Senior Security Engineer

Senior Security Engineer

Full-Time 70000 - 85000 £ / year (est.) Home office (partial)
SLAMcore

At a Glance

  • Tasks: Strengthen security through design, implementation, and improvement of security controls and cloud solutions.
  • Company: Join Copper, a leading firm in digital asset infrastructure with a dynamic culture.
  • Benefits: Enjoy 35 days paid time off, comprehensive medical insurance, and enhanced pension contributions.
  • Other info: Collaborative team culture with opportunities for growth and learning.
  • Why this job: Make a real impact on security in a fast-paced, innovative environment.
  • Qualifications: Experience in security engineering, IAM solutions, and cloud security is essential.

The predicted salary is between 70000 - 85000 £ per year.

Since being founded in 2018, Copper has been building the standard for institutional digital asset infrastructure with a focus on custody, collateral management, and prime services. Led by Amar Kuchinad, Copper's Global CEO, the firm provides a comprehensive suite of custody, trading and settlement solutions that reduce counterparty risk and bring greater capital and operational efficiency to digital asset markets.

At the heart of Copper's offering is Multi-Party Computation (MPC) technology – the gold standard in secure custody. Copper’s multi-award winning custody system is unique in that it can be connected to centralised exchanges, DeFi applications and even staking pools without the assets leaving the custody. Built on top of this state-of-the-art custody, ClearLoop is the first solution in the market that overcomes a growing industry challenge; counterparty risk with exchanges. This solution underpins a full prime services offering, connecting global exchanges, and enabling customers to trade and settle directly from the safety of their MPC-secured wallets.

By reducing settlement time for transfers to a few milliseconds (without blockchain network dependency) and offering enhanced security measures, ClearLoop is rapidly reshaping the way asset managers trade and manage capital. In addition to industry-leading security certifications, Copper has one of the strongest insurance coverages in the industry from an A+ rated insurer, positioning the firm as the partner of choice for institutions seeking to safeguard their assets.

Department Purpose
We aim to achieve a balance between corporate culture and start-up culture, and at the same time be close to product solutions. Therefore, we divide our department into small self-sufficient teams that can make decisions on their own. This applies to all stages of product production: from conceptualisation to architecture, to build, to release, to iteration and support.

Team Purpose
Copper’s Information Security department keeps the business’ systems and network resources secure and protects the company, employees, and client data. The Infrastructure Security team focuses on providing objective oversight and validation of Copper’s infrastructure security controls and processes.

Role Purpose
As a Senior Security Engineer, you will play a key role in strengthening Copper's security posture through the design, implementation, and continuous improvement of security controls, identity services, cloud security solutions, and governance processes. Working closely with technology, infrastructure, and business teams, you will lead initiatives to protect Copper's systems, data, and digital assets. You will be responsible for enhancing our security capabilities across identity and access management, cloud platforms, endpoint security, vulnerability management, automation, and security monitoring, ensuring security controls remain effective, scalable, and aligned to business and regulatory requirements. This is a hands-on technical role requiring strong security engineering expertise, a proactive approach to risk reduction, and the ability to influence security best practices across the organisation.

Key Responsibilities

  • Identity and Access Management (IAM)
    Design, implement, and maintain Identity and Access Management (IAM) solutions, including Microsoft Entra ID, Entra Identity Governance, AWS IAM Identity Centre, and supporting authentication and authorisation services. Manage permission settings and access controls to ensure secure and efficient user access to company resources.
  • Security Systems Configuration and Analysis
    Ensure security systems are configured according to specified requirements and industry best practices. Assess security configurations across cloud and endpoint platforms, benchmark controls against CIS, STIG, SOC2, and internal security standards, and drive remediation activities to improve security posture.
  • Security Solution Inventory and Maintenance
    Own the administration, configuration, and lifecycle management of security platforms across cloud, endpoint, identity, and network domains. Maintain accurate inventories of security tooling and integrations. Evaluate new technologies and recommend enhancements to improve security effectiveness and operational efficiency. Partner with vendors and internal stakeholders to troubleshoot issues and maximise platform value.
  • Security Practices and Technical Advice
    Act as a trusted security advisor to technical teams, business stakeholders, and senior leadership, providing guidance on security architecture, risk reduction, and regulatory compliance. Provide technical advice on security measures and potential enhancements. Create or update policies and procedures to align with industry regulations and best practices.
  • Security Risk Management
    Manage vulnerability management activities across cloud infrastructure, endpoints, SaaS applications, and identity platforms using tools such as Wiz, Microsoft Defender, and ArmorCode. Prioritise and coordinate remediation efforts based on business impact, exploitability, and risk exposure. Conduct security assessments and threat modelling exercises for new projects and technologies. Ensure security controls align with SOC2, ISO27001, CIS Controls, and organisational risk management requirements. Produce reports and metrics demonstrating security posture, control effectiveness, and remediation progress.
  • Scripting and Automation
    Develop and maintain automation solutions using PowerShell, Python, Bash, and APIs to improve operational efficiency and reduce manual effort. Design, implement, and support Infrastructure as Code (IaC) solutions using Terraform and cloud-native tooling. Integrate security telemetry into SIEM platforms such as Microsoft Sentinel to improve threat detection and monitoring capabilities. Develop automated controls and workflows to enhance governance, compliance, and incident response processes.

