At a Glance
- Tasks: Strengthen security infrastructure and protect digital assets against threats.
- Company: Join a leading digital asset technology company focused on secure crypto solutions.
- Benefits: Enjoy 27 days holiday, health insurance, and flexible working options.
- Why this job: Make a real impact in the fast-paced world of digital assets and cybersecurity.
- Qualifications: Experience in security systems, IAM, and scripting languages like PowerShell or Python.
- Other info: Be part of a diverse team with excellent career growth opportunities.
The predicted salary is between 43200 - 72000 £ per year.
Copper is a digital asset technology company dedicated to helping institutional investors safely acquire, trade, and store crypto assets. Built and led by Dmitry Tokarev, the firm provides a comprehensive suite of custody, trading and settlement solutions that reduce counterparty risk and bring greater capital and operational efficiency to digital asset markets. At the heart of Copper's offering is Multi-Party Computation (MPC) technology – the gold standard in secure custody. Copper’s multi-award winning custody system can be connected to centralised exchanges, DeFi applications and even staking pools without the assets leaving the custody. ClearLoop is the first solution in the market that overcomes a growing industry challenge; counterparty risk with exchanges. This solution underpins a full prime services offering, connecting global exchanges and enabling customers to trade and settle directly from the safety of their MPC-secured wallets.
Department environment: Copper’s Information Security department keeps the business’ systems and network resources secure and protects the company, employees, and client data. The Infrastructure Security team focuses on providing objective oversight and validation of Copper’s infrastructure security controls and processes. As a Senior Security Engineer, you will be instrumental in strengthening Copper's security infrastructure, technical controls, and assurance. You will collaborate with various teams to implement and maintain robust security measures, ensuring the effectiveness of our security posture across Copper, and safeguarding our digital assets against threats.
Key Responsibilities of the role
- Identity and Access Management (IAM): Responsible for configuring and implementing Identity and Access Management solutions and supporting systems, including Entra ID (AAD), Identity Governance, and AWS Identity Centre. Manage permission settings and access controls to ensure secure and efficient user access to company resources.
- Security Systems Configuration and Analysis: Ensure security systems are configured according to specified requirements and industry best practices. Analyse current security setups, recommend improvements, and assess against standards like CIS, STIG, and internal control frameworks.
- Security Solution Inventory and Maintenance: Maintain an inventory of security solutions like firewalls and anti-virus software. Regularly review and recommend changes or upgrades to existing security tools.
- Security Practices and Technical Advice: Consult with staff, managers, and executives to advocate best security practices. Provide technical advice on security measures and potential enhancements. Create or update policies and procedures to align with industry regulations and best practices.
- Security Risk Management: Manage vulnerability scanning tools (Wiz, Defender, Armorcode) to identify and mitigate security risks across endpoints and cloud infrastructure. Conduct risk assessment activities to identify potential threats and develop plans to address vulnerabilities. Ensure security controls comply with SOC2 framework and other regulatory requirements.
- Scripting and Automation: Design and implement solutions for log shipping to managed SIEM systems, such as Microsoft Sentinel. Oversee the integration of diverse data sources, including network logs, application logs, and security feeds, to enhance the analytical capabilities of our security systems. Develop and maintain scripts for efficient operation and response within the security infrastructure, utilising a variety of high-level programming languages (notably, PowerShell and/or Python).
Your experience, skills and knowledge
- Essential: Proficient in managing corporate identity solutions, including integrations with third-party applications to ensure secure access to resources. Skilled in configuring and reporting across Identity Governance and entitlement management within a Microsoft and AWS environment.
- AWS Security: Skilled in leveraging AWS security services to fortify cloud infrastructure, deploying GuardDuty and AWS Security Hub for continuous security monitoring and threat detection, managing AWS Identity and Access Management to ensure robust access controls, and utilising Route 53 and Key Management Service for enhanced security and encryption.
- Microsoft 365 and Azure Security: Demonstrated expertise in securing corporate environments using Microsoft 365 and Azure Security tools, effectively managing Azure Active Directory, implementing robust identity governance frameworks, and deploying Azure Sentinel for advanced threat protection.
