Start Your Search Here

push notification bell

Would you like to receive notifications about IT & Technology jobs in Greater London?

push notification bell

You have blocked notifications

Oops! You have blocked notifications. Click here for more info

You have blocked notifications, please check your browser settings.

push notification bell

You're currently subscribed to job notifications

Want to change your notifications for job alerts?

push notification bell

Subscribe to notifications

You will no longer receive notifications

Job Search

McCabe & Barton

Greater London / Global

Senior Application Security Engineer

Job Description

We are working with a leading private equity firm seeking a Cyber Security Engineer to join their London office. This is an exciting opportunity to join a fast-paced, highly regulated environment and play a key role in strengthening cyber security controls across critical business platforms and infrastructure.

Key Responsibilities

  • Drive triage and remediation governance for the AI-assisted code audit of proprietary products.
  • Support the rollout of FIDO2/WebAuthn across all privileged accounts with access to proprietary systems and Entra admin roles.
  • Assist with third-party trust boundary reviews.
  • Maintain and enhance the emergency patching runbook for critical vulnerabilities (CVSS 9.0+).
  • Contribute to the micro-segmentation of proprietary applications from general M365 workloads, including honeytoken deployment for early-warning threat detection.
  • Run continuous External Attack Surface Management (EASM) across the firm's external footprint and cross-reference findings weekly with the CMDB.
  • Support SIEM and UEBA enhancements, building detection logic around normal deal workflow behavioural baselines.

Skills & Experience

  • Previous experience within Security Operations, Cyber Security Analysis, or Threat Analysis.
  • Experience working within financial services, private equity, or another regulated environment
  • Hands-on experience with SIEM, UEBA, EDR, and identity management technologies including Entra ID, Conditional Access, and FIDO2/WebAuthn.
  • Good understanding of application security vulnerabilities including deserialisation, IDOR, injection, and authorisation logic flaws.
  • Working knowledge of software supply chain security practices, including SBOMs, Software Composition Analysis (SCA), and dependency management.
  • Understanding of DORA ICT risk obligations is desirable
  • Self-motivated and capable of operating independently within a fast-paced, evolving environment.
#J-18808-Ljbffr
Apply Now

Similar Opportunities

View all jobs