# Engineering Manager, Security

[Insignisassetmanagement](https://gurify.com/jobs?q=Insignisassetmanagement) · london · Posted 4 days ago

[Engineering Manager](https://gurify.com/jobs/engineering-manager)

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://job-boards.eu.greenhouse.io/insignisassetmanagement/jobs/4955499101`)

## Job description

We are a fast-growing FinTech company looking for a talented and enthusiastic engineer to join our team. We are expanding, making this a perfect position if you would like to have a significant impact on our company’s growth and develop your role and career as the business evolves. You will join a team where your ideas will be welcomed and valued.

This is a senior individual contributor and leadership role. You will report to the CTO, with a functional dotted line to the Head of Compliance. You will work closely with engineering, compliance, and risk functions, and represent security at board level. You will be the architect of a security culture that is rigorous, pragmatic, and commercially aware. The role will be hands on at the outset.

### Role responsibilities

### Security strategy & governance:

- Own the information security strategy, aligned to FCA requirements, ISO 27001, and the firm’s risk appetite.

- Chair the Information Security Working Group; prepare materials for the board and Insignis Risk Committee.

- Lead the ISO 27001 programme, including ongoing audit readiness and continual improvement.

- Maintain and evolve the ISMS, risk register, and security policy suite.

- Represent security in regulatory engagements, including FCA supervisory requests and third-party due diligence.

### Technical security & architecture:

- Define and enforce the security architecture across our Azure-native, Kubernetes-based platform.

- Govern security controls across the full stack: Kafka, .NET/C#, Vue.js, Kong API Gateway, Auth0, and Salesforce.

- Lead threat modelling, penetration testing, and vulnerability management programmes.

- Own identity and access management strategy, including Entra ID, Auth0, and partner federation.

- Drive security engineering best practices within product and platform teams.

- Build and govern security for AI and machine-learning systems — covering model and data governance, defences against prompt injection and model abuse, and safe adoption of generative-AI tooling across the business.

- Lead the firm's quantum-safe transition to post-quantum cryptography — maintaining a cryptographic inventory, assessing exposure, and planning a crypto-agile migration to NIST-standardised PQC algorithms.

### Compliance & regulatory:

- Ensure security controls meet FCA SYSC obligations, SYSC 15A operational risk requirements and ISO27001 standard.

- Work closely with the Head of Compliance on regulatory horizon scanning, security-related policy obligations, and audit responses.

- Partner with the DPO on data governance and breach notification obligations.

- Manage third-party and supply chain security risk, including critical outsourcing oversight.

### Incident management & operations:

- Own the security incident response plan; lead major incident management for cyber events.

- Operate and improve security monitoring, SIEM, and alerting across the Azure estate.

- Run the security awareness and training programme for all ~180 staff.

- Manage relationships with external SOC, MSSP, and specialist security partners.

##

### Requirements

### Essential:

- Demonstrable experience leading information security in a regulated financial services or fintech environment.

- Strong working knowledge of FCA regulatory requirements (SYSC, operational resilience).

- Hands-on familiarity with cloud-native security on Azure (Entra ID, Defender, Sentinel, Key Vault, Policy).

- Proven delivery of ISO 27001 certification or equivalent ISMS framework.

- Ability to translate technical risk into board-level narrative clearly and credibly.

- Experience partnering with engineering teams — you are comfortable in a technical conversation and a risk committee meeting.

- CISM, CISSP, or equivalent professional qualification (or demonstrable equivalent experience).

### Desirable:

- Familiarity with API security patterns (Kong, OAuth 2.0, OIDC) and modern identity architectures.

- Background in or strong exposure to software engineering — understanding of SDLC security, threat modelling, and DevSecOps.

- Experience managing a security team and developing talent toward senior positions.

- Familiarity with Kafka-backed event architectures and the security considerations they introduce.

- Awareness of AI and machine-learning security risks and emerging AI governance frameworks (e.g. NIST AI RMF, ISO/IEC 42001).

- Understanding of post-quantum cryptography and quantum-safe migration and crypto-agility planning.

### Benefits

- 25 days holiday (exc. Bank holidays)

- 5% Pension contributions

- Private medical insurance with Vitality

- Health cash Plan offering contributions to dental, optical and much more

- Enhanced Parental Leave

- Cycle to Work Scheme

- Monthly team lunches, quarterly company socials

### Working pattern

- Hybrid working pattern in London office, 3 days in the office (Tuesday to Thursday), 2 days remote.

**Live in Insignisassetmanagement’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- BJ [Engineering Manager - AI Payments App](https://gurify.com/job/engineering-manager-ai-payments-app-at-bjak-81b1ec240d37) Bjak · United Kingdom · last week
- BJ [Engineering Manager](https://gurify.com/job/engineering-manager-at-bjak-8294655ae76a) Bjak · United Kingdom · last week
- DA [Pre-sales Engineering Manager (Retail & CPG)](https://gurify.com/job/pre-sales-engineering-manager-retail-cpg-at-databricks-ba6a8c6dc6b0) Databricks · London, United Kingdom · last week
- BJ [Engineering Manager - Stock Trading App](https://gurify.com/job/engineering-manager-stock-trading-app-at-bjak-cb0e33073b6f) Bjak · United Kingdom · last week
- BJ [Engineering Manager - Wealth Management App](https://gurify.com/job/engineering-manager-wealth-management-app-at-bjak-3a698495bbb4) Bjak · United Kingdom · last week
- BJ [Engineering Manager - AI-Native Email App](https://gurify.com/job/engineering-manager-ai-native-email-app-at-bjak-ff967cbd044a) Bjak · United Kingdom · last week

