Senior Security Engineer (Governance, Risk & Compliance)
About the role
We run our technology department on one principle: agent-operated, human-supervised. Agents handle monitoring, routine operations, integration and a growing share of the code. People keep the decisions that carry consequences and we write down exactly which ones those are.
Four of them sit in Trust, the part of the department this role belongs to:
- Accepting risk on the company's behalf.
- Approving an agent to act without supervision.
- Deciding what data leaves our estate, and to which vendors.
- Signing off the evidence we give auditors and partners.
You will take them on alongside the Head of Technology at first, and hold them yourself once the controls and evidence behind them are yours. We expect that inside two quarters.
The work is engineering, not paperwork. You build the guardrails, then you are the person trusted to say where they sit. Wide remit, nothing between you and the people who decide things.
Roles & Responsibilities:
Risk. Own the register end to end, what goes on it, how it is rated, who carries each item, and the monthly review with the Head of Technology. It should answer what we are exposed to and who accepted it, current enough to be quoted in a paper without checking it first.
Identity and access. Set the standard across our cloud and SaaS estate: role-based access, least privilege, provisioning and deprovisioning, secrets and key rotation, access reviews on a cadence. Then keep it true.
Agent guardrails. Our agents create repositories, call paid vendor APIs, publish content and register domains. Decide and enforce what they may do unattended isolation, credential boundaries, spend ceilings, kill switches, and the bar an agent-created service clears before it becomes supported. Most published guidance covers one agent doing one task; you will be writing for teams of agents with open objectives.
AI governance. Which AI vendors and runtimes we standardise on, what data may leave the estate, and what an evaluation must prove before an agent runs unattended. You set the boundary our AI strategy runs inside and the written reasoning that makes it defensible.
Evidence. Build evidence capture as a pipeline rather than a periodic scramble, so that a due-diligence request, a partner security questionnaire or a takedown obligation is answered from records that already exist.
Requirements:
- Several years in security engineering, infrastructure security, platform security or a closely related discipline hands-on, not advisory.
- Practical command of identity and access: SSO, provisioning and deprovisioning, secrets management, privilege boundaries in cloud environments.
- You ship the control rather than the policy describing it. Comfortable in a terminal, in configuration, and in whatever language the fix requires.
- Experience producing evidence for an audit, certification or serious customer security review and the judgement to know what is worth capturing in the first place.
- Clear written English. Much of this job is a decision recorded well enough that someone can rely on it a year later.
- Exposure to AI or agent tooling, MCP, model runtimes, evaluation frameworks or a real appetite to learn them quickly.
- Experience in an engineering team with a broad estate, where ownership mattered more than process.
- Familiarity with GCP, Cloudflare, or a multi-platform hosting estate.
- Any of ISO 27001, SOC 2, GDPR obligations, or the compliance regime of a regulated vertical.
Our Benefits:
We offer a competitive salary, and the opportunity to work with a talented and passionate team in a fast-paced, dynamic environment.