Intropic
Senior Security Engineer Overview
| Company Name | Intropic |
| Job Role | Senior Security Engineer |
| Qualifications | Not Specified |
| Category | IT Jobs |
| Job Type | Full Time |
| Location | London |
Intropic is a financial information and software company that operates at the forefront of global capital markets. We leverage modern technology, including elastic cloud infrastructure and advanced AI systems, combined with deep market expertise to create information products relied upon by sophisticated financial institutions. Our clientele includes hedge funds, proprietary trading firms, index fund managers, large asset managers, sovereign wealth funds, and investment banks, all of whom utilize our products to enhance decision-making and manage risk in dynamic markets. We are headquartered in London’s Canary Wharf and are expanding our global reach, fostering a fast-paced environment where team members take ownership and uphold high standards of rigor and integrity.
The Senior Security Engineer will be responsible for managing the entire security stack at Intropic. This includes overseeing cloud security, endpoint protection, detection and response, compliance, and the security of our AI agent usage. The role is designed for a senior professional who is eager to lead security initiatives within a growing FinTech environment, rather than working within a limited scope in a larger team. Responsibilities will vary week to week, including tasks such as hardening EKS clusters, tuning detection systems, scoping penetration tests, and ensuring secure access for engineers to coding agents. The position also requires out-of-hours response to security alerts.
Responsibilities
- Oversee the entire security stack at Intropic, including cloud infrastructure, endpoints, detection and response, compliance, and AI security.
- Engineer and manage security for cloud infrastructure across AWS and GCP, handling everything from individual EC2 instances to large EKS microservices.
- Run detection and response operations, triaging alerts, expanding coverage, and ensuring the reliability of security tools.
- Respond to security alerts, including after-hours incidents, ensuring timely resolution.
- Threat model new products and services prior to their release, embedding security checks into CI/CD processes.
- Define security standards for external SaaS app integrations, including building approval workflows for OAuth connections.
- Secure the use of AI agents and production generative AI systems, both for client-facing and internal applications.
- Collaborate with various business units to implement security measures that protect the company while maintaining operational efficiency.
- Establish an automated patching system for all cloud systems.
- Own the SOC 2 compliance process, managing the yearly Type II audit and scoping the annual web application pentest.
- Automate evidence collection for compliance using Drata and identify gaps in security policies to develop new policies.
- Assist with onboarding and offboarding processes for employees, ensuring efficiency and completeness.
- Manage approximately 100 endpoints using Jamf and Intune, primarily macOS devices.
- Address and resolve colleagues’ security and IT access inquiries promptly and courteously.
- Manage core SaaS applications, including Google Workspace and GitLab, automating repetitive tasks.
Requirements
- Minimum of 5 years of experience in security across multiple domains.
- Advanced hands-on knowledge of various AWS services, including EC2, S3, GuardDuty, Lambda, ECS, and EKS.
- Practical experience with Kubernetes, particularly EKS.
- Experience in threat modeling web applications and responding to security incidents.
- Familiarity with AI agents, either in personal workflows or security tools.
- Understanding of SOC 2 compliance and proficiency with Git.
- Working knowledge of Jamf for endpoint management.
- Strong scripting skills in Python or Bash for task automation and system integration.
- Willingness to learn and develop skills in new areas of security, IT, or GRC.
- Ability to switch between different domains while maintaining attention to detail and providing excellent user support.
Degree Requirement: Not Specified
Visa Sponsorship May be
To apply for this job please visit jobs.lever.co.