Skills and Experience

Essential

  • Microsoft Entra ID / Identity Governance: Extensive experience administering Microsoft Entra ID, including Conditional Access, Identity Protection, Privileged Identity Management (PIM), Entitlement Management, Access Reviews, Lifecycle Workflows, and application integrations. Experience of implementing governance controls within hybrid Microsoft and AWS environments.
  • AWS Security: Experience securing AWS environments using services such as IAM, Security Hub, GuardDuty, CloudTrail, Config, AWS Organizations, Route 53, and Key Management Service (KMS).
  • Microsoft 365 and Azure Security: Strong experience with Microsoft security technologies including Microsoft Defender XDR, Microsoft Sentinel, Microsoft Purview, Intune, Entra ID, Azure Security services, and Information Protection capabilities.
  • Scripting and Automation: Demonstrated ability in using scripting languages like PowerShell, Bash, and Python to automate security tasks, streamline processes, and enhance system efficiencies.
  • System and Application Hardening: Skilled in the assessment and hardening of operating systems and SaaS applications, adhering to CIS and STIG standards. This includes a comprehensive understanding of the best practices in system security and the application of these practices to ensure robust defence against cyber threats.
  • SaaS Security: Experience securing and administering SaaS platforms through SSO, SCIM provisioning, Conditional Access, entitlement governance, and lifecycle management.
  • Endpoint Security: Experience managing endpoint security solutions across Windows and macOS environments, including EDR, device hardening, application control, and compliance monitoring.
  • Network Perimeter Security: Experience securing enterprise networks using firewalls, Web Application Firewalls (WAF), Secure Web Gateways (SWG), Zero Trust Network Access (ZTNA), DNS security solutions, and cloud-native network controls.

Desirable

  • Secure Web Gateway Management: Experience in configuring and managing Secure Web Gateways, such as Zscaler, iBoss, and Netskope, to protect against web-based threats and enforce company security policies.
  • Binary Execution Control: Experience with solutions like AppLocker, Defender Application Control, Santa, ThreatLocker across both Mac and Windows endpoints.

Why Copper?
At Copper, we keep innovation, openness, and curiosity at the centre of everything we do. Here, bold ideas get the spotlight, learning is constant, and diversity shapes our team from the ground up. Jump into a fast-moving, dynamic team that loves a challenge and knows how to have fun along the way. Collaboration is just as important as results—you’ll be surrounded by smart, driven colleagues in London and across our APAC, Switzerland, UAE, and US offices.

Hybrid working model – we believe in the value of bringing people together and at the same time we embrace the adaptability of flexibly working. Diversity and inclusion matter to us – they’re woven into Copper life. From employee-led groups like Women at Copper to a committee focused on community and wellbeing, you’ll have a network that supports you from day one. Everyone's voice matters. If you’re looking to ramp up your career, or keen to do something new in your field, with us, you’ll keep moving forward. Ready to make your mark, keep growing, and join a supportive, dynamic team? Copper’s the place.

The interview process at Copper
Our interview process is designed to be thoughtful, efficient, and engaging. While specific steps may vary slightly depending on the role, the typical journey includes:

  • Initial Screening
    A brief conversation with our Talent Acquisition team to explore your background, motivations, and alignment with the role.
  • Technical Interview
    A virtual session conducted via Microsoft Teams, where you'll engage with team members to discuss relevant skills, problem-solving approaches, and technical experience.
  • In-Person Interview
    A conversation focused on team dynamics, collaboration style, and any final technical questions. This may be with cross-functional peers or leadership.

Additional steps may be added based on the role's complexity or seniority. We aim to keep the process transparent and respectful of your time.

Benefits
In return for everything you can bring to Copper, we can offer you an exciting, challenging role in a fast-growing and dynamic business, with career opportunities and a welcoming working environment. Some of our key UK benefits are highlighted below:

  • Paid Time Off - A minimum of 35 days of paid time off per year, inclusive of annual leave and public holidays. Employees also receive one additional day of annual leave for each year of service.
  • Comprehensive Medical Insurance - Inclusive of dental, optical, audiology, and mental health coverage, with medical history disregarded.
  • Life Insurance.
  • Enhanced Pension Contributions - Includes an enhanced employer matching contribution.
  • 24/7 Employee Assistance Programme (EAP).

Copper is an equal opportunity employer. We embrace diversity and equal opportunities in a serious way. We are committed to building a team that represents a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better our work will be. So, bring us your experience, perspectives, and skills. It is in our differences that we will continue to grow and ensure Copper is transforming how institutional investors engage with digital assets. Copper is a Disability Confident Employer, please let us know if you have a disability. If you require us to provide any assistance during the recruitment process, then we would ask you to highlight this to us and we will be happy to accommodate.

Senior Security Engineer employer: SLAMcore

At SLAMcore, we pride ourselves on being an exceptional employer that values innovation and collaboration. Our supportive work culture fosters personal and professional growth, offering ample opportunities for career advancement while ensuring a meaningful impact on our users' experiences. Located in a vibrant tech hub, we provide a dynamic environment where your contributions are recognised and celebrated, making every day rewarding.

SLAMcore

Contact Details:

SLAMcore Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior Security Engineer

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including SLAMcore, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through SLAMcore

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at SLAMcore. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Senior Security Engineer

Identity and Access Management (IAM)
Microsoft Entra ID
AWS Security
Microsoft 365 Security
Scripting (PowerShell, Python, Bash)
System and Application Hardening
SaaS Security

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at SLAMcore insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to SLAMcore that you’re committed to staying ahead in the game.

How to prepare for a job interview at SLAMcore

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at SLAMcore to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at SLAMcore.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.