Staff Security Engineer
Department: CISO
Employment Type: Permanent - Full Time
Location: UK - London
Description
At CFC, technology is at the heart of everything we do. As a market leader in cyber insurance and a business built on innovation, we’re looking for a Staff Security Engineer to play a critical role in evolving our security capabilities and driving measurable risk reduction across our global technology estate.
This is a senior individual contributor opportunity for an engineer who enjoys solving complex security challenges at scale. You’ll work across engineering, data, AI and digital workplace teams to build security observability, automate control assurance and influence how security is embedded into products, platforms and processes.
If you're passionate about turning security data into actionable insight, building elegant automation and raising the security maturity of a fast-moving technology organisation, we'd love to hear from you.
About the role
- Designing and building security observability capabilities that provide meaningful visibility across systems, infrastructure and applications
- Developing automated control monitoring, evidence collection and continuous testing solutions that strengthen security governance
- Partnering with engineering, data and technology teams to embed effective security controls into products and platforms
- Driving improvements in security event monitoring, exposure management and alerting capabilities
- Conducting security reviews of new products, services and technology initiatives
- Building meaningful security metrics and reporting that support informed decision-making
- Supporting the evolution of security policies, standards and technical guardrails through automation and measurable outcomes
- Contributing to access governance and security control assurance activities across both human and non-human identities
Acting as a technical leader and trusted security advisor, helping raise standards across the wider technology organisation
About you
We're interested in hearing from engineers who combine strong technical depth with a practical, collaborative approach to security.
You'll likely bring:
- A strong background in security engineering, information security, governance, risk or compliance
- Experience building security controls and automated security solutions within modern cloud environments
- Knowledge of security technologies such as SIEM, vulnerability management, data protection, endpoint security or exposure management platforms
- Experience working with APIs, automation, scripting and infrastructure-as-code technologies
- Familiarity with cloud platforms including Azure, AWS or GCP
- An understanding of security frameworks and control standards such as ISO 27001, SOC 2 and CIS Controls
- Experience operating in regulated environments and working with security and data protection requirements
- Excellent communication skills and the ability to influence stakeholders across technical and non-technical teams
Core Values
Love what you do:
We show up each day ready to take on the world. Our passion and intensity set us apart and makes the difference to our colleagues, customers, brokers and carriers.
Challenge everything:
We’re never afraid to question the way that things are done and we constantly challenge ourselves and others to makes things better.
Have fun, be good:
Insurance is a serious business, but we don’t take ourselves too seriously. We make it fun to work at CFC, we welcome all viewpoints, and we treat everyone how we would expect to be treated.