HireFT
Browse JobsHow it worksPricingAboutSuccess Stories
    Back to jobs
    IN

    Insignis

    Financial Services

    Senior Engineering Manager, Security

    London, United KingdomOn-SiteFull-timePosted 1mo ago
    View all jobs

    Job description

    We are a fast-growing FinTech company looking for a talented and enthusiastic engineer to join our team. We are expanding, making this a perfect position if you would like to have a significant impact on our company’s growth and develop your role and career as the business evolves. You will join a team where your ideas will be welcomed and valued.

    This is a senior individual contributor and leadership role. You will report to the CTO, with a functional dotted line to the Head of Compliance. You will work closely with engineering, compliance, and risk functions, and represent security at board level. You will be the architect of a security culture that is rigorous, pragmatic, and commercially aware. The role will be hands on at the outset.

    Role responsibilities

    Security strategy & governance:

    • Own the information security strategy, aligned to FCA requirements, ISO 27001, and the firm’s risk appetite.
    • Chair the Information Security Working Group; prepare materials for the board and Insignis Risk Committee.
    • Lead the ISO 27001 programme, including ongoing audit readiness and continual improvement.
    • Maintain and evolve the ISMS, risk register, and security policy suite.
    • Represent security in regulatory engagements, including FCA supervisory requests and third-party due diligence.

    Technical security & architecture:

    • Define and enforce the security architecture across our Azure-native, Kubernetes-based platform.
    • Govern security controls across the full stack: Kafka, .NET/C#, Vue.js, Kong API Gateway, Auth0, and Salesforce.
    • Lead threat modelling, penetration testing, and vulnerability management programmes.
    • Own identity and access management strategy, including Entra ID, Auth0, and partner federation.
    • Drive security engineering best practices within product and platform teams.
    • Build and govern security for AI and machine-learning systems — covering model and data governance, defences against prompt injection and model abuse, and safe adoption of generative-AI tooling across the business.
    • Lead the firm's quantum-safe transition to post-quantum cryptography — maintaining a cryptographic inventory, assessing exposure, and planning a crypto-agile migration to NIST-standardised PQC algorithms.

    Compliance & regulatory:

    • Ensure security controls meet FCA SYSC obligations, SYSC 15A operational risk requirements and ISO27001 standard.
    • Work closely with the Head of Compliance on regulatory horizon scanning, security-related policy obligations, and audit responses.
    • Partner with the DPO on data governance and breach notification obligations.
    • Manage third-party and supply chain security risk, including critical outsourcing oversight.

    Incident management & operations:

    • Own the security incident response plan; lead major incident management for cyber events.
    • Operate and improve security monitoring, SIEM, and alerting across the Azure estate.
    • Run the security awareness and training programme for all ~180 staff.
    • Manage relationships with external SOC, MSSP, and specialist security partners.

    Requirements

    Essential:

    • Demonstrable experience leading information security in a regulated financial services or fintech environment.
    • Strong working knowledge of FCA regulatory requirements (SYSC, operational resilience).
    • Hands-on familiarity with cloud-native security on Azure (Entra ID, Defender, Sentinel, Key Vault, Policy).
    • Proven delivery of ISO 27001 certification or equivalent ISMS framework.
    • Ability to translate technical risk into board-level narrative clearly and credibly.
    • Experience partnering with engineering teams — you are comfortable in a technical conversation and a risk committee meeting.
    • CISM, CISSP, or equivalent professional qualification (or demonstrable equivalent experience).

    Desirable:

    • Familiarity with API security patterns (Kong, OAuth 2.0, OIDC) and modern identity architectures.
    • Background in or strong exposure to software engineering — understanding of SDLC security, threat modelling, and DevSecOps.
    • Experience managing a security team and developing talent toward senior positions.
    • Familiarity with Kafka-backed event architectures and the security considerations they introduce.
    • Awareness of AI and machine-learning security risks and emerging AI governance frameworks (e.g. NIST AI RMF, ISO/IEC 42001).
    • Understanding of post-quantum cryptography and quantum-safe migration and crypto-agility planning.

    Benefits

    • 25 days holiday (exc. Bank holidays)
    • 5% Pension contributions
    • Private medical insurance with Vitality
    • Health cash Plan offering contributions to dental, optical and much more
    • Enhanced Parental Leave
    • Cycle to Work Scheme
    • Monthly team lunches, quarterly company socials

    Working pattern

    • Hybrid working pattern in London office, 3 days in the office (Tuesday to Thursday), 2 days remote.

    Job details are sourced from the employer's original posting.

    Open job posting
    IN

    About the company

    Insignis

    Insignis is a digital asset management company.

    View all Insignis jobs
    Industry
    Financial Services
    Open roles
    6

    Interested in this role?

    Apply with HireFT

    Free to start — no card required.

    Your fit

    How well do you match?

    Sign in to see how your résumé lines up with this role.