Lead Security Engineer

CFC Underwriting

Greater London

On-site

GBP 110,000 - 150,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Lead Security Engineer role at CFC Underwriting in London. You will shape and deliver security across networks, devices, identity and access. You will lead with principal judgement and hands-on delivery, designing reusable security architectures and automating controls.

The role involves cross-functional collaboration, threat modelling, and embedding security into code, cloud and AI architectures. You will act as a technical authority on identity and access management, strengthening

Qualifications

  • Deep experience designing and engineering security across enterprise networks, devices, identity and access.
  • Strong knowledge of authentication, authorisation, secrets management and least privilege concepts.
  • Experience designing access for human and non-human identities at scale.

Responsibilities

  • Design, implement and operate automated security governance across network, device, identity and access systems.
  • Architect reusable security services for enterprise systems and integrate governance across layers.
  • Lead cross-functional security design and threat-modelling activities.
  • Automate security policies and guardrails across workflows and endpoints, including AI considerations.

Skills

Security architecture
Identity access
Network security
Cloud security
Automation
Threat modelling
Access controls

Job description

Lead Security Engineer

Department: CISO

Employment Type: Permanent - Full Time

Location: UK - London

Reporting To: Simon Goldsmith

Description

Technology is at the heart of everything we do at CFC. We’re looking for a Lead Security Engineer to shape and deliver security across our networks, devices, identity and access environment.

This is a senior individual-contributor role for an engineer who combines strong technical judgement with sustained, hands‑on delivery. You’ll solve complex, cross-functional security challenges, turning requirements and identified risks into practical, effective controls.

You’ll design how people, devices, services and non-human identities securely access our systems and data. Working across our technology teams, you’ll create reusable security architectures, implement and automate controls, diagnose weaknesses and ensure that security remains effective as our technology environment evolves.

At CFC, people are trusted to take ownership, challenge how things are done and deliver meaningful change. You’ll have the opportunity to influence security architecture across the business while working in an open, supportive and low-ego environment where ideas are welcomed

About the role
  • Design, implement and operate highly automated security governance and controls across network, device, identity and access systems.
  • Architect reusable security services for enterprise systems, integrating governance, protection, detection, response and recovery capabilities.
  • Design and implement access controls for human and non-human identities, including service and agentic AI identities.
  • Strengthen authentication, authorisation, secrets management, audit and privilege segmentation across systems and services.
  • Implement scalable access-control models and access policy-as-code, enabling teams to provision access consistently and securely.
  • Embed security governance and controls into code, cloud and AI architectures, including network segmentation and identity controls.
  • Diagnose and remediate identity, infrastructure and access-control weaknesses, identifying root causes and implementing controls that prevent recurrence.
  • Lead cross-functional security design and threat-modelling activities, translating risks into layered and prioritised engineering improvements.
  • Automate security policies and guardrails across workflows and endpoints, including the appropriate use of AI augmentation.
  • Act as a technical authority for network, device and identity security, advising technology teams on complex architecture and access-control decisions.
About you

We’re looking for an experienced security engineer who combines principal-level judgement with a practical, hands‑on approach.You’ll bring:

  • Deep experience designing and engineering security across enterprise networks, devices, identity and access.
  • A strong understanding of network segmentation, identity controls and security architecture across cloud systems.
  • Hands‑on experience implementing identity and access management and privileged‑access controls across enterprise identity platforms.
  • Strong knowledge of authentication, authorisation, secrets management, audit, least privilege and privilege segmentation.
  • Experience designing access for human and non‑human identities, including addressing excessive permissions, exposed secrets and access‑governance weaknesses.
  • Experience implementing role‑based or attribute‑based access control, automated policy enforcement or access policy‑as‑code at scale.
  • The ability to create effective security architectures and navigate trade‑offs between security, accessibility, decentralisation and performance.
  • The ability to automate controls through code, policy and workflow automation.
  • Strong technical judgement, with the ability to influence cross‑functional technology teams through clear and credible architectural reasoning.

You’ll enjoy taking ownership of complex problems, challenging established approaches and working collaboratively to make security effective by default. This is an opportunity to make a visible impact in a business that gives people the trust and responsibility to shape what comes next.

Core Values

Love what you do:

We show up each day ready to take on the world. Our passion and intensity set us apart and makes the difference to our colleagues, customers, brokers and carriers.

Challenge everything:

We’re never afraid to question the way that things are done and we constantly challenge ourselves and others to makes things better.

Have fun, be good:

Insurance is a serious business, but we don’t take ourselves too seriously. We make it fun to work at CFC, we welcome all viewpoints, and we treat everyone how we would expect to be treated.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Security Engineer
Lead Security Engineer

CFC • City Of London

On-site
GBP 110,000 - 170,000
Lead Security Engineer
Lead Security Engineer

CFC • Greater London

Hybrid
GBP 90,000 - 130,000
Principal Product Security Engineer
Principal Product Security Engineer

CFC • City Of London

On-site
GBP 140,000 - 190,000
Principal Product Security Engineer
Principal Product Security Engineer

CFC Underwriting • Greater London

On-site
GBP 110,000 - 150,000
Staff Security Engineer
Staff Security Engineer

CFC • Greater London

On-site
GBP 90,000 - 140,000
Staff Security Engineer
Staff Security Engineer

CFC Underwriting • Greater London

On-site
GBP 90,000 - 130,000
Lead Security Engineer: Identity & Access Architect
Lead Security Engineer: Identity & Access Architect

CFC Underwriting • Greater London

On-site
GBP 110,000 - 150,000
Software Engineer
Software Engineer

CFC • Greater London

On-site
GBP 65,000 - 90,000
Lead Security Engineer
Lead Security Engineer

Ocho People • Belfast City District

On-site
GBP 90,000 - 120,000
Share options
Hybrid/Remote Belfast
35 days annual leave inc stats
+2
Lead Security Engineer
Lead Security Engineer

Eeze • Greater London

On-site
GBP 80,000 - 100,000
26 days paid holiday
Hybrid Working
Pension and Life Assurance
+2