Lantern Ltd
Senior Security & Compliance Engineer

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
About Lantern
The trusted data platform for private markets.
Lantern is built by operators who have lived the exact problem we've set out to fix. Our leadership team has founded, scaled, and exited private markets technology and large-scale tech companies through acquisitions, IPOs, and global expansions. We know what GPs, LPs, and administrators actually need because we've sat on their side of the table.
Private markets data today is fragmented, manual, and slow. Every quarter the same story plays out: numbers arrive from disparate places, sources do not agree, and someone spends their week rebuilding trust from scratch in Excel, hoping nothing slipped through the cracks. It's exhausting. It's avoidable. And it's exactly what Lantern was built to end.
Lantern is not another dashboard. We're building the infrastructure that makes private markets data trustworthy, and we're just getting started.
The Role
We're looking for a Senior Security & Compliance Engineer to own and develop Lantern's security programme as we scale.
This is a broad, hands-on role spanning cloud and application security, vulnerability management, identity and access management, incident response, secure software delivery, SOC 2, risk management, and customer security assurance.
You'll be the internal owner for security: maintaining a clear view of our security posture, identifying where we need to improve, and working directly with engineering and leadership to make those improvements happen. You'll turn findings from security tooling, audits, penetration tests, and engineering reviews into clear actions with owners and deadlines, and follow them through to remediation or explicit risk acceptance.
You'll also own our day-to-day SOC 2 programme and audit readiness. That means making sure our controls reflect how Lantern actually operates, maintaining Vanta, coordinating evidence and auditor requests, keeping policies and procedures current, and ensuring our controls are operational rather than just documented.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
This isn't a role where security sits outside engineering and produces a list of findings. You'll work closely with our Platform and product engineering teams on GCP, GitHub, CI/CD, identity, infrastructure, application security, and production operations. You'll help design controls that are secure, pragmatic, auditable, and don't unnecessarily slow down the people building the product.
As our dedicated security specialist, you'll have significant scope to define how security works at Lantern and establish the standards and practices we use as the company grows.
What You'll Own
- Security posture and risk. Maintain a clear view of security risks across our applications, cloud infrastructure, endpoints, and third-party services, driving issues through remediation or documented risk acceptance.
- SOC 2 and audit readiness. Own day-to-day SOC 2 readiness, including controls, evidence, audit preparation, auditor requests, findings, and remediation.
- Security tooling and monitoring. Own Vanta and our security integrations, ensuring controls, tests, alerts, and underlying data remain accurate and actionable.
- Vulnerability management. Own vulnerability management across applications and infrastructure, including triage, remediation, penetration testing, and escalation of critical issues.
- Secure engineering and access. Work with engineering on secure software delivery, change management, IAM, privileged access, environment separation, and protection of customer data.
- Incident response. Own and continuously improve our security incident process, from identification and escalation through investigation, documentation, and remediation.
- Policies, vendors, and customer assurance. Maintain our security policies, oversee third-party security, and own responses to customer and prospect security questionnaires.
- Security governance. Provide clear security-risk updates to engineering and company leadership, turning findings into decisions, owners, and deadlines.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
About You
- 5+ years of professional security experience, ideally in a cloud-native SaaS or technology environment.
- Hands-on experience securing AWS, GCP, or Azure environments and working directly with engineering teams.
- Experience owning or playing a significant role in a SOC 2 Type II programme, including controls, evidence, auditor interaction, and remediation.
- Experience with compliance or GRC platforms such as Vanta, Drata, or Secureframe.
- Strong understanding of vulnerability management, IAM, application security, secure software delivery, and incident response.
- Comfortable working with modern engineering environments including CI/CD, GitHub, infrastructure as code, and production cloud infrastructure.
- Pragmatic about security: able to distinguish genuine risk from a compliance checkbox and design controls that work in a fast-moving engineering environment.
- Able to communicate clearly with engineers, leadership, auditors, customers, and non-technical teams.
- Comfortable taking ownership where a process doesn't exist yet: defining it, implementing it, and making sure it continues to work.
What You'll Get
- Real ownership. Shape how security works at Lantern and build the standards, controls, tooling, and practices that support us as we grow.
- Security close to engineering. Work directly with the engineers building and operating the platform, solving problems rather than simply reporting them.
- Visible impact. Your work will directly influence our product, engineering practices, customer relationships, and ability to scale.
- A competitive package. A competitive salary and benefits package, including generous annual leave and other benefits appropriate to your location.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location