At a Glance
- Tasks: Join our team as a hands-on Security Engineer, ensuring secure trading processes and infrastructure.
- Company: Be part of a leading blockchain company committed to innovation and security.
- Benefits: Enjoy competitive salary, flexible work options, and opportunities for professional growth.
- Other info: Diverse and inclusive workplace with excellent career advancement opportunities.
- Why this job: Make a real impact in the financial sector while working with cutting-edge technology.
- Qualifications: 5+ years in security engineering with expertise in threat modelling and risk assessment.
The predicted salary is between 70000 - 90000 £ per year.
You’ll be the hands-on security engineer embedded with the Institutional Trading and Financial Operations (FinOps) team. Your focus is the secure operation of off-chain trading processes and infrastructure that empowers our institutional business: integrations, signing flows, key custody interfaces, middle-office workflows, order routing and settle pipelines that handle significant capital. You will support risk assessments, operating controls, automation to detect operational anomalies and remediation coordination. This is a high-visibility role where you will focus on operational security engineering—ensuring that the tools and processes our traders use are resilient against both external threats and internal errors. This role does not require smart-contract auditing.
What You Will Do
- Partner with Trading, Middle Office and Quant (Institutional FinOps) teams to map out inventory trading systems, data flows, third-party integrations and custody/settlement touchpoints.
- Conduct deep-dive assessments mapping critical assets and workflows to identify structural vulnerabilities.
- You will be responsible for defining the Target State and drafting the strategic Risk Treatment Plans (RTP) required to meet institutional-grade standards (e.g., CCSS, NIST, DORA).
- Act as the primary security liaison for Senior Management and third-party vendors.
- You will translate complex technical gaps into actionable business risk summaries, drive vendor evaluations for core security infrastructure, and manage the project lifecycle for high-impact posture uplifts.
- Implement and maintain monitoring for FinOps-specific security signals such as abnormal order patterns, signature misuse, unusual settlements.
- You will integrate these signals into our SIEM/SOAR for real-time response.
- Support secrets and key-management hygiene.
- You will ensure app/service keys are stored in KMS/Vault, scoped to least privilege and rotated automatically to prevent credential leakage.
- Assist product security in triage of SAST/SCA findings for FinOps-related repositories.
- You will help implement CI checks and remediation playbooks.
- Participate in incident exercises, post-incident reviews and remediation tracking for trading incidents.
- Document controls and produce concise risk summaries for FinOps leads and the Security.
What You Will Need
- 5+ years in security engineering, platform security, or application security experience.
- Proven expertise in Threat Modeling.
- Ability to perform structured reviews (e.g., STRIDE) of complex data flows and operational processes.
- Experience with observability and detection tooling (SIEM, logs, metrics) and ability to write basic detection rules.
- Practical experience with KMS/HSM, secrets management platforms (Vault, 1Password, AWS/GCP KMS), IAM patterns and least-privilege.
- Exceptional ability to translate “Technical Debt” into Business Risk for C-suite stakeholders (CFO, CTO, Head of Trading).
- Ability to raise, read and audit Pull Requests in at least one language used in our stack (TypeScript, Java/Kotlin, Python).
- Experience conducting technical due diligence and scoping for third-party security integrations.
Nice to Have
- Familiarity with trading systems or financial operations (market-making, execution, settlement) or close collaboration background with trading/quant teams.
- Exposure to blockchain on-chain concepts (wallets, addresses, transactions) but no requirement to audit contracts.
- Familiarity with SOC operations, and post-incident forensic analysis.
- Familiarity with SOC2, ISO 27001, or financial audit requirements.
- Any relevant industry certification.
Blockchain is committed to diversity and inclusion in the workplace and is proud to be an equal opportunity employer. We prohibit discrimination and harassment of any kind based on race, religion, color, national origin, gender, gender expression, sex, sexual orientation, age, marital status, veteran status, disability status or any other characteristic protected by law. This policy applies to all employment practices within our organization, including hiring, recruiting, promotion, termination, layoff, recall, leave of absence, and apprenticeship. Blockchain makes hiring decisions based solely on qualifications, merit, and business needs at the time.
Security Engineer (Institutional Trading) employer: Prudence Holdings
At Blockchain, we pride ourselves on fostering a dynamic and inclusive work environment where innovation thrives. As a Security Engineer embedded within the Institutional Trading and Financial Operations team, you will have the opportunity to work on high-impact projects that directly influence our institutional business. With a strong emphasis on employee growth, we offer continuous learning opportunities and a collaborative culture that values diverse perspectives, making us an exceptional employer for those seeking meaningful and rewarding careers in the financial technology sector.
StudySmarter Expert Advice🤫
We think this is how you could land Security Engineer (Institutional Trading)
✨Tip Number 1
Network like a pro! Reach out to folks in the trading and financial ops space on LinkedIn. Join relevant groups, attend webinars, and don’t be shy about asking for informational chats. You never know who might have the inside scoop on job openings!
✨Tip Number 2
Show off your skills! Create a portfolio or a GitHub repository showcasing your security engineering projects. Highlight your experience with threat modelling and detection tooling. This gives potential employers a tangible look at what you can bring to the table.
✨Tip Number 3
Prepare for interviews by brushing up on your knowledge of trading systems and operational security. Be ready to discuss how you would handle specific scenarios related to risk assessments and incident responses. Practice makes perfect!
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who take that extra step to connect directly with us. Good luck!
We think you need these skills to ace Security Engineer (Institutional Trading)
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Security Engineer role. Highlight your experience in security engineering, especially any hands-on work with trading systems or financial operations. We want to see how your skills align with what we need!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about security engineering and how your background makes you a perfect fit for our team. Don’t forget to mention any relevant projects or experiences that showcase your expertise.
Showcase Your Technical Skills:In your application, be sure to highlight your technical skills, especially in threat modelling and observability tools. We love seeing candidates who can translate complex technical concepts into business risks, so don’t hold back on those details!
Apply Through Our Website:We encourage you to apply through our website for the best chance of getting noticed. It’s super easy, and you’ll be able to keep track of your application status. Plus, we love seeing applications come directly from our site!
How to prepare for a job interview at Prudence Holdings
✨Know Your Stuff
Make sure you brush up on your security engineering knowledge, especially around threat modelling and operational processes. Be ready to discuss specific tools and methodologies you've used in the past, like SIEM or KMS, as this will show you're not just familiar with the concepts but have practical experience.
✨Speak Their Language
When discussing technical gaps or risk assessments, use terminology that resonates with the trading and financial operations teams. This means translating complex security issues into business risks that C-suite stakeholders can understand. Practise how you would explain these concepts clearly and concisely.
✨Show Your Problem-Solving Skills
Prepare to share examples of how you've tackled security challenges in previous roles. Think about specific incidents where you identified vulnerabilities or implemented monitoring solutions. Highlight your ability to conduct structured reviews and how you’ve contributed to improving security posture.
✨Engage with Questions
Interviews are a two-way street! Prepare thoughtful questions about the company's security practices, their approach to incident response, or how they integrate security within their trading systems. This shows your genuine interest in the role and helps you assess if it's the right fit for you.