At a Glance
- Tasks: Design and implement security controls across applications, infrastructure, and cloud environments.
- Company: Join CUBE Global, a dynamic RegTech company shaping the future of financial services security.
- Benefits: Competitive salary, professional development, and opportunities to attend conferences.
- Other info: Collaborative culture focused on mentorship and raising security maturity across teams.
- Why this job: Make a real impact in security engineering while working with cutting-edge technology.
- Qualifications: Strong expertise in security engineering and hands-on experience with modern software delivery environments.
The predicted salary is between 60000 - 80000 £ per year.
We are looking for a Senior Security Engineer to join CUBE Global and help drive the standard of security engineering across our product and platform. This is a hands‑on, high‑impact role in a growing security function, reporting to the Head of Information Security. You will be a key contributor to our security engineering capability: designing and building security controls, embedding security into development and delivery workflows, and building the automation and systems integration that allows security to scale across the organization. We need someone who can help ensure our systems meet the standards expected of a RegTech company serving the global financial services industry.
Key Responsibilities
- Act as a senior hands‑on contributor to the design, implementation, and operation of security controls across application, infrastructure, and cloud environments.
- Partner with Software Engineering and Platform Engineering teams to embed security into system design, code review, CI/CD pipelines, and operational workflows.
- Design, build, and maintain reusable security patterns, guardrails, and automated controls that engineering teams can adopt with confidence.
- Build and operate security automation and systems integration: connecting security tooling into development, delivery, and compliance workflows to reduce manual effort and increase coverage.
- Develop and maintain integrations between security platforms, compliance tooling, and engineering systems to enable continuous visibility and evidence collection.
- Support and contribute to threat modelling and security design review for new and changing systems, focusing on enablement rather than gatekeeping.
- Contribute to vulnerability management operations: triage, prioritization, remediation tracking, and verification across the product and infrastructure estate.
- Participate in investigation and response to security incidents, coordinating with affected teams through containment, recovery, and root cause analysis.
- Help ensure security controls are implemented consistently and produce auditable evidence, supporting ISO 27001, SOC 2, and regulatory compliance requirements.
- Provide security input to change management, ensuring risk is understood and mitigated without unnecessary friction in delivery.
- Collaborate with Architecture and Platform Engineering to ensure security principles are reflected in shared patterns, reference designs, and infrastructure decisions.
- Contribute to security standards, guidance, and policy in partnership with GRC and compliance functions.
- Mentor and support other security engineers, raising security engineering maturity and consistency across the organization.
Skills and Experience
Essential
- Strong security engineering expertise across application security, cloud security (Azure preferred), and infrastructure security.
- Hands‑on experience securing modern software delivery environments: CI/CD pipelines, containerised workloads, IaC, and cloud‑native services.
- Practical experience with security tooling: SAST, SCA, DAST, vulnerability scanners, endpoint protection, and SIEM integration.
- Demonstrated ability to build security automation and systems integration: scripting, API integration, workflow orchestration, and connecting tooling into engineering pipelines.
- Experience with threat modelling methodologies and security architecture review for complex, distributed systems.
- Strong understanding of identity and access management principles, including privileged access, RBAC, and SSO/MFA architectures.
- Experience contributing to security incident investigation and response.
- Ability to produce clear, auditable evidence of security controls for internal audit and external certification (ISO 27001, SOC 2).
- Clear communication skills: able to articulate security risks and trade‑offs to engineering teams, leadership, and non‑technical stakeholders.
- Collaborative, enabling mindset: focused on raising the security capability of engineering teams rather than policing delivery.
Desirable
- Experience operating in a regulated financial services or RegTech environment.
- Familiarity with DORA, NIS2, or UK Cyber Security and Resilience Bill requirements as they apply to technology controls.
- Experience with compliance automation platforms (e.g., Vanta) and integrating evidence collection into engineering workflows.
- Exposure to AI/ML security considerations: model security, data pipeline integrity, and responsible AI governance.
- Experience with asset discovery and inventory tooling (e.g., Axonius) and configuration management at scale.
- Track record of supporting external certification audits.
Performance Indicators
- Measurable adoption of secure patterns and automated controls by engineering teams.
- Reduction in repeat security findings across audit cycles and vulnerability assessments.
- Timely remediation of vulnerabilities and security findings within agreed SLAs.
- Effective incident handling with clear root cause analysis, learning, and preventive action.
- Audit readiness: ability to produce evidence of control effectiveness on demand.
- Positive feedback from engineering teams on the quality and approachability of security partnership.
Why CUBE Global
- The opportunity to build and shape a security engineering function from the ground up in a growing, PE‑backed RegTech company.
- Direct reporting line to the Head of Information Security with visibility to executive leadership.
- A product that matters: CUBE tracks regulations across 750+ jurisdictions for 1,000+ financial services clients globally.
- A technology environment with real problems to solve: cloud migration, multi‑region operations, and regulatory technology at scale.
- Investment in your development: conference attendance, training, and certification support.
CUBE is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.
Senior Security Engineer employer: CUBE
Contact Detail:
CUBE Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Security Engineer
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with current employees at CUBE Global. A friendly chat can sometimes lead to opportunities that aren’t even advertised!
✨Tip Number 2
Show off your skills! If you’ve got a portfolio or GitHub showcasing your security projects, make sure to highlight it during interviews. It’s a great way to demonstrate your hands-on experience and passion for security engineering.
✨Tip Number 3
Prepare for those tricky questions! Brush up on your knowledge of security principles, threat modelling, and compliance standards. Being able to discuss these topics confidently will show that you’re the right fit for the role.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who take the initiative to engage directly with us.
We think you need these skills to ace Senior Security Engineer
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Senior Security Engineer role. Highlight your hands-on experience with security controls, cloud security, and automation. We want to see how your skills align with what we’re looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you’re passionate about security engineering and how you can contribute to our team. Don’t forget to mention any relevant experience in regulated environments!
Showcase Your Projects: If you've worked on any projects that involved security automation or systems integration, make sure to include them. We love seeing real-world examples of your work and how you’ve tackled challenges in security engineering.
Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. It’s the easiest way for us to keep track of your application and ensure it reaches the right people. Let’s get started on this journey together!
How to prepare for a job interview at CUBE
✨Know Your Security Fundamentals
Make sure you brush up on your security engineering expertise, especially in application and cloud security. Be ready to discuss specific tools you've used, like SAST or DAST, and how they fit into CI/CD pipelines.
✨Showcase Your Hands-On Experience
Prepare to share examples of your hands-on experience with security automation and systems integration. Talk about any scripting or API integration you've done, and how it improved security workflows in your previous roles.
✨Communicate Clearly and Confidently
Practice articulating complex security concepts in a way that non-technical stakeholders can understand. This will be crucial when discussing risks and trade-offs with engineering teams and leadership.
✨Emphasise Collaboration Over Policing
Highlight your collaborative mindset during the interview. Discuss how you've worked with engineering teams to raise their security capabilities rather than just enforcing rules. This will resonate well with CUBE Global's culture.