Lead Cybersecurity Engineer

Skills & Experience

  • Job roles: Security Engineer

  • Experience level: Lead

  • Tech stack/tooling used: Cyber Security, Cloud Security, Network Security, GCP, Threat Detection, Python, PowerShell, Bash, Azure

  • Core skills considered: Cyber Security, Cloud Security, Network Security, GCP, Azure

  • Other skills considered: Python, PowerShell, Bash

Logistics

  • Employment type: Permanent

  • Remote working: Hybrid (up to 2 remote days p/w)

  • Visa sponsorship: Not available

Job Description

Fundment is a fast-growing wealth infrastructure company, building on our success in transforming the £3 trillion UK wealth management market with our cutting-edge digital investment system. We are passionate about revolutionising the investment experience for financial advisers and their clients by combining innovative proprietary technology with exceptional customer service.

About the Role

We are looking for a Lead Cybersecurity Engineer to play a critical role in designing, implementing, and continuously improving the security of our cloud and IT infrastructure across a fast-growing fintech platform.

This is a hands-on technical role focused on securing our cloud infrastructure and user endpoints. Working closely with the Head of IT Infrastructure, you will translate security strategy and policies into scalable, automated technical controls that support secure-by-design principles and regulatory compliance.

You will be responsible for strengthening our cybersecurity posture, implementing security automation, securing identity and access management, and embedding security throughout our infrastructure and software delivery lifecycle.

Key Responsibilities

Cloud & Infrastructure Security

  • Implement and maintain cloud security controls across our Google Cloud Platform (GCP) environment, ensuring services are secure, resilient, and aligned with security best practices.

  • Design, implement, and continuously improve cloud security architecture, including identity, networking, data protection, and workload security.

  • Implement and manage GCP security capabilities including IAM, VPC Service Controls, Identity-Aware Proxy (IAP), and Security Command Center.

  • Implement and maintain security controls within CI/CD pipelines, including IaC validation, vulnerability scanning, secret detection, and compliance checks.

  • Develop and maintain Infrastructure as Code using Terraform.

  • Work with engineering teams to embed security by design into application development.

  • Perform security architecture reviews, threat modelling, and technical risk assessments.

  • Continuously improve cloud and infrastructure security monitoring, detection, and automation.

Identity & Endpoint Security

  • Secure and manage Microsoft 365, Entra ID, and Intune environments using MFA, Conditional Access, PIM, device compliance, and least-privilege access.

  • Drive the implementation of Zero Trust security principles across cloud infrastructure, corporate systems, endpoints, and identity platforms.

  • Support and optimise MDR/EDR technologies.

Security Operations & Incident Response

  • Support vulnerability management and remediation.

  • Maintain vulnerability management processes.

  • Act as a technical escalation point during security incidents.

Compliance & Governance

  • Support cybersecurity certification, compliance, and audit requirements, including SOC 2 and ISO 27001.

  • Support audits by providing technical evidence.

  • Ensure controls align with regulatory and organisational requirements.

Skills & Experience

Essential

  • 5–8+ years in cloud security engineering or infrastructure security.

  • Email security, phishing protection, and user security awareness.

  • Experience implementing and managing identity and access management solutions, including SSO, MFA, and privileged access controls.

  • Vulnerability management across cloud infrastructure, servers, and endpoints.

  • Understanding of SOC 2 and/or ISO 27001 controls, audits, and compliance processes.

  • Networking, cloud, and IT infrastructure security.

  • Zero Trust and cloud security architecture knowledge.

  • MDR/EDR and cloud monitoring.

Desirable

  • FinTech or Financial Services experience.

  • Strong hands-on GCP security experience.

  • Strong Microsoft 365, Entra ID and Intune security experience.

  • Exposure Container security, GKE and Cloud Run.

  • Python, PowerShell or Bash automation.

Qualifications & Certifications

  • A degree in Cybersecurity, Computer Science, Information Technology, or a related discipline is advantageous.

  • Relevant industry certifications (desirable), such as CISSP, CISM, Google Professional Cloud Security Engineer, or equivalent cloud security certifications.

Company Benefits

  • Be part of a modern, inclusive, high-trust engineering culture

  • Take ownership and ship code that directly improves client outcomes

  • Work with a smart, friendly team that values balance, growth, and support

  • Pension 6% employer contribution, minimum 2% employee contribution.

  • BUPA Private Health Insurance – fully paid for by the company, for you and your immediate family.

  • Medicash Cashplan – fully paid for by the company, for you and your immediate family.

  • Travel insurance – fully paid for by the company, for you and your immediate family.

  • Life Assurance – 4 x base salary.

  • Employee Assistance Programme

  • 28 days annual leave plus bank holidays.

  • Paid compassionate leave – up to 5 days per year.

  • Enhanced paternity/maternity/adoption leave – 16 weeks at full pay after 12 months of service.

  • Jury service – 10 days at full pay.

  • Hybrid working arrangements – 3 days per week in the Fitzrovia office.

  • Coaching&Counselling sessions

  • Training Budget

  • Annual pay review

  • Annual training budget