Senior Security Engineer, London London

Senior Security Engineer, London London

London Full-Time 80000 - 100000 £ / year (est.) No working from home possible
Isomorphic Labs Limited

At a Glance

  • Tasks: Secure our innovative AI platforms and HPC infrastructure while tackling diverse technical challenges.
  • Company: Join Isomorphic Labs, a leader in AI-driven drug discovery.
  • Benefits: Enjoy competitive pay, flexible work options, and opportunities for professional growth.
  • Other info: Be part of a collaborative culture that values innovation and adaptability.
  • Why this job: Make a real impact in healthcare by securing groundbreaking technologies.
  • Qualifications: Experience in cloud security, coding, and risk management is essential.

The predicted salary is between 80000 - 100000 £ per year.

Isomorphic Labs is applying frontier AI to help unlock deeper scientific insights, faster breakthroughs, and life‑changing medicines with an ambition to solve all disease. We drive breakthrough innovation in drug discovery, leveraging cutting‑edge AI models and high‑performance computing infrastructure.

Your impact

As a Senior Security Engineer, you will architect and manage the security of our groundbreaking ML‑based platform and High Performance Computing (HPC) infrastructure. This role requires a highly proactive problem‑solver who enjoys a fast‑paced environment and possesses the curiosity to dive into diverse technical challenges.

What you will do

  • Secure Architecture and Product Engineering: Participate in the design and perform security reviews of our evolving AI platforms and underlying HPC infrastructure.
  • Infrastructure as Code (IaC) Security: Partner with our DevOps / SRE team to harden our cloud infrastructure and network, ensuring security by design, automation and auditability through Policy as Code.
  • Third Party Systems Secure Integration: Perform deep‑dive technical assessments of third‑party platforms, AI solutions, Cloud or SaaS providers and support secure integration or deployment.
  • Secure CI/CD: Design and implement automated security controls within our CI/CD pipelines to ensure code is secure from commit to production without slowing down research velocity.
  • Threat Modeling & Risk Assessment: Conduct proactive threat modeling and risk assessment, support teams in the implementation of remediation plan and audit expected outcomes.
  • Incident Response: Act as a L2/L3 escalation point for the remediation of complex vulnerabilities and security incidents.
  • Identity & Access Management: Implement our state‑of‑the‑art Zero Trust framework, ensuring robust access control and consistent enforcement of the principle of least privilege.
  • Risk Management and Compliance Automation: Bridge the gap between technical controls and regulatory requirements (GDPR, GxP, EU AI Act) by automating evidence collection and risk posture monitoring (CSPM).
  • Security Tooling Development: Build or integrate custom internal tools that automate repetitive security tasks, shifting our operational load from manual toil to scalable engineering.
  • End‑to‑End Solution Delivery: Manage the full lifecycle of security controls, from initial user needs analysis and requirements gathering to structured testing and phased implementation and communication, ensuring high‑quality deployment followed by data‑driven continuous improvement.

Skills and qualifications

  • Cloud Engineering Proficiency: Deep technical knowledge of cloud platform security (GCP preferred) including Network and VPC design, IAM policy construction, Cloud resources hardening and Cloud native security services.
  • Analytical Risk Management and Problem Solving: Proficiency in assessing multi‑faceted risks and decomposing complex security issues into manageable tasks and providing data‑driven recommendations to stakeholders.
  • Coding Skills: Ability to write small production‑grade code (e.g. in Python) and to automate security tasks, build custom tooling, etc.
  • DevSecOps Tooling: Hands‑on experience with Infrastructure as Code (Terraform) and version control systems (GitHub) to manage security configurations.
  • Container Security: Proven ability to secure containerised workloads (Kubernetes/Docker), focusing on image signing, runtime protection, and orchestration security.
  • Network Security Fundamentals: Solid understanding of modern networking, including zero‑trust architecture, encryption in transit (TLS/mTLS), and API gateway security.
  • Identities and Access Management: Proficiency in implementing a state‑of‑the‑art IAM strategy both from an organisational and technical standpoints in a multi‑tenant cloud environment.
  • Collaborative Security Culture: Strong ability to support researchers in AI and Drug Discovery, leveraging excellent listening skills, to provide pragmatic advice that balances high‑security requirements with business agility.
  • Adaptability & Communication: Excellent soft skills with the ability to navigate an ambiguous, high‑growth environment and explain technical risks to non‑security audiences.
  • Offensive Mindset: Strong understanding of the MITRE ATT&CK framework and the ability to think like an adversary to identify "blind spots" in our defence.

