{"id":1191449,"url":"https://alion.io/job/insignis-senior-engineering-manager-security","title":"Senior Engineering Manager, Security","company":{"id":2681195,"name":"Insignis","domain":"insigniscash.com","url":"https://alion.io/company/insignis","size_band":"5000+","is_staffing_agency":false,"is_intermediary":false,"listed_via":null,"ats_vendor":"Greenhouse","truth_index":null},"role":"Leadership","role_family":"Leadership","seniority":"lead","employment_type":null,"work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["London, United Kingdom"],"countries":["GB"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":95000,"max_usd":205000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":22},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":".NET","optional":false},{"name":"Agile","optional":false},{"name":"Apache Kafka","optional":false},{"name":"API Gateway","optional":false},{"name":"Auth0","optional":false},{"name":"Azure","optional":false},{"name":"C#","optional":false},{"name":"Incident Management","optional":false},{"name":"ISO 27001","optional":false},{"name":"Kong","optional":false},{"name":"Kubernetes","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"SIEM","optional":false},{"name":"Vue.js","optional":false},{"name":"JavaScript","optional":true},{"name":"NIST AI RMF","optional":true}],"status":"live","first_seen_at":"2026-08-21T14:03:02Z","employer_posted_date":"2026-08-29","last_verified_at":"2026-09-24T16:56:28Z","board_verified":true,"closed_at":null,"days_open":34,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":34},"description":"We are a fast-growing FinTech company looking for a talented and enthusiastic engineer to join our team. We are expanding, making this a perfect position if you would like to have a significant impact on our company’s growth and develop your role and career as the business evolves. You will join a team where your ideas will be welcomed and valued.\nThis is a senior individual contributor and leadership role. You will report to the CTO, with a functional dotted line to the Head of Compliance. You will work closely with engineering, compliance, and risk functions, and represent security at board level. You will be the architect of a security culture that is rigorous, pragmatic, and commercially aware. The role will be hands on at the outset.\nRole responsibilities\nSecurity strategy & governance:\nOwn the information security strategy, aligned to FCA requirements, ISO 27001, and the firm’s risk appetite.\nChair the Information Security Working Group; prepare materials for the board and Insignis Risk Committee.\nLead the ISO 27001 programme, including ongoing audit readiness and continual improvement.\nMaintain and evolve the ISMS, risk register, and security policy suite.\nRepresent security in regulatory engagements, including FCA supervisory requests and third-party due diligence.\nTechnical security & architecture:\nDefine and enforce the security architecture across our Azure-native, Kubernetes-based platform.\nGovern security controls across the full stack: Kafka, .NET/C#, Vue.js, Kong API Gateway, Auth0, and Salesforce.\nLead threat modelling, penetration testing, and vulnerability management programmes.\nOwn identity and access management strategy, including Entra ID, Auth0, and partner federation.\nDrive security engineering best practices within product and platform teams.\nBuild and govern security for AI and machine-learning systems - covering model and data governance, defences against prompt injection and model abuse, and safe adoption of generative-AI tooling across the business.\nLead the firm's quantum-safe transition to post-quantum cryptography - maintaining a cryptographic inventory, assessing exposure, and planning a crypto-agile migration to NIST-standardised PQC algorithms.\nCompliance & regulatory:\nEnsure security controls meet FCA SYSC obligations, SYSC 15A operational risk requirements and ISO27001 standard.\nWork closely with the Head of Compliance on regulatory horizon scanning, security-related policy obligations, and audit responses.\nPartner with the DPO on data governance and breach notification obligations.\nManage third-party and supply chain security risk, including critical outsourcing oversight.\nIncident management & operations:\nOwn the security incident response plan; lead major incident management for cyber events.\nOperate and improve security monitoring, SIEM, and alerting across the Azure estate.\nRun the security awareness and training programme for all ~180 staff.\nManage relationships with external SOC, MSSP, and specialist security partners.\n\nRequirements\nEssential:\nDemonstrable experience leading information security in a regulated financial services or fintech environment.\nStrong working knowledge of FCA regulatory requirements (SYSC, operational resilience).\nHands-on familiarity with cloud-native security on Azure (Entra ID, Defender, Sentinel, Key Vault, Policy).\nProven delivery of ISO 27001 certification or equivalent ISMS framework.\nAbility to translate technical risk into board-level narrative clearly and credibly.\nExperience partnering with engineering teams - you are comfortable in a technical conversation and a risk committee meeting.\nCISM, CISSP, or equivalent professional qualification (or demonstrable equivalent experience).\nDesirable:\nFamiliarity with API security patterns (Kong, OAuth 2.0, OIDC) and modern identity architectures.\nBackground in or strong exposure to software engineering - understanding of SDLC security, threat modelling, and DevSecOps.\nExperience managing a security team and developing talent toward senior positions.\nFamiliarity with Kafka-backed event architectures and the security considerations they introduce.\nAwareness of AI and machine-learning security risks and emerging AI governance frameworks (e.g. NIST AI RMF, ISO/IEC 42001).\nUnderstanding of post-quantum cryptography and quantum-safe migration and crypto-agility planning.\nBenefits\n25 days holiday (exc. Bank holidays)\n5% Pension contributions\nPrivate medical insurance with Vitality\nHealth cash Plan offering contributions to dental, optical and much more\nEnhanced Parental Leave\nCycle to Work Scheme\nMonthly team lunches, quarterly company socials\nWorking pattern\nHybrid working pattern in London office, 3 days in the office (Tuesday to Thursday), 2 days remote.","description_format":"text","description_chars":4756,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Health insurance","Hybrid work","Parental leave"],"hiring_locations":[{"name":"United Kingdom","iso":"GB","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Artificial Intelligence","Financial Services","Professional Services"],"lifecycle":[{"event":"open","at":"2026-09-24T16:56:28Z"}],"liveness":{"score":27,"band":"fade","label":"Fading","p_open":1,"p_active":0.609,"p_room":0.45,"age_days":34,"expected_fill_days":18,"reasons":["conf:8","win:tail"],"computed_at":"2026-09-25T01:19:08Z"},"pay":null,"html_url":"https://alion.io/job/insignis-senior-engineering-manager-security","json_url":"https://alion.io/job/insignis-senior-engineering-manager-security.json","meta":{"generated_at":"2026-09-25T01:19:08Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1296,"day_limit":5000,"remaining_today":3704,"minute_limit":60,"resets_at":"2026-09-26T00:00:00Z"}}}