Lead Engineer - Infrastructure & Cyber Security

Broaden

Greater London

Hybrid

GBP 108,000 - 132,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Bonus

Job summary

Broaden is recruiting a Lead Engineer – Infrastructure & Cyber Security for its London hybrid operations. You will own and rebuild the Cloud security pillar, working directly with the Group CTO to define a scalable Zero Trust platform and to integrate acquired environments into secure cloud landing zones.

The role requires hands-on expertise in Azure, Entra ID, Defender, Sentinel, and Terraform, plus experience managing external delivery partners and end-to-end security architecture.

Qualifications

  • Hands-on engineering capabilities in cloud-native environments.
  • Experience shipping and running production systems in cloud-native setups.
  • Security/compliance delivered via code and platform architecture; FCA-regulated exposure is a plus.

Responsibilities

  • Own the password-less destination and secure the perimeter with Entra ID P2, FIDO2 keys, and Conditional Access policies.
  • Architect and manage the Azure tenant, subscriptions, and landing zones; migrate on-prem to cloud services.
  • Oversee endpoint compute with Intune, MAM-first approach, and MDM enrollment; support AVD/AppStreaming as needed.
  • Direct the security stack (Defender XDR and Sentinel) and own detection engineering and SOC partnerships.
  • Implement infrastructure in Terraform with drift detection and Azure Policy guardrails.
  • Own total cost of ownership for global infrastructure and security; optimize using tagging and auto-suspension.
  • Demonstrate hands-on mastery of Microsoft security, identity, and Azure stacks (Entra ID, Intune, Defender, Purview, Sentinel, Terraform).
  • Drive cloud consumption as an engineering problem to optimize rather than control costs.

Skills

Azure
Terraform
Entra ID
Defender
Sentinel
Intune
PIM
FIDO2
Conditional Access

Tools

Azure SQL
App Service
Functions
MAM
MDM
AVD
AppStreaming
Azure Policy

Job description

Lead Engineer – Infrastructure & Cyber Security | Global Insurance Group | London (Hybrid) | up to £120K + bonus
About the Company

Our client is a fast-scaling, global commercial insurance group growing rapidly both organically and through international acquisitions across the UK, Europe, Australia, and Asia. They are completely rebuilding their technology operating model around a modern, identity-centric, cloud-native architecture on the Microsoft stack.

Operating in an incredibly fast-paced, high-growth scale-up environment, they champion absolute autonomy and radical ownership. They move dynamically from start-up flexibility to scale-up discipline, meaning they listen well, move fast, and empower their people to execute without layers of bureaucracy or hand-holding. They are anti-bureaucracy but pro-governance, meaning regulatory compliance is delivered as code and automated platform controls rather than committees and paperwork. If a candidate is exceptionally bright, thrives in a rapid-iteration culture, and wants the freedom to define a roadmap and see their work directly move the business forward, they will find a massive opportunity here.

About the Role

The client is completely re-engineering their tech division and hiring three bright, peer Lead Engineers to own and rebuild three brand-new pillars in the business. Reporting directly to the Group CTO with no layers of management in between, the successful candidate will own the Infrastructure & Cyber Security pillar.

This is a hands-on building role, not a legacy people-management position. You will lead a small internal team - which is set to grow - and gain massive operational leverage by directing high-performing external delivery partners. The mandate is to take the "Frictionless Fortress" blueprint - a highly scalable, Zero Trust infrastructure design - and build, run, and keep it honest as the group continues to expand. You will also own the global M&A integration playbook, systematically pulling acquired environments into the secure cloud landing-zone pattern within a strict Day 1 / Day 30 / Day 90 cadence.

Key Responsibilities
  • Own the password-less destination, securing the perimeter utilizing Entra ID P2, FIDO2 passkeys, Conditional Access policies, PIM, and Identity Protection.
  • Architect and manage the Azure tenant, subscriptions, and landing zones PaaS-first; migrate remaining legacy physical office infrastructure into managed cloud services (Azure SQL, App Service, Functions).
  • Oversee the endpoint compute model using Intune, configured MAM-first, with MDM enrollment and AVD/AppStreaming where required.
  • Direct the security stack (Defender XDR and Sentinel) and own detection engineering, playbooks, and the quality of outcomes delivered by the 24/7 external SOC partner.
  • Implement infrastructure entirely in Terraform, establishing drift detection, Azure Policy guardrails, and compliance controls directly within deployment gates.
  • Hold the total cost of ownership for global infrastructure and security, using tagging, rightsizing, and auto-suspension to drive down per-head costs as the business scales.
  • Deep, current, hands‑on-keyboard command of the Microsoft security, identity, and Azure platform stacks (Entra ID, Intune, Defender, Purview, Sentinel, Terraform).
  • Real Azure platform engineering experience, with the technical scars to prove they can transition physical assets to cloud PaaS without just recreating legacy VMs.
  • Treats cloud consumption as an engineering problem to instrument and optimize, rather than a bill to accept.
  • Measures success by what they build and how they upskill the wider team and partners, rather than hoarding knowledge or building a personal fiefdom.
Qualifications & Experience
  • Genuinely strong, hands-on engineering capabilities. They are hiring for trajectory and technical instinct rather than arbitrary years of tenure.
  • Proven track record of shipping and running production systems in a cloud-native environment.
  • Experience working within an FCA-regulated or structured environment, demonstrating that security and compliance can be delivered cleanly through code and platform architecture.
  • Desirable: Prior experience wrangling acquired IT estates, executing data center exits, or managing multi-jurisdiction data residency guardrails.
  • Note: Certifications (SC-300, SC-200, AZ-104, AZ-305) are valued as evidence of depth, but are not used as a hiring gate.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Junior Cyber Security Engineer
Junior Cyber Security Engineer

Broaden • Greater London

Hybrid
GBP 90,000 - 120,000
Azure Technical Lead
Azure Technical Lead

Arthur Recruitment • Greater London

Hybrid
Infrastructure Team Lead
Infrastructure Team Lead

Quant Capital • Hounslow

Hybrid
GBP 54,000 - 90,000
Cyber Security Engineer
Cyber Security Engineer

Big Red Recruitment • Greater London

Hybrid
GBP 60,000 - 75,000
Profit-share scheme
Flexible hybrid working
Senior Security Engineer
Senior Security Engineer

Sanderson • Greater London

On-site
GBP 70,000 - 90,000
IT Infrastructure Security Engineer
IT Infrastructure Security Engineer

Tria • City Of London

Hybrid
GBP 60,000 - 65,000
Lead Security Architect - Microsoft Security specialist
Lead Security Architect - Microsoft Security specialist

Anson McCade • United Kingdom

Hybrid
GBP 90,000 - 130,000
Performance bonus
Lead Security Engineer
Lead Security Engineer

iO Associates • Greater London

Hybrid
GBP 46,000 - 77,000
Security Engineer
Security Engineer

Burns Sheehan • Greater London

Hybrid
GBP 75,000 - 90,000
Infrastructure Lead
Infrastructure Lead

Michael Page • Sale

Hybrid
GBP 55,000 - 70,000
Performance-related bonus
Hybrid working model
Ownership of infrastructure and cloud
+1