Security Engineer, Institutional Trading

Company: Blockchain
Apply for the Security Engineer, Institutional Trading
Location: London
Job Description:

Overview

As a hands-on Security Engineer embedded with the Institutional FinOps team, you secure off-chain trading operations and infrastructure that power our institutional business. You partner with Trading, Middle Office, and Quant teams to map data flows, integrations, and custody touchpoints, and you drive risk treatment plans to meet institutional standards. You implement monitoring, secrets management, and risk-focused incident response. This role emphasizes operational security and collaboration with senior stakeholders and third-party vendors to ensure resilient, compliant trading workflows.

Responsibilities

  • Collaborate with Trading, Middle Office and Quant teams to map inventory trading systems, data flows, third-party integrations and custody/settlement touchpoints
  • Perform deep-dive assessments of assets and workflows to identify structural vulnerabilities; define Target State and Risk Treatment Plans (RTP) aligned to CCSS, NIST, DORA
  • Serve as security liaison to Senior Management and vendors; translate gaps into business risk summaries; manage security vendor evaluations and posture uplift projects
  • Implement and maintain monitoring for FinOps security signals; integrate signals into SIEM/SOAR for real-time response
  • Oversee secrets and key-management hygiene; ensure keys stored in KMS/Vault with least-privilege access and automatic rotation
  • Assist product security in triage of SAST/SCA findings for FinOps repositories; contribute to CI checks and remediation playbooks
  • Participate in incident exercises, post-incident reviews, and remediation tracking for trading incidents
  • Document controls and produce concise risk summaries for FinOps leads and Security teams

Key requirements

  • 5+ years in security engineering, platform security, or application security
  • Proven expertise in Threat Modeling
  • Ability to perform structured reviews (e.g., STRIDE) of complex data flows
  • Experience with observability and detection tooling (SIEM, logs, metrics) and ability to write basic detection rules
  • Practical experience with KMS/HSM, secrets management platforms (Vault, 1Password, AWS/GCP KMS), IAM patterns and least-privilege
  • Exceptional ability to translate Technical Debt into Business Risk for C-suite stakeholders
  • Ability to raise, read and audit Pull Requests in at least one stack language (TypeScript, Java/Kotlin, Python)
  • Experience conducting technical due diligence and scoping for third-party security integrations
  • Clear communication with stakeholders at all levels, including executives
  • Structured, risk-based thinking and ability to translate complex gaps into actionable plans
  • Collaborative mindset and ability to work cross-functionally with trading and ops teams
  • Threat Modeling (STRIDE)
  • Security monitoring and incident response (SIEM, SOAR)
  • KMS/HSM and secrets management (Vault, 1Password, AWS/GCP KMS)

…

Posted: September 26th, 2026