Information Security Engineer
A leading investment firm is looking to hire an experienced Information Security Engineer to play a key role in strengthening and evolving its security function. This position offers a blend of hands-on technical security, security assurance, risk management, and governance, making it ideal for someone who enjoys operating across both engineering and GRC disciplines. You'll work closely with technology teams, auditors, compliance, legal, and business stakeholders to assess security controls, drive remediation efforts, and help shape the firm's overall security strategy.
Key Responsibilities
- Lead and support internal and external security audits, regulatory reviews, client due diligence exercises, and security assessments.
- Evaluate the effectiveness of security controls across infrastructure, cloud, identity, endpoint security, vulnerability management, monitoring, and data protection.
- Manage audit findings, risk treatment plans, control deficiencies, and remediation activities through to completion.
- Conduct security and technology risk assessments, documenting risks, mitigations, and improvement initiatives.
- Act as a trusted advisor to technical and business teams on security controls, regulatory requirements, and best practices.
- Provide oversight of security processes including IAM, incident response, vulnerability management, cloud security, and security monitoring.
- Develop and deliver reporting on security posture, audit activity, control effectiveness, and material risks.
- Identify opportunities to improve security processes, tooling, automation, and reporting capabilities.
- Serve as a key point of contact for auditors, assessors, and other assurance stakeholders.
What we are looking for
- 5+ years of experience within Information Security, Security Engineering, Security Operations, Technology Risk, Security Assurance, or a related field.
- Strong understanding of enterprise security domains including:
- Identity & Access Management (IAM)
- Vulnerability Management
- Endpoint Security
- Cloud Security
- Logging & Monitoring
- Incident Management
- Data Protection
- Experience supporting audits, regulatory assessments, security reviews, or assurance programmes.
- Working knowledge of security frameworks such as ISO 27001, NIST CSF, NIST 800-53, or CIS Controls.
- Ability to assess technical controls and translate security requirements into practical, business-aligned solutions.
- Strong stakeholder management and communication skills, with the confidence to challenge where required.
- Financial services, asset management, hedge fund, banking, or other regulated industry experience.
- Experience with security tooling including SIEM, EDR, cloud security, vulnerability management, identity platforms, and GRC tools.
- Familiarity with UK financial services regulatory and operational resilience requirements.
- Professional certifications such as CISSP, CISM, CISA, CRISC, or ISO 27001 Lead Auditor/Implementer
FAQs
Congratulations, we understand that taking the time to apply is a big step. When you apply, your details go directly to the consultant who is sourcing talent. Due to demand, we may not get back to all applicants that have applied. However, we always keep your resume and details on file so when we see similar roles or see skillsets that drive growth in organizations, we will always reach out to discuss opportunities.
Yes. Even if this role isn’t a perfect match, applying allows us to understand your expertise and ambitions, ensuring you're on our radar for the right opportunity when it arises.
We also work in several ways, firstly we advertise our roles available on our site, however, often due to confidentiality we may not post all. We also work with clients who are more focused on skills and understanding what is required to future-proof their business.Â
That's why we recommend registering your resume so you can be considered for roles that have yet to be created.Â
Yes, we help with resume and interview preparation. From customized support on how to optimize your resume to interview preparation and compensation negotiations, we advocate for you throughout your next career move.
