Rodeo
Get started

Insignis

Engineering Manager, Security

London
Posted about 20 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

About the Role

We are a fast-growing FinTech company looking for a talented and enthusiastic engineer to join our team. We are expanding, making this a perfect position if you would like to have a significant impact on our company’s growth and develop your role and career as the business evolves. You will join a team where your ideas will be welcomed and valued.

This is a senior individual contributor and leadership role. You will report to the CTO, with a functional dotted line to the Head of Compliance. You will work closely with engineering, compliance, and risk functions, and represent security at board level. You will be the architect of a security culture that is rigorous, pragmatic, and commercially aware. The role will be hands-on at the outset.

Role Responsibilities

Security Strategy & Governance

  • Own the information security strategy, aligned to FCA requirements, ISO 27001, and the firm’s risk appetite.
  • Chair the Information Security Working Group; prepare materials for the board and Insignis Risk Committee.
  • Lead the ISO 27001 programme, including ongoing audit readiness and continual improvement.
  • Maintain and evolve the ISMS, risk register, and security policy suite.
  • Represent security in regulatory engagements, including FCA supervisory requests and third-party due diligence.

Technical Security & Architecture

  • Define and enforce the security architecture across our Azure-native, Kubernetes-based platform.
  • Govern security controls across the full stack: Kafka,.NET/C#, Vue.js, Kong API Gateway, Auth0, and Salesforce.
  • Lead threat modelling, penetration testing, and vulnerability management programmes.
  • Own identity and access management strategy, including Entra ID, Auth0, and partner federation.
  • Drive security engineering best practices within product and platform teams.
  • Build and govern security for AI and machine-learning systems — covering model and data governance, defences against prompt injection and model abuse, and safe adoption of generative-AI tooling across the business.
  • Lead the firm's quantum-safe transition to post-quantum cryptography — maintaining a cryptographic inventory, assessing exposure, and planning a crypto-agile migration to NIST-standardised PQC algorithms.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Compliance & Regulatory

  • Ensure security controls meet FCA SYSC obligations, SYSC 15A operational risk requirements and ISO27001 standard.
  • Work closely with the Head of Compliance on regulatory horizon scanning, security-related policy obligations, and audit responses.
  • Partner with the DPO on data governance and breach notification obligations.
  • Manage third-party and supply chain security risk, including critical outsourcing oversight.

Incident Management & Operations

  • Own the security incident response plan; lead major incident management for cyber events.
  • Operate and improve security monitoring, SIEM, and alerting across the Azure estate.
  • Run the security awareness and training programme for all ~180 staff.
  • Manage relationships with external SOC, MSSP, and specialist security partners.

Requirements

Essential

  • Demonstrable experience leading information security in a regulated financial services or fintech environment.
  • Strong working knowledge of FCA regulatory requirements (SYSC, operational resilience).
  • Hands-on familiarity with cloud-native security on Azure (Entra ID, Defender, Sentinel, Key Vault, Policy).
  • Proven delivery of ISO 27001 certification or equivalent ISMS framework.
  • Ability to translate technical risk into board-level narrative clearly and credibly.
  • Experience partnering with engineering teams — you are comfortable in a technical conversation and a risk committee meeting.
  • CISM, CISSP, or equivalent professional qualification (or demonstrable equivalent experience).

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Desirable

  • Familiarity with API security patterns (Kong, OAuth 2.0, OIDC) and modern identity architectures.
  • Background in or strong exposure to software engineering — understanding of SDLC security, threat modelling, and DevSecOps.
  • Experience managing a security team and developing talent toward senior positions.
  • Familiarity with Kafka-backed event architectures and the security considerations they introduce.
  • Awareness of AI and machine-learning security risks and emerging AI governance frameworks (e.g. NIST AI RMF, ISO/IEC 42001).
  • Understanding of post-quantum cryptography and quantum-safe migration and crypto-agility planning.

Benefits

  • 25 days holiday (exc. Bank holidays)
  • 5% Pension contributions
  • Private medical insurance with Vitality
  • Health cash Plan offering contributions to dental, optical and much more
  • Enhanced Parental Leave
  • Cycle to Work Scheme
  • Monthly team lunches, quarterly company socials

Working Pattern

Hybrid working pattern in London office, 3 days in the office (Tuesday to Thursday), 2 days remote.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Information security
Azure
ISO 27001
Risk management
Compliance
Security architecture
Threat modelling
Identity and access management
Incident management
FCA regulatory requirements
Cybersecurity
Security governance
Cloud security
Data governance
Cryptography
Leadership

Location

London, England, United Kingdom

Sign up to applySee more jobs like this