At a Glance
- Tasks: Lead threat modelling and secure design reviews while integrating security tools in CI/CD.
- Company: Join a dynamic team focused on enhancing security in the financial services sector.
- Benefits: Enjoy a competitive salary, flexible remote work, and opportunities for professional growth.
- Why this job: Be hands-on in solving real-world security challenges and make a tangible impact.
- Qualifications: Must have strong AppSec experience and knowledge of GCP or Azure security.
- Other info: This role is perfect for engineers who thrive on delivering results, not for managers.
The predicted salary is between 48000 - 72000 £ per year.
Department: Cyber Security
Reports To: Head of Security Architecture & Engineering
Salary: £600 Per Day Inside IR35
Location: Central London (3 days per week on site, 2 days per week remote)
The Role
We are looking for a hands-on Application Security Engineer with a strong engineering mindset and a background in financial services, insurance, or fintech. You will be embedded with product and engineering teams, driving secure development practices and owning security controls across our SDLC and cloud-native platforms. This is a technical role, not for architects or managers - you will be writing code, integrating tools, running threat modelling sessions, and solving real-world security problems.
What You’ll Do
- Lead threat modelling, secure design reviews, and AppSec assessments.
- Integrate and automate SAST, DAST, SCA, and container scanning in CI/CD.
- Triage and drive remediation of vulnerabilities across cloud and app layers.
- Deliver security controls via code (Terraform, YAML, scripting).
- Support and improve cloud security posture (GCP/Azure).
- Run internal pen testing and security assessments.
- Build and manage a Security Champions network.
- Be a visible, vocal SME on all things AppSec.
What You’ll Bring
- Strong hands-on experience in AppSec with a background in software engineering or DevOps.
- Deep knowledge of GCP (preferred) or Azure security.
- Experience with Kubernetes, container security, and cloud infra.
- Proficiency in IaC (Terraform), scripting (Python, etc.), and CI/CD pipelines.
- Excellent communication skills - clear, concise, and credible with engineers.
- Exposure to regulated environments (FS, insurance, fintech) is a big plus.
Not for You If...
You’re an architect, people manager, or hands-off strategist. This is for engineers who deliver.
Cyber Security Engineer *INSURANCE EXPERIENCED* employer: MN Climate Innovation Finance Authority (MNCIFA)
Contact Detail:
MN Climate Innovation Finance Authority (MNCIFA) Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Cyber Security Engineer *INSURANCE EXPERIENCED*
✨Tip Number 1
Make sure to highlight your hands-on experience in application security and software engineering during networking opportunities. Engage with professionals in the insurance and fintech sectors, as they can provide valuable insights and potentially refer you to open positions.
✨Tip Number 2
Join relevant online communities or forums focused on cyber security, especially those that cater to the insurance industry. Participating in discussions can help you stay updated on industry trends and may lead to job leads or recommendations.
✨Tip Number 3
Attend industry conferences or meetups related to cyber security and insurance. These events are great for networking and often feature companies looking to hire talent directly, giving you a chance to make a personal connection.
✨Tip Number 4
Consider obtaining certifications that are highly regarded in the insurance sector, such as Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM). This can enhance your credibility and make you stand out to potential employers.
We think you need these skills to ace Cyber Security Engineer *INSURANCE EXPERIENCED*
Some tips for your application 🫡
Highlight Relevant Experience: Make sure to emphasise your experience in the insurance sector. Detail specific projects or roles where you applied your cyber security skills within financial services, insurance, or fintech.
Showcase Technical Skills: Clearly outline your hands-on experience with application security, cloud platforms (GCP or Azure), and tools like Terraform and CI/CD pipelines. Use specific examples to demonstrate your proficiency.
Tailor Your CV: Customise your CV to reflect the job description. Focus on your engineering mindset and ability to integrate security practices into development processes. Make it clear that you are not just an architect or manager but a hands-on engineer.
Craft a Strong Cover Letter: Write a compelling cover letter that connects your background in cyber security with the specific needs of the role. Mention your communication skills and how you can be a visible subject matter expert in AppSec.
How to prepare for a job interview at MN Climate Innovation Finance Authority (MNCIFA)
✨Showcase Your Technical Skills
Be prepared to discuss your hands-on experience with application security, coding, and cloud platforms. Bring examples of past projects where you integrated security practices into the development lifecycle.
✨Demonstrate Insurance Knowledge
Since the role requires insurance experience, be ready to talk about how your background in financial services or fintech has shaped your understanding of security challenges specific to these sectors.
✨Prepare for Scenario-Based Questions
Expect questions that assess your problem-solving skills in real-world scenarios. Think about how you would handle vulnerabilities or security assessments and be ready to explain your thought process.
✨Communicate Clearly and Confidently
Excellent communication is key. Practice explaining complex technical concepts in a clear and concise manner, as you'll need to convey your ideas effectively to both technical and non-technical stakeholders.