A leading investment firm is looking to hire an experienced Information Security Engineer to play a key role in strengthening and evolving its security function. This position offers a blend of hands-on technical security, security assurance, risk management, and governance, making it ideal for someone who enjoys operating across both engineering and GRC disciplines. You'll work closely with technology teams, auditors, compliance, legal, and business stakeholders to assess security controls, drive remediation efforts, and help shape the firm's overall security strategy.
Key Responsibilities
Lead and support internal and external security audits, regulatory reviews, client due diligence exercises, and security assessments.
Evaluate the effectiveness of security controls across infrastructure, cloud, identity, endpoint security, vulnerability management, monitoring, and data protection.
Manage audit findings, risk treatment plans, control deficiencies, and remediation activities through to completion.
Conduct security and technology risk assessments, documenting risks, mitigations, and improvement initiatives.
Act as a trusted advisor to technical and business teams on security controls, regulatory requirements, and best practices.
Provide oversight of security processes including IAM, incident response, vulnerability management, cloud security, and security monitoring.
Develop and deliver reporting on security posture, audit activity, control effectiveness, and material risks.
Identify opportunities to improve security processes, tooling, automation, and reporting capabilities.
Serve as a key point of contact for auditors, assessors, and other assurance stakeholders.
What we are looking for
5+ years of experience within Information Security, Security Engineering, Security Operations, Technology Risk, Security Assurance, or a related field.
Strong understanding of enterprise security domains including:
Identity & Access Management (IAM)
Vulnerability Management
Endpoint Security
Cloud Security
Logging & Monitoring
Incident Management
Data Protection
Experience supporting audits, regulatory assessments, security reviews, or assurance programmes.
Working knowledge of security frameworks such as ISO 27001, NIST CSF, NIST 800-53, or CIS Controls.
Ability to assess technical controls and translate security requirements into practical, business-aligned solutions.
Strong stakeholder management and communication skills, with the confidence to challenge where required.
Financial services, asset management, hedge fund, banking, or other regulated industry experience.
Experience with security tooling including SIEM, EDR, cloud security, vulnerability management, identity platforms, and GRC tools.
Familiarity with UK financial services regulatory and operational resilience requirements.
Professional certifications such as CISSP, CISM, CISA, CRISC, or ISO 27001 Lead Auditor/Implementer
Numbers & Facts
Location
Greenwich, CT
Skills
Asset Managementunmatched
Auditingunmatched
Automationunmatched
Banking Servicesunmatched
Best Practicesunmatched
CISA - Certified Information Systems Auditorunmatched
CISM - Certified Information Security Managerunmatched
CISSP - Certified Information Systems Security Professionalunmatched
Cloud Computingunmatched
Communication Skillsunmatched
Computer Securityunmatched
Documentationunmatched
Due Diligenceunmatched
Endpoint Securityunmatched
Enterprise Protectionunmatched
External Auditunmatched
Financial Regulationsunmatched
Financial Servicesunmatched
Hedge Fundsunmatched
ISO (International Organization for Standardization)unmatched
Identity Data Managementunmatched
Incident Managementunmatched
Incident Responseunmatched
Information/Data Security (InfoSec)unmatched
Internal Auditunmatched
Legalunmatched
Machine Toolunmatched
Process Improvementunmatched
Regulationsunmatched
Regulatory Requirementsunmatched
Reporting Skillsunmatched
Riskunmatched
Risk Analysisunmatched
Risk Managementunmatched
Security Analysisunmatched
Security Auditingunmatched
Security Information and Event Management (SIEM)unmatched
Security Infrastructureunmatched
Security Monitoringunmatched
Team Playerunmatched
Technical Analysisunmatched
Technical Operationsunmatched
Technology Analysisunmatched
Treatment Planunmatched
U.S. National Institute of Standards and Technology (NIST)unmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.