Lead Security Engineer

CFC

City Of London

On-site

GBP 110,000 - 170,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

CFC in London is seeking a Lead Security Engineer to shape and deliver security across networks, devices, identity and access. This senior individual-contributor role requires practical, hands-on delivery and strong technical judgement to translate risks into effective controls.

You'll design identity and access controls, automate security policies, and guide architecture across cloud, on-prem and AI-enabled environments while collaborating with technology teams in a low-ego, open culture in

Qualifications

  • Extensive experience designing security across networks, devices, identity and access.
  • Strong knowledge of network segmentation and cloud security.
  • Hands-on IAM and privileged-access controls across enterprise platforms.

Responsibilities

  • Design, implement and operate automated security governance and controls.
  • Architect reusable security services for enterprise systems with governance and detection.
  • Design and implement access controls for human and non-human identities.
  • Strengthen authentication, authorisation, secrets management and audit.
  • Automate security policies across workflows and endpoints, including AI usage.
  • Lead cross-functional security design and threat-modelling activities.

Skills

Security architecture
Identity and access management
Threat modelling
Automation
Policy-as-code
Privilege management
Network segmentation
Cloud security

Job description

Lead Security Engineer

Department: CISO

Employment Type: Permanent - Full Time

Location: UK - London

Reporting To: Simon Goldsmith

Description

Technology is at the heart of everything we do at CFC. We're looking for a Lead Security Engineer to shape and deliver security across our networks, devices, identity and access environment.

This is a senior individual-contributor role for an engineer who combines strong technical judgement with sustained, hands‑on delivery. You'll solve complex, cross-functional security challenges, turning requirements and identified risks into practical, effective controls.

You'll design how people, devices, services and non-human identities securely access our systems and data. Working across our technology teams, you'll create reusable security architectures, implement and automate controls, diagnose weaknesses and ensure that security remains effective as our technology environment evolves.

At CFC, people are trusted to take ownership, challenge how things are done and deliver meaningful change. You'll have the opportunity to influence security architecture across the business while working in an open, supportive and low-ego environment where ideas are welcomed

About the role
  • Design, implement and operate highly automated security governance and controls across network, device, identity and access systems.
  • Architect reusable security services for enterprise systems, integrating governance, protection, detection, response and recovery capabilities.
  • Design and implement access controls for human and non-human identities, including service and agentic AI identities.
  • Strengthen authentication, authorisation, secrets management, audit and privilege segmentation across systems and services.
  • Implement scalable access-control models and access policy-as-code, enabling teams to provision access consistently and securely.
  • Embed security governance and controls into code, cloud and AI architectures, including network segmentation and identity controls.
  • Diagnose and remediate identity, infrastructure and access‑control weaknesses, identifying root causes and implementing controls that prevent recurrence.
  • Lead cross-functional security design and threat-modelling activities, translating risks into layered and prioritised engineering improvements.
  • Automate security policies and guardrails across workflows and endpoints, including the appropriate use of AI augmentation.
  • Act as a technical authority for network, device and identity security, advising technology teams on complex architecture and access‑control decisions.
About you

We're looking for an experienced security engineer who combines principal-level judgement with a practical, hands‑on approach.You'll bring:

  • Deep experience designing and engineering security across enterprise networks, devices, identity and access.
  • A strong understanding of network segmentation, identity controls and security architecture across cloud systems.
  • Hands‑on experience implementing identity and access management and privileged‑access controls across enterprise identity platforms.
  • Strong knowledge of authentication, authorisation, secrets management, audit, least privilege and privilege segmentation.
  • Experience designing access for human and non‑human identities, including addressing excessive permissions, exposed secrets and access‑governance weaknesses.
  • Experience implementing role‑based or attribute‑based access control, automated policy enforcement or access policy‑as‑code at scale.
  • The ability to create effective security architectures and navigate trade‑offs between security, accessibility, decentralisation and performance.
  • The ability to automate controls through code, policy and workflow automation.Strong technical judgement, with the ability to influence cross‑functional technology teams through clear and credible architectural reasoning.

You'll enjoy taking ownership of complex problems, challenging established approaches and working collaboratively to make security effective by default. This is an opportunity to make a visible impact in a business that gives people the trust and responsibility to shape what comes next.

Core Values

Love what you do: We show up each day ready to take on the world. Our passion and intensity set us apart and makes the difference to our colleagues, customers, brokers and carriers.

Challenge everything: We're never afraid to question the way that things are done and we constantly challenge ourselves and others to makes things better.

Have fun, be good: Insurance is a serious business, but we don't take ourselves too seriously. We make it fun to work at CFC, we welcome all viewpoints, and we treat everyone how we would expect to be treated.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Security Engineer
Lead Security Engineer

CFC Underwriting • Greater London

On-site
GBP 110,000 - 150,000
Lead Security Engineer
Lead Security Engineer

CFC • Greater London

Hybrid
GBP 90,000 - 130,000
Principal Product Security Engineer
Principal Product Security Engineer

CFC • City Of London

On-site
GBP 140,000 - 190,000
Principal Product Security Engineer
Principal Product Security Engineer

CFC Underwriting • Greater London

On-site
GBP 110,000 - 150,000
Staff Security Engineer
Staff Security Engineer

CFC • Greater London

On-site
GBP 90,000 - 140,000
Staff Security Engineer
Staff Security Engineer

CFC Underwriting • Greater London

On-site
GBP 90,000 - 130,000
Lead Security Engineer: Identity & Access Architect
Lead Security Engineer: Identity & Access Architect

CFC Underwriting • Greater London

On-site
GBP 110,000 - 150,000
Software Engineer
Software Engineer

CFC • Greater London

On-site
GBP 65,000 - 90,000
Lead Security Engineer
Lead Security Engineer

Ocho People • Belfast City District

On-site
GBP 90,000 - 120,000
Share options
Hybrid/Remote Belfast
35 days annual leave inc stats
+2
Lead Security Engineer
Lead Security Engineer

Eeze • Greater London

On-site
GBP 80,000 - 100,000
26 days paid holiday
Hybrid Working
Pension and Life Assurance
+2