Description:
Senior Security Engineer
I'm working with a London-based hedge fund that's investing properly in its security function for the first time at scale - and they're hiring a generalist Senior Security Engineer to help build it.
- Established, highly profitable multi-strategy fund with a serious technology footprint
- Small, senior technology team - engineers from trading firms, big tech, and top-tier startups
- Genuine autonomy: no legacy security org, no ticket queue, no committee to design around
This is a broad, hands-on role covering the full surface: cloud, applications, endpoint, identity, and everything in between. You're not owning one narrow vertical - you're the person the business relies on across all of it.
What you'll be working on:
- Owning and evolving the firm's security posture end to end - AppSec, CloudSec, infrastructure, identity, endpoint
- Automating security operations - vulnerability management, asset inventory, patching, detection tuning
- Securing trading and research infrastructure without slowing down the people using it
- Embedding security-first principles across engineering, research, and the wider business
- Partnering with technology leadership on architecture decisions, third-party risk, and regulatory expectations
What they're looking for:
- Strong hands-on security engineering experience - hedge fund, trading firm, big tech, or high-growth startup
- Genuine breadth: comfortable moving between cloud, application, and endpoint security in the same week
- Solid engineering fundamentals - Python, Go, or similar; you automate rather than administer
- Experience owning cloud security at scale (AWS, GCP, or Azure)
- A builder - someone who writes the playbook rather than following one