Nice to have

  • AI/ML Security Interest: Familiarity with the unique security challenges of an AI first company and other common AI solutions such as LLMs.
  • Regulated Industry Experience: Prior experience working in BioTech, Pharma where data integrity and regulatory compliance are paramount.
  • Advanced Security Certifications: Holding industry‑recognised credentials such as GSE, OSCP, CISSP or professional‑level Cloud Security Engineer certifications.
  • Application Security (AppSec): Experience with SAST/DAST/SCA tools and a strong understanding of the OWASP Top 10 vulnerabilities.
  • Zero Trust Implementation: Past success in transitioning an organisation away from traditional perimeter‑based security towards a mature Zero Trust model.
  • SecOps Maturity: Experience building or scaling a Security Operations Centre (SOC) or a Modern Detection and Response (MDR) function.
  • Collaboration Tool Mastery: Advanced experience securing and automating SaaS. In particular, Google Workspace, the Atlassian stack (Jira/Confluence), Slack.
  • Bio‑Pharma Experience: Prior exposure to GxP validation, clinical trial data protections, or the nuances of Lab‑IT security.
  • Privacy Engineering: Knowledge of PETs (Privacy Enhancing Technologies) like differential privacy or homomorphic encryption.

We are committed to equal employment opportunities regardless of sex, race, religion or belief, ethnic or national origin, disability, age, citizenship, marital, domestic or civil partnership status, sexual orientation, gender identity, pregnancy or related condition (including breastfeeding) or any other basis protected by applicable law. If you have a disability or additional need that requires accommodation, please do not hesitate to let us know.

Senior Security Engineer, London London employer: Isomorphic Labs Limited

Isomorphic Labs is an exceptional employer, offering a dynamic work environment in London where innovation meets purpose. Employees benefit from a collaborative culture that prioritises professional growth and development, alongside competitive compensation and comprehensive benefits. With a focus on cutting-edge AI technology in drug discovery, team members are empowered to make meaningful contributions towards solving global health challenges.

Isomorphic Labs Limited

Contact Details:

Isomorphic Labs Limited Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior Security Engineer, London London

Tip Number 1

Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those related to security engineering. This gives potential employers a taste of what you can do and sets you apart from the crowd.

Tip Number 3

Prepare for interviews by brushing up on common security scenarios and challenges. Practice explaining your thought process and how you tackle problems. Remember, they want to see how you think, not just what you know!

Tip Number 4

Apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who are genuinely interested in joining our mission to revolutionise drug discovery with AI.

We think you need these skills to ace Senior Security Engineer, London London

Cloud Engineering Proficiency
Network Security Fundamentals
Identity & Access Management
Infrastructure as Code (IaC) Security
DevSecOps Tooling
Container Security
Analytical Risk Management

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Senior Security Engineer role. Highlight your experience with cloud security, coding skills, and any relevant certifications. We want to see how your background aligns with our mission at Isomorphic Labs!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about AI and drug discovery. Share specific examples of how you've tackled security challenges in the past. We love a good story that showcases your problem-solving skills!

Show Off Your Technical Skills:Don’t hold back on showcasing your technical prowess! Mention your experience with Infrastructure as Code, container security, and any tools you’ve used. We’re looking for someone who can dive into diverse technical challenges, so let us know what you bring to the table.

Apply Through Our Website:We encourage you to apply through our website for a smoother process. It helps us keep track of applications and ensures you don’t miss out on any important updates. Plus, it’s super easy – just a few clicks and you’re in!

How to prepare for a job interview at Isomorphic Labs Limited

Know Your Stuff

Make sure you brush up on your cloud security knowledge, especially if you're familiar with GCP. Be ready to discuss specific security measures you've implemented in the past, particularly around Infrastructure as Code and container security.

Show Off Your Problem-Solving Skills

Prepare examples of how you've tackled complex security challenges. Think about times when you've had to break down a multifaceted issue into manageable tasks and how you communicated those solutions to non-technical stakeholders.

Get Familiar with the Company’s Tech Stack

Research Isomorphic Labs' AI platforms and HPC infrastructure. Understanding their technology will help you tailor your answers and demonstrate your genuine interest in their work and how you can contribute.

Be Ready for Technical Assessments

Expect to dive deep into technical assessments during the interview. Brush up on threat modelling, risk assessment, and secure CI/CD practices. Being able to articulate your thought process will show that you’re proactive and detail-oriented.