Lead Security Engineer

Posted 3 Days Ago
Be an Early Applicant
London, England, GBR
Hybrid
Expert/Leader
Insurance • Cybersecurity
The Role
Lead security engineering across enterprise networks, devices, cloud systems, identity, and access environments. Design reusable security architectures, automated governance controls, authentication and authorization models, privileged access controls, secrets management, and policy-as-code. Diagnose and remediate security weaknesses, lead threat modeling, implement scalable controls for human and non-human identities including AI agents, and advise technology teams on complex security architecture decisions.
Summary Generated by Built In
Technology is at the heart of everything we do at CFC. We’re looking for a Lead Security Engineer to shape and deliver security across our networks, devices, identity and access environment.
This is a senior individual-contributor role for an engineer who combines strong technical judgement with sustained, hands-on delivery. You’ll solve complex, cross-functional security challenges, turning requirements and identified risks into practical, effective controls.
You’ll design how people, devices, services and non-human identities securely access our systems and data. Working across our technology teams, you’ll create reusable security architectures, implement and automate controls, diagnose weaknesses and ensure that security remains effective as our technology environment evolves.
 
At CFC, people are trusted to take ownership, challenge how things are done and deliver meaningful change. You’ll have the opportunity to influence security architecture across the business while working in an open, supportive and low-ego environment where ideas are welcomed

About the role
  • Design, implement and operate highly automated security governance and controls across network, device, identity and access systems.
  • Architect reusable security services for enterprise systems, integrating governance, protection, detection, response and recovery capabilities.
  • Design and implement access controls for human and non-human identities, including service and agentic AI identities.
  • Strengthen authentication, authorisation, secrets management, audit and privilege segmentation across systems and services.
  • Implement scalable access-control models and access policy-as-code, enabling teams to provision access consistently and securely.
  • Embed security governance and controls into code, cloud and AI architectures, including network segmentation and identity controls.
  • Diagnose and remediate identity, infrastructure and access-control weaknesses, identifying root causes and implementing controls that prevent recurrence.
  • Lead cross-functional security design and threat-modelling activities, translating risks into layered and prioritised engineering improvements.
  • Automate security policies and guardrails across workflows and endpoints, including the appropriate use of AI augmentation.
  • Act as a technical authority for network, device and identity security, advising technology teams on complex architecture and access-control decisions.

About you
We’re looking for an experienced security engineer who combines principal-level judgement with a practical, hands-on approach. You’ll bring:
  • Deep experience designing and engineering security across enterprise networks, devices, identity and access.
  • A strong understanding of network segmentation, identity controls and security architecture across cloud systems.
  • Hands-on experience implementing identity and access management and privileged-access controls across enterprise identity platforms.
  • Strong knowledge of authentication, authorisation, secrets management, audit, least privilege and privilege segmentation.
  • Experience designing access for human and non-human identities, including addressing excessive permissions, exposed secrets and access-governance weaknesses.
  • Experience implementing role-based or attribute-based access control, automated policy enforcement or access policy-as-code at scale.
  • The ability to create effective security architectures and navigate trade-offs between security, accessibility, decentralisation and performance.
  • The ability to automate controls through code, policy and workflow automation.
  • Strong technical judgement, with the ability to influence cross-functional technology teams through clear and credible architectural reasoning.
You’ll enjoy taking ownership of complex problems, challenging established approaches and working collaboratively to make security effective by default. This is an opportunity to make a visible impact in a business that gives people the trust and responsibility to shape what comes next.

Core Values
Love what you do:
We show up each day ready to take on the world. Our passion and intensity set us apart and makes the difference to our colleagues, customers, brokers and carriers.
Challenge everything:
We’re never afraid to question the way that things are done and we constantly challenge ourselves and others to makes things better.
Have fun, be good:
Insurance is a serious business, but we don’t take ourselves too seriously. We make it fun to work at CFC, we welcome all viewpoints, and we treat everyone how we would expect to be treated.

About
CFC is a specialist insurance provider, pioneering emerging risk and market leader in cyber. Our global insurance platform uses cutting-edge technology and data science to deliver smarter, faster underwriting and protect customers from today's most critical business risk.Headquartered in London with offices in New York, Melbourne, Sydney, Austin, Madrid, Brussels and Brisbane, CFC has over 1200 staff and is trusted by more than 100,000 businesses across 90 countries.At CFC, insurance isn't just about underwriting. From data science to software development, and digital marketing design, we've got something for everyone. We're passionate about pushing boundaries, thinking differently and building the insurance company of the future.CFC is committed to the principles of equal opportunities and creating an environment in which all individuals are always treated with dignity and respect. We encourage a diverse corporate culture of openness and appreciation to create an environment in which your talent can be developed in the best possible way. Should you require any reasonable adjustments at any stage of the recruitment process please let us know.Feeling like you need to tick every box before applying? We see things differently. In a rapidly scaling company like ours, ambition and the drive to learn count for more than a 'perfect' checklist. We're building the future of insurance, and that requires diverse talent eager to grow with us. If this role excites you and you're ready to make a significant impact, bring your unique background and let's build something great together.

Skills Required

  • Deep experience designing and engineering security across enterprise networks, devices, identity, and access
  • Strong understanding of network segmentation, identity controls, and security architecture across cloud systems
  • Hands-on experience implementing identity and access management and privileged-access controls across enterprise identity platforms
  • Strong knowledge of authentication, authorization, secrets management, audit, least privilege, and privilege segmentation
  • Experience designing access for human and non-human identities, including addressing excessive permissions, exposed secrets, and access-governance weaknesses
  • Experience implementing role-based or attribute-based access control, automated policy enforcement, or access policy-as-code at scale
  • Ability to create effective security architectures and navigate trade-offs between security, accessibility, decentralization, and performance
  • Ability to automate controls through code, policy, and workflow automation
  • Strong technical judgment and ability to influence cross-functional technology teams through clear architectural reasoning

CFC Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about CFC and has not been reviewed or approved by CFC.

  • Strong & Reliable Incentives — Variable pay is positioned as a core part of total compensation, with a group‑wide annual bonus highlighted as a consistent feature. Expanding employee share ownership is described as enhancing overall rewards alongside bonuses.
  • Healthcare Strength — Private medical insurance is provided, complemented by dental and optical cashback and a 24/7 employee assistance programme. These elements indicate comprehensive health coverage beyond standard medical plans.
  • Leave & Time Off Breadth — Time away provisions include 25 days of holiday and paid volunteer time, signaling a broad approach to time off. Additional practices such as company social events support overall work–life rhythm, though they are not leave per se.

CFC Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: London
Year Founded: 1999

What We Do

CFC is a specialist insurance provider, pioneer in emerging risk and market leader in cyber. Their global insurance platform uses cutting-edge technology and data science to deliver smarter, faster underwriting and protect customers from today’s most critical business risks.

Similar Jobs

Hybrid
London, Greater London, England, GBR
289097 Employees
Hybrid
3 Locations
289097 Employees

Rebellion Logo Rebellion

Security Engineer

Digital Media • Gaming
In-Office
3 Locations
600 Employees
Hybrid
London, Greater London, England, GBR
289097 Employees

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account