Skip to content

Open nowPosted 36 days ago

Security Engineer

intropic12 open roles

Where
London UK
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity Engineerintropic · London UK
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on intropic's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 36 days ago

The posting

Who We Are

Intropic is a financial information and software company operating at the cutting edge of global capital markets. We pair modern technology (elastic cloud infrastructure and agentic AI systems) with deep market expertise to build information products that the world's most sophisticated financial institutions rely on every day. Our clients include hedge funds, proprietary trading firms, index fund managers, large asset managers, sovereign wealth funds, and investment banks, who use our products to generate alpha, manage risk, and make better decisions in fast-moving markets. We're best known for our Index Rebalance Forecast products, and we're now extending that edge into several other strategies. Headquartered in London's Canary Wharf and expanding globally, we're a team that moves fast, takes real ownership, and holds itself to a high standard of rigour and integrity.

The Role

You will own the entire security stack at Intropic. Cloud, endpoints, detection and response, compliance, IT, and the security of our growing AI agent usage all sit with you. You set the priorities, you do the work, and you answer for the results.

This suits someone who would enjoy the opportunity to lead security at a growing FinTech, rather than operating with small scope in a large team. On a given week you might harden an EKS cluster, tune a detection, scope a pentest, and work out how to give engineers safe access to coding agents. The AI security work in particular is a largely unsolved, very interesting problem, and you will define our approach to it. The role includes out-of-hours response to security alerts.

This role is suitable for someone with 3+ years of experience in security.

Responsibilities

Security Engineering - 60%

  • Engineer and manage the security of our cloud infrastructure across AWS and GCP, from individual EC2 instances to a large EKS microservice estate.
  • Run detection and response: triage alerts, expand coverage, and keep the tooling honest. If a true positive alert fires at 9pm and it matters, you are the person who handles it.
  • Threat model new products and services before they ship, and embed security checks directly into CI/CD.
  • Define what good looks like when it comes to the security of our external SaaS app integrations. This might look like building out an apporval workflow to approve new OAuth connections for our Google accounts.
  • Secure our use of AI agents (Claude Code, Codex, and similar) and our production generative AI systems, both client facing and internal. Work with each business unit to find mitigations that protect the company without slowing it down.
  • Establish an automated patching system for systems across every part of our cloud.

GRC - 20%

  • Own SOC 2. Run the yearly Type II audit, scope the annual web application pentest, and automate as much of the evidence collection in Drata as you can.
  • Evaluate where gaps exist in our security policies and build out new policies to fill those gaps.

IT - 20%

  • Assist with running onboarding and offboarding for joiners and leavers, building any automation that makes both fast and complete.
  • Assist with managing our fleet of roughly 100 endpoints through Jamf and Intune (about 90% macOS, 10% Windows).
  • Respond to colleagues' security and IT access questions, and resolve them quickly and courteously.
  • Own and manage our core SaaS estate, including Google Workspace and GitLab access, scripting away the repetitive parts.

Requirements

  • 3+ years security experience spanning multiple domains. You don’t have to have directly led a team before although it would be a plus.
  • Advanced, hands-on knowledge of a wide range of AWS services, including but not limited to EC2, S3, GuardDuty, Lambda, ECS, and EKS
  • Practical experience with Kubernetes, ideally EKS.
  • Experience threat modelling web applications and responding to real security incidents.
  • Experience using AI agents, in your own workflow or in security tooling.
  • Understanding of SOC 2 and comfort with Git.
  • Working knowledge of Jamf.
  • Solid scripting ability in Python or Bash, enough to automate a repetitive task and glue two systems together through their APIs
  • Willingness and interest in learning and upskilling in areas of security, IT, or GRC you have not encountered before.
  • Ability to pivot quickly between different domains while keeping a high attention to detail and courteousness to end-users.

Nice to Have

  • Experience of using both Jamf and InTune at a high level.
  • Experience securing microservice architectures or EKS clusters specifically.
  • Experience using AI agents for production security workflows.
  • Ability to use SQL for detection and incident investigation.
  • Having rolled out DAST or SAST in a production environment.
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against intropic's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on intropic's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    intropic's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.