Overview
In this role you will lead the UK security function for a London-based hedge fund, shaping technical controls and governance. You will partner with the global CISO team to translate regulatory requirements into practical security measures and provide reporting on posture, risk, and compliance. You’ll design and maintain security controls across networks, endpoints, and identity, balancing technical excellence with risk oversight. This high-visibility position offers influence over security strategy in a data- and technology-driven financial services firm, with cross-border collaboration and impact.
Pay / Benefits
- Salary up to 150k
- Significant bonus
- Generous pension contribution
- Life assurance
- Critical illness cover
- Childcare vouchers
Responsibilities
- Lead design, implementation and ongoing operation of security controls and GRC activities for the London office
- Translate regulatory requirements into technical controls and governance processes
- Collaborate with New York-based teams and the global CISO to influence security strategy
- Provide reporting on security posture, risk and compliance to senior stakeholders
- Act as the sole UK-based security engineer/lead for the office, engaging with auditors and regulators as needed
Key requirements
- Experience as Systems/Infrastructure Security Engineer or similar security role
- Strong knowledge of network/endpoint security operations, vulnerability management and threat assessment
- Linux/Unix administration and hardening; Windows security and GPO management
- EDR tools (e.g., CrowdStrike, Microsoft Defender for Endpoint) and SIEM platforms (Splunk, ELK Stack, Datadog)
- IAM concepts and tools (Active Directory, OKTA)
- Experience in Information Security, Security Assurance, IT Audit or Cyber Risk within a regulated Investment Management environment
- Understanding of security frameworks (NIST, ISO 27001, COBIT) and incident response procedures
- Excellent stakeholder management and ability to communicate with auditors and senior leaders
- Stakeholder management
- Effective communication with technical and business teams
- Collaboration and cross-functional partnering
- Network security
- Endpoint security
- Vulnerability management
…
