Senior Security Engineer

Brevan Howard Asset Management

Brevan Howard Asset Management

Software Engineering
London, UK
Posted on Friday, February 23, 2024

The BH Digital division is undergoing a period of growth with a strong focus and investment in the technology platform, infrastructure and tooling. The successful applicant will join a small high impact team of engineers reporting directly into the CISO and working closely with the CTO and Engineering team of BH Digital. You will be pivotal in securing the build out of the foundational Digital platform – spanning execution, treasury, risk and market data.

You will work to design, develop, enforce and review our Security posture. Knowledge, experience and understanding of the evolving threat landscape, digital asset attack vectors, threat testing and assessment, vulnerability detection and resolution is essential. You will be capable of managing penetration testing on applications, systems and networks using formal processes and industry standard tooling.

MAIN DUTIES/RESPONSIBILITIES OF THE ROLE: Essential Responsibilities:

  • Be pragmatic and commercially driven positioning the security function as an enabler for the business.
  • Work to design, develop and execute on the BH Digital security strategy.
  • Design and execute an adversarial security program to proactively identify vulnerabilities and risks.
  • Own the relationship with key stakeholders across the firm to inform the Security requirements, roadmap and priorities.
  • Take the lead on security incidents, investigations and remediation.
  • Familiar with Red Teaming and/or penetration testing.
  • Advocate of the principle of “shift left” and approach to DevSecOps

PERSON SPECIFICATION

WORK EXPERIENCE/BACKGROUND:

Essential

  • 5+ years of professional hands-on experience with a programming or scripting language, e.g. Java, Golang, Python, Bash, Node.js, etc.
  • 3+ years professional experience in financial services
  • Experience of working in a dynamic, fast paced environment
  • Experience with microservice architecture
  • Experience with offensive tools including, Kali Linux, Metasploit, CobaltStrike, etc.

Desirable

  • Familiarity with secure execution environments, air gapped system architecture, infra-as-code, tamper proof hardware.
  • Experience with application security and reviews
  • Familiarity with cryptographically secured data, assets and infrastructure
  • Experience with cryptocurrency and blockchain technologies, e.g. Bitcoin, Ethereum