Job roles: Security Engineer
Experience level: Lead
Tech stack/tooling used: Cyber Security, Cloud Security, Network Security, GCP, Threat Detection, Python, PowerShell, Bash, Azure
Core skills considered: Cyber Security, Cloud Security, Network Security, GCP, Azure
Other skills considered: Python, PowerShell, Bash
Employment type: Permanent
Remote working: Hybrid (up to 2 remote days p/w)
Visa sponsorship: Not available
Fundment is a fast-growing wealth infrastructure company, building on our success in transforming the £3 trillion UK wealth management market with our cutting-edge digital investment system. We are passionate about revolutionising the investment experience for financial advisers and their clients by combining innovative proprietary technology with exceptional customer service.
We are looking for a Lead Cybersecurity Engineer to play a critical role in designing, implementing, and continuously improving the security of our cloud and IT infrastructure across a fast-growing fintech platform.
This is a hands-on technical role focused on securing our cloud infrastructure and user endpoints. Working closely with the Head of IT Infrastructure, you will translate security strategy and policies into scalable, automated technical controls that support secure-by-design principles and regulatory compliance.
You will be responsible for strengthening our cybersecurity posture, implementing security automation, securing identity and access management, and embedding security throughout our infrastructure and software delivery lifecycle.
Implement and maintain cloud security controls across our Google Cloud Platform (GCP) environment, ensuring services are secure, resilient, and aligned with security best practices.
Design, implement, and continuously improve cloud security architecture, including identity, networking, data protection, and workload security.
Implement and manage GCP security capabilities including IAM, VPC Service Controls, Identity-Aware Proxy (IAP), and Security Command Center.
Implement and maintain security controls within CI/CD pipelines, including IaC validation, vulnerability scanning, secret detection, and compliance checks.
Develop and maintain Infrastructure as Code using Terraform.
Work with engineering teams to embed security by design into application development.
Perform security architecture reviews, threat modelling, and technical risk assessments.
Continuously improve cloud and infrastructure security monitoring, detection, and automation.
Secure and manage Microsoft 365, Entra ID, and Intune environments using MFA, Conditional Access, PIM, device compliance, and least-privilege access.
Drive the implementation of Zero Trust security principles across cloud infrastructure, corporate systems, endpoints, and identity platforms.
Support and optimise MDR/EDR technologies.
Support vulnerability management and remediation.
Maintain vulnerability management processes.
Act as a technical escalation point during security incidents.
Support cybersecurity certification, compliance, and audit requirements, including SOC 2 and ISO 27001.
Support audits by providing technical evidence.
Ensure controls align with regulatory and organisational requirements.
5–8+ years in cloud security engineering or infrastructure security.
Email security, phishing protection, and user security awareness.
Experience implementing and managing identity and access management solutions, including SSO, MFA, and privileged access controls.
Vulnerability management across cloud infrastructure, servers, and endpoints.
Understanding of SOC 2 and/or ISO 27001 controls, audits, and compliance processes.
Networking, cloud, and IT infrastructure security.
Zero Trust and cloud security architecture knowledge.
MDR/EDR and cloud monitoring.
FinTech or Financial Services experience.
Strong hands-on GCP security experience.
Strong Microsoft 365, Entra ID and Intune security experience.
Exposure Container security, GKE and Cloud Run.
Python, PowerShell or Bash automation.
A degree in Cybersecurity, Computer Science, Information Technology, or a related discipline is advantageous.
Relevant industry certifications (desirable), such as CISSP, CISM, Google Professional Cloud Security Engineer, or equivalent cloud security certifications.
Be part of a modern, inclusive, high-trust engineering culture
Take ownership and ship code that directly improves client outcomes
Work with a smart, friendly team that values balance, growth, and support
Pension 6% employer contribution, minimum 2% employee contribution.
BUPA Private Health Insurance – fully paid for by the company, for you and your immediate family.
Medicash Cashplan – fully paid for by the company, for you and your immediate family.
Travel insurance – fully paid for by the company, for you and your immediate family.
Life Assurance – 4 x base salary.
Employee Assistance Programme
28 days annual leave plus bank holidays.
Paid compassionate leave – up to 5 days per year.
Enhanced paternity/maternity/adoption leave – 16 weeks at full pay after 12 months of service.
Jury service – 10 days at full pay.
Hybrid working arrangements – 3 days per week in the Fitzrovia office.
Coaching&Counselling sessions
Training Budget
Annual pay review
Annual training budget
The location your currently viewing doesn't match your previous selection or browser locale.