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Engineering Manager, Security","description":"\u003Cp\u003EWe are a fast-growing FinTech company looking for a talented and enthusiastic engineer to join our team. We are expanding, making this a perfect position if you would like to have a significant impact on our company\u2019s growth and develop your role and career as the business evolves. You will join a team where your ideas will be welcomed and valued.\u003C/p\u003E\u003Cp\u003EThis is a senior individual contributor and leadership role. You will report to the CTO, with a functional dotted line to the Head of Compliance. You will work closely with engineering, compliance, and risk functions, and represent security at board level. You will be the architect of a security culture that is rigorous, pragmatic, and commercially aware. The role will be hands on at the outset.\u003C/p\u003E\u003Ch3\u003ERole responsibilities\u003C/h3\u003E\u003Ch3\u003ESecurity strategy \u0026amp; governance:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EOwn the information security strategy, aligned to FCA requirements, ISO 27001, and the firm\u2019s risk appetite.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EChair the Information Security Working Group; prepare materials for the board and Insignis Risk Committee.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ELead the ISO 27001 programme, including ongoing audit readiness and continual improvement.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EMaintain and evolve the ISMS, risk register, and security policy suite.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ERepresent security in regulatory engagements, including FCA supervisory requests and third-party due diligence.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ETechnical security \u0026amp; architecture:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EDefine and enforce the security architecture across our Azure-native, Kubernetes-based platform.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EGovern security controls across the full stack: Kafka, .NET/C#, Vue.js, Kong API Gateway, Auth0, and Salesforce.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ELead threat modelling, penetration testing, and vulnerability management programmes.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EOwn identity and access management strategy, including Entra ID, Auth0, and partner federation.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDrive security engineering best practices within product and platform teams.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild and govern security for AI and machine-learning systems \u2014 covering model and data governance, defences against prompt injection and model abuse, and safe adoption of generative-AI tooling across the business.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ELead the firm\u0026#39;s quantum-safe transition to post-quantum cryptography \u2014 maintaining a cryptographic inventory, assessing exposure, and planning a crypto-agile migration to NIST-standardised PQC algorithms.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ECompliance \u0026amp; regulatory:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EEnsure security controls meet FCA SYSC obligations, SYSC 15A operational risk requirements and ISO27001 standard.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWork closely with the Head of Compliance on regulatory horizon scanning, security-related policy obligations, and audit responses.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPartner with the DPO on data governance and breach notification obligations.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EManage third-party and supply chain security risk, including critical outsourcing oversight.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EIncident management \u0026amp; operations:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EOwn the security incident response plan; lead major incident management for cyber events.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EOperate and improve security monitoring, SIEM, and alerting across the Azure estate.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ERun the security awareness and training programme for all ~180 staff.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EManage relationships with external SOC, MSSP, and specialist security partners.\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003E##\u003C/p\u003E\u003Ch3\u003ERequirements\u003C/h3\u003E\u003Ch3\u003EEssential:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EDemonstrable experience leading information security in a regulated financial services or fintech environment.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong working knowledge of FCA regulatory requirements (SYSC, operational resilience).\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHands-on familiarity with cloud-native security on Azure (Entra ID, Defender, Sentinel, Key Vault, Policy).\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EProven delivery of ISO 27001 certification or equivalent ISMS framework.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAbility to translate technical risk into board-level narrative clearly and credibly.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience partnering with engineering teams \u2014 you are comfortable in a technical conversation and a risk committee meeting.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECISM, CISSP, or equivalent professional qualification (or demonstrable equivalent experience).\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EDesirable:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EFamiliarity with API security patterns (Kong, OAuth 2.0, OIDC) and modern identity architectures.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBackground in or strong exposure to software engineering \u2014 understanding of SDLC security, threat modelling, and DevSecOps.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience managing a security team and developing talent toward senior positions.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFamiliarity with Kafka-backed event architectures and the security considerations they introduce.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAwareness of AI and machine-learning security risks and emerging AI governance frameworks (e.g. NIST AI RMF, ISO/IEC 42001).\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EUnderstanding of post-quantum cryptography and quantum-safe migration and crypto-agility planning.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EBenefits\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003E25 days holiday (exc. Bank holidays)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003E5% Pension contributions\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPrivate medical insurance with Vitality\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHealth cash Plan offering contributions to dental, optical and much more\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EEnhanced Parental Leave\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECycle to Work Scheme\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EMonthly team lunches, quarterly company socials\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EWorking pattern\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EHybrid working pattern in London office, 3 days in the office (Tuesday to Thursday), 2 days remote.\u003C/li\u003E\u003C/ul\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"engineering-manager-security-at-insignisassetmanagement-1de25d895cde"},"url":"https://gurify.com/job/engineering-manager-security-at-insignisassetmanagement-1de25d895cde","datePosted":"2026-08-21","validThrough":"2026-10-09T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Insignisassetmanagement","sameAs":"https://job-boards.eu.greenhouse.io/insignisassetmanagement"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"GB","addressLocality":"london"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"United Kingdom","item":"https://gurify.com/jobs/united-kingdom"},{"@type":"ListItem","position":3,"name":"Engineering Manager, Security","item":"https://gurify.com/job/engineering-manager-security-at-insignisassetmanagement-1de25d895cde"}]}
```
