Senior Security Engineer, London London

Senior Security Engineer, London London

Full-Time 80000 - 100000 £ / year (est.) No working from home possible
Isomorphic Labs Limited

At a Glance

  • Tasks: Secure our innovative AI platforms and HPC infrastructure while tackling diverse technical challenges.
  • Company: Join Isomorphic Labs, a leader in AI-driven drug discovery.
  • Benefits: Enjoy competitive pay, flexible work options, and opportunities for professional growth.
  • Other info: Be part of a collaborative culture that values innovation and adaptability.
  • Why this job: Make a real impact in healthcare by securing groundbreaking technologies.
  • Qualifications: Experience in cloud security, coding, and risk management is essential.

The predicted salary is between 80000 - 100000 £ per year.

Isomorphic Labs is applying frontier AI to help unlock deeper scientific insights, faster breakthroughs, and life‑changing medicines with an ambition to solve all disease. We drive breakthrough innovation in drug discovery, leveraging cutting‑edge AI models and high‑performance computing infrastructure.

Your impact

As a Senior Security Engineer, you will architect and manage the security of our groundbreaking ML‑based platform and High Performance Computing (HPC) infrastructure. This role requires a highly proactive problem‑solver who enjoys a fast‑paced environment and possesses the curiosity to dive into diverse technical challenges.

What you will do

  • Secure Architecture and Product Engineering: Participate in the design and perform security reviews of our evolving AI platforms and underlying HPC infrastructure.
  • Infrastructure as Code (IaC) Security: Partner with our DevOps / SRE team to harden our cloud infrastructure and network, ensuring security by design, automation and auditability through Policy as Code.
  • Third Party Systems Secure Integration: Perform deep‑dive technical assessments of third‑party platforms, AI solutions, Cloud or SaaS providers and support secure integration or deployment.
  • Secure CI/CD: Design and implement automated security controls within our CI/CD pipelines to ensure code is secure from commit to production without slowing down research velocity.
  • Threat Modeling & Risk Assessment: Conduct proactive threat modeling and risk assessment, support teams in the implementation of remediation plan and audit expected outcomes.
  • Incident Response: Act as a L2/L3 escalation point for the remediation of complex vulnerabilities and security incidents.
  • Identity & Access Management: Implement our state‑of‑the‑art Zero Trust framework, ensuring robust access control and consistent enforcement of the principle of least privilege.
  • Risk Management and Compliance Automation: Bridge the gap between technical controls and regulatory requirements (GDPR, GxP, EU AI Act) by automating evidence collection and risk posture monitoring (CSPM).
  • Security Tooling Development: Build or integrate custom internal tools that automate repetitive security tasks, shifting our operational load from manual toil to scalable engineering.
  • End‑to‑End Solution Delivery: Manage the full lifecycle of security controls, from initial user needs analysis and requirements gathering to structured testing and phased implementation and communication, ensuring high‑quality deployment followed by data‑driven continuous improvement.

Skills and qualifications

  • Cloud Engineering Proficiency: Deep technical knowledge of cloud platform security (GCP preferred) including Network and VPC design, IAM policy construction, Cloud resources hardening and Cloud native security services.
  • Analytical Risk Management and Problem Solving: Proficiency in assessing multi‑faceted risks and decomposing complex security issues into manageable tasks and providing data‑driven recommendations to stakeholders.
  • Coding Skills: Ability to write small production‑grade code (e.g. in Python) and to automate security tasks, build custom tooling, etc.
  • DevSecOps Tooling: Hands‑on experience with Infrastructure as Code (Terraform) and version control systems (GitHub) to manage security configurations.
  • Container Security: Proven ability to secure containerised workloads (Kubernetes/Docker), focusing on image signing, runtime protection, and orchestration security.
  • Network Security Fundamentals: Solid understanding of modern networking, including zero‑trust architecture, encryption in transit (TLS/mTLS), and API gateway security.
  • Identities and Access Management: Proficiency in implementing a state‑of‑the‑art IAM strategy both from an organisational and technical standpoints in a multi‑tenant cloud environment.
  • Collaborative Security Culture: Strong ability to support researchers in AI and Drug Discovery, leveraging excellent listening skills, to provide pragmatic advice that balances high‑security requirements with business agility.
  • Adaptability & Communication: Excellent soft skills with the ability to navigate an ambiguous, high‑growth environment and explain technical risks to non‑security audiences.
  • Offensive Mindset: Strong understanding of the MITRE ATT&CK framework and the ability to think like an adversary to identify "blind spots" in our defence.

