Skip to content

Open nowPosted 75 days ago

Senior Security Engineer

cmgx11 open roles

Where
London
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Security Engineercmgx · London
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on cmgx's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.4% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.5%1 day
  2. 3.5%3 days
  3. 7.4%7 days
  4. 13.2%14 days
  5. 34.6%30 days
This job: posted 75 days ago

The posting

The Company

Capital Markets Gateway LLC (CMG) is a capital markets-focused fintech transforming global equity capital markets (ECM) through data, technology, and connectivity. As the preferred source for ECM analytics and the first network connecting the buy-side and sell-side for ECM workflows, we are committed to reshaping how capital markets operate. Founded in 2017 by a team of ECM practitioners, CMG has completed three successful fundraising rounds and is backed by a group of the world’s most prestigious financial institutions. The CMG platform is currently relied upon by 25 investment banks and 135 asset managers representing over $40 trillion in AUM. For more information, please visit www.cmgx.io.

The Role

We are hiring a Senior Security Engineer to lead our security risk management and governance work. This is a senior individual-contributor role for someone who thrives on owning large, ambiguous initiatives end-to-end and turning them into shipped, operationalized programs. You will report directly to the CISO, own cross-program initiatives, and collaborate closely with senior leadership across the firm.

The core of the role is hands-on security risk management, threat modeling, security risk assessments, and security design and architecture reviews, paired with the governance and process work that scales the program. You will partner on customer due-diligence and SOC 2 evidence and turn security controls into repeatable workflows that fit how the business already works. You will apply that lens across the full control landscape: cloud security, supply-chain and vulnerability management, endpoint and identity, detection and response, and AI security.

CMG operates in a highly regulated, client-facing market, so scope and impact here are unusually large for the level. We value strong collaboration and a deep sense of ownership: you will be trusted to take initiatives and run with them, often without an established process or a big team behind you. The defining shift for the program is moving from reactive to proactive, and this role is central to it. This is a high-growth-potential role: we expect the right person to start as a senior individual-contributor and grow into broader leadership, including people's leadership, as the function scales.

Responsibilities

  • Lead threat modeling across products, infrastructure, and new initiatives, identifying and prioritizing risks, attack surfaces, and vulnerabilities.
  • Conduct security risk assessments and translate findings into pragmatic, risk-based remediation prioritized by impact and blast radius.
  • Run security design and architecture reviews, partnering with Engineering and DevOps to reduce risk through secure design and simplicity, not just added controls.
  • Partner on customer due-diligence (DDQ) and SOC 2 Type II evidence gathering, keeping compliance sustainable rather than fire-drilled.
  • Build repeatable security workflows that embed controls into existing engineering processes instead of creating parallel ones.
  • Develop and maintain clear, role-relevant security policies, standards, and procedures, and drive consensus without direct authority.
  • Understand and implement controls for supply-chain risk and vulnerability management, including CI/CD enforcement and dependency hygiene, and build vulnerability triage workflows that score real risk by exploitability, reachability, and compensating controls rather than raw CVSS.
  • Harden and secure our cloud environment (Azure), partnering with platform engineering on secure configuration, reviewing and remediating vulnerabilities, identity and network controls, posture management, and logging and detection.
  • Strengthen endpoint and identity controls across a global, remote workforce: least privilege, phishing-resistant MFA, and privileged access controls.
  • Support detection and response, partnering with our DFIR and MDR relationships and helping mature toward a proactive posture.
  • Address AI security risks (prompt injection, data poisoning, model and agent governance) and help keep AI controls ahead of adoption.
  • Take ownership of large, loosely defined initiatives and drive them from problem framing to operationalized program.
  • Work closely with senior leadership across the firm, bringing structure to ambiguity and sequencing work against risk.
  • Surface risk early, challenge assumptions, and communicate clearly to both technical teams and senior stakeholders.

Qualifications

  • Have 6+ years of hands-on security experience, with real depth in security risk management: threat modeling, risk assessments, and security design and architecture review.
  • Have run governance, risk, and compliance work in practice, including audit and customer due-diligence support (SOC 2 or similar), and made it operational rather than just documented.
  • Have thrived in a startup or other small, fast-paced environment, owning large, ambiguous initiatives end-to-end with little scaffolding and shipping them.
  • Have working breadth across the control landscape: cloud security, supply-chain and vulnerability management, endpoint and identity, and detection and response.
  • Are genuinely technical: comfortable in cloud environments Azure, CI/CD, Microsoft 365, and at least one scripting language (e.g. Python, Bash, PowerShell), so your controls hold up in engineering reality.
  • Lead with empathy and influence, and distill complex security concepts into clear, actionable guidance for technical and non-technical audiences alike.
  • Thrive navigating ambiguity and make sound, risk-based calls with incomplete information.
  • Work effectively in a remote-first setup: most of the team is remote, with a small London in-office presence, so you communicate crisply and operate well asynchronously.
  • Navigate an organization to get things done you know who to pull in for information or alignment, and you drive that alignment without formal authority.

Nice to have

  • Have banking, fintech, or other regulated industry experience.
  • Use AI tooling fluently in your own day-to-day work and are eager to integrate it into security workflows as a force multiplier.
  • Have a bias toward automating repeatable security work — scripting, tooling, and process — to scale your impact.
  • Be familiar with AI and agentic security risks (prompt injection, data poisoning, model and agent governance).
  • Have experience mapping security frameworks (NIST CSF, ISO 27001, OWASP, NIST AI RMF).
  • Have hands-on exposure to detection and response, red-team, or pen-test work.
  • Have experience with our stack: Entra ID, GitHub Enterprise Cloud (GHAS, Actions, Dependabot), Sentinel, Zscaler, Intune, Vanta, and the Atlassian suite.
  • Hold relevant certifications (e.g. CISSP, CRISC, OSCP) — valued but not required.

Our Values

  • We innovate with purpose
  • We focus on outcomes vs. output
  • We believe diverse and inclusive teams fuel innovation
  • We are humble yet candid
  • We do right by the customer

What We Offer

  • Equity
  • Unlimited PTO (28 days including bank holidays + unlimited additional paid leave)
  • Comprehensive benefits program managed by Globalization Partners
  • Premium life and income protection
  • Top private medical and dental insurance
  • Employee Assistance Program (EAP)
  • Pension contributions
  • Hybrid work environment
  • Education reimbursement
  • Continuous learning opportunities
  • Employee referral bonus
  • Parental leave

CMG embraces our ongoing commitment to building a culture reflecting the people, perspectives, and passions it represents. We will accept nothing less than equity, inclusion, and belonging for all. With the only constant in life being change, we will always listen, learn, and improve for the betterment of our teams, customers, and communities. CMG is proud to be an Equal Opportunity Employer.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against cmgx's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on cmgx's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    cmgx's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.