to-end, including audits, gap analysis, and remediation.
  • Conduct threat modeling (STRIDE, DREAD) and risk assessments for systems, processes, and cloud environments.
  • Oversee incident response, vulnerability management, penetration testing, and red/blue/purple team exercises.
  • Design and implement security architecture for multi-cloud and hybrid environments (AWS, Azure, GCP).
  • Integrate security into CI/CD pipelines, including SAST/DAST, IaC hardening, container and Kubernetes security.
  • Implement automated compliance and security testing at scale.
  • Develop and maintain information assurance policies, standards, and control frameworks.
  • Mentor and guide security teams and cross-functional stakeholders, fostering a proactive security culture.
  • Advise on adoption of emerging technologies and secure operational practices.
  • Communicate complex security concepts to technical and executive audiences.
  • Extensive experience leading enterprise security programs, including ISO 27001, SOC 2, GDPR, PCI DSS, or equivalent frameworks.
  • Proven track record in planning, executing, and delivering compliance projects end-to-end.
  • Expertise in cloud security architecture and operations (AWS, Azure, GCP) including IAM, network security, encryption, and monitoring.
  • Deep knowledge of threat modeling, risk assessment, vulnerability management, penetration testing, and incident response.
  • Hands-on experience with DevSecOps practices: CI/CD security integration, automated testing, IaC hardening (Terraform, CloudFormation), container and Kubernetes security.
  • Familiarity with SIEM, SOAR, CSPM, CWPP, and advanced security monitoring tools.
  • Strong leadership, mentoring, and stakeholder management capabilities.
  • Excellent communication skills, able to translate complex security topics for technical and non-technical audiences.
  • Willingness to travel to the UK ~1x per quarter, with expenses covered.
  • Commitment to continuous learning and staying ahead of emerging threats.

Nice to Have

  • Experience with red/blue/purple team exercises and adversary simulation frameworks.
  • Exposure to serverless and microservices security best practices.
  • Prior experience in financial services or SaaS environments.
  • Certifications such as CISSP, CISM, CISA, or cloud security certifications (AWS, Azure, GCP).

Join us and take a leading role in shaping the future of secure, cloud-native finance technology, where your expertise will directly impact our systems, products, and global customer trust!

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.