- Scripting and Automation: Demonstrated ability in using scripting languages like PowerShell, Bash, and Python to automate security tasks, streamline processes, and enhance system efficiencies.
- System and Application Hardening: Skilled in the assessment and hardening of operating systems and SaaS applications, adhering to CIS and STIG standards.
- Network Perimeter Security: Experience in securing, configuring, and managing outbound and inbound network traffic using tools for filtering and securing web traffic, network security devices that control traffic, virtualised network environments and Web Application Firewalls (WAF).
Desirable: Experience in configuring and managing Secure Web Gateways, familiarity with Enterprise Risk Management (ERM) programmes and compliance with standards like IS27001, SOC2, and NIST CSF, and awareness of the global regulatory landscape as it pertains to cryptocurrencies and digital assets.
The benefits offered
- Holidays: 27 days per annum paid holiday, in addition to bank holidays.
- Years of Service Days: Employees are awarded one additional day of paid time off per year of service (up to three years).
- Vitality Health: Medical Insurance, Dental Insurance, Audiology Cover, Optical Cover, Menopause Support, and additional benefits through the Vitality programme.
- Home Working Energy Support Scheme: Monthly top-up of £60 or £75 (subject to your energy supplier).
- Pension: Up to 10% matched contribution to our company pension scheme via Smart Pensions.
- Cycle to Work.
- Life Insurance cover: Four times your base salary.
- EAP: Access unlimited mental health consultations and contact a 24/7 confidential helpline for emotional support.
- Sponsored Learning and Development opportunities.
- Regular company events and social activities.
If you think you have everything we’re looking for and more, then we’d love you to apply for the opportunity. Copper is an equal opportunity employer. We embrace diversity and equal opportunities in a serious way. We are committed to building a team that represents a variety of backgrounds, perspectives, and skills.
Senior Security Engineer in London employer: Copper.co
Contact Detail:
Copper.co Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Security Engineer in London
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with Copper employees on LinkedIn. Building relationships can open doors that applications alone can't.
✨Tip Number 2
Show off your skills! If you have a portfolio or GitHub showcasing your security projects, make sure to share it during interviews. It’s a great way to demonstrate your expertise beyond just words.
✨Tip Number 3
Prepare for the technical interview! Brush up on your scripting and automation skills, especially in PowerShell and Python. Be ready to discuss how you've implemented security measures in past roles.
✨Tip Number 4
Apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you're genuinely interested in joining the Copper team.
We think you need these skills to ace Senior Security Engineer in London
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience with security systems, IAM solutions, and AWS security. We want to see how your skills align with what we're looking for at Copper!
Showcase Your Technical Skills: Don’t hold back on showcasing your scripting abilities and experience with security tools. Mention specific projects or achievements that demonstrate your expertise in PowerShell, Python, or any relevant security frameworks.
Be Clear and Concise: Keep your application clear and to the point. Use bullet points where possible to make it easy for us to read through your qualifications and experiences. We appreciate a well-structured application!
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it’s super easy!
How to prepare for a job interview at Copper.co
✨Know Your Security Stuff
Make sure you brush up on your knowledge of Identity and Access Management, AWS security services, and Microsoft 365 security tools. Be ready to discuss how you've implemented these in past roles, as Copper is looking for someone who can hit the ground running.
✨Show Off Your Scripting Skills
Since scripting and automation are key parts of the role, prepare to talk about your experience with PowerShell, Python, or Bash. Maybe even bring a small example of a script you've written that improved security processes – it’ll show you’re proactive and hands-on!
✨Understand the Company’s Tech
Familiarise yourself with Copper's Multi-Party Computation (MPC) technology and how it enhances security. Being able to discuss how this tech fits into the broader landscape of digital asset security will impress the interviewers and show your genuine interest in the company.
✨Prepare Questions
Interviews are a two-way street! Prepare thoughtful questions about Copper's security practices, team dynamics, and future projects. This not only shows your enthusiasm but also helps you gauge if the company is the right fit for you.