Nice to have

  • AI/ML Security Interest: Familiarity with the unique security challenges of an AI first company and other common AI solutions such as LLMs.
  • Regulated Industry Experience: Prior experience working in BioTech, Pharma where data integrity and regulatory compliance are paramount.
  • Advanced Security Certifications: Holding industry‑recognised credentials such as GSE, OSCP, CISSP or professional‑level Cloud Security Engineer certifications.
  • Application Security (AppSec): Experience with SAST/DAST/SCA tools and a strong understanding of the OWASP Top 10 vulnerabilities.
  • Zero Trust Implementation: Past success in transitioning an organisation away from traditional perimeter‑based security towards a mature Zero Trust model.
  • SecOps Maturity: Experience building or scaling a Security Operations Centre (SOC) or a Modern Detection and Response (MDR) function.
  • Collaboration Tool Mastery: Advanced experience securing and automating SaaS. In particular, Google Workspace, the Atlassian stack (Jira/Confluence), Slack.
  • Bio‑Pharma Experience: Prior exposure to GxP validation, clinical trial data protections, or the nuances of Lab‑IT security.
  • Privacy Engineering: Knowledge of PETs (Privacy Enhancing Technologies) like differential privacy or homomorphic encryption.

We are committed to equal employment opportunities regardless of sex, race, religion or belief, ethnic or national origin, disability, age, citizenship, marital, domestic or civil partnership status, sexual orientation, gender identity, pregnancy or related condition (including breastfeeding) or any other basis protected by applicable law. If you have a disability or additional need that requires accommodation, please do not hesitate to let us know.

Senior Security Engineer, London London employer: Isomorphic Labs Limited

Isomorphic Labs is an exceptional employer, offering a dynamic work environment in London where innovation meets purpose. As a Senior Security Engineer, you will be at the forefront of securing cutting-edge AI technologies that aim to revolutionise drug discovery, with ample opportunities for professional growth and collaboration within a culture that values curiosity and proactive problem-solving. Enjoy competitive benefits and the chance to contribute to life-changing advancements in healthcare while working alongside passionate experts in the field.

Isomorphic Labs Limited

Contact Details:

Isomorphic Labs Limited Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior Security Engineer, London London

Tip Number 1

Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those related to security engineering. This gives potential employers a taste of what you can do and sets you apart from the crowd.

Tip Number 3

Prepare for interviews by brushing up on common security scenarios and challenges. Practice articulating your thought process and problem-solving skills, as this is key for roles like Senior Security Engineer.

Tip Number 4

Don't forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive about their job search!

We think you need these skills to ace Senior Security Engineer, London London

Cloud Engineering Proficiency
Network Security Fundamentals
Identity & Access Management
Infrastructure as Code (IaC) Security
DevSecOps Tooling
Container Security
Analytical Risk Management

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience with cloud security and AI platforms. We want to see how your skills align with our mission at Isomorphic Labs!

Show Off Your Problem-Solving Skills:In your application, share examples of how you've tackled complex security challenges in the past. We love proactive problem-solvers who can think outside the box!

Be Clear and Concise:Keep your writing straightforward and to the point. We appreciate clarity, especially when it comes to technical details. Make it easy for us to see your qualifications!

Apply Through Our Website:Don’t forget to submit your application through our website! It’s the best way for us to receive your details and get you into our hiring process smoothly.

How to prepare for a job interview at Isomorphic Labs Limited

Know Your Stuff

Make sure you brush up on your cloud security knowledge, especially if you're familiar with GCP. Be ready to discuss specific security measures you've implemented in the past, particularly around Infrastructure as Code and container security.

Show Off Your Problem-Solving Skills

Prepare examples of how you've tackled complex security challenges. Think about times when you had to break down a multifaceted issue into manageable tasks and how you communicated those solutions to non-technical stakeholders.

Get Familiar with the Company’s Tech Stack

Research Isomorphic Labs' AI platforms and HPC infrastructure. Understanding their technology will help you tailor your answers and demonstrate your genuine interest in their work and how you can contribute.

Be Ready for Technical Assessments

Expect to dive deep into technical assessments during the interview. Brush up on threat modelling, risk assessment, and secure CI/CD practices. Being able to articulate your thought process will show that you’re proactive and detail-oriented.