Head of Security Engineering

Brevan Howard Asset Management

Brevan Howard Asset Management

Other Engineering
London, UK
Posted 6+ months ago

MAIN DUTIES/RESPONSIBILITIES OF THE ROLE:

  • Lead the Security Engineering team and set the strategic roadmap, this is a hands-on role
  • Ensure the team is taking a risk-based approach across all the environments (multi-cloud and on-prem)
  • Partner with all Technology teams at Brevan Howard including Platform Engineering and Front, Middle and Back Office Technology
  • Design, implement and evangelise secure defaults for our internal users, including Identity & Access Management, Secrets, Logging and Monitoring
  • Lead and Coordinate response to security incidents, investigations and alerts
  • Engage with vendors, service providers and leverage open source to enable us to buy, build and operate effective solutions for our environment
  • Have a solution-focused and enabling mindset
  • Manage the resources, demands and stakeholders in a dynamic and fast paced environment
  • Collaborate across the business to remediate security issues and risks
  • Influence the security culture across Technology and be an evangelist
  • Deliver using efficient, reliable and scalable methods including automation, testing and monitoring
  • Have an as-code mindset with proficiency in at least one programming language

WORK EXPERIENCE/BACKGROUND:

Essential

  • 5+ years professional experience in securing one or more public cloud environments (AWS preferred)
  • Proficient in using infra-as-code to reliably scale and automate the management of cloud services
  • Hands-on experience with scripting and at least one programming language, e.g. Java, Golang, Python etc
  • Experience working in a software delivery lifecycle, GitOps, CI/CD tooling
  • Proactive, team-orientated attitude with a strong emphasis on collaboration and continuous learning

Desirable

  • Familiarity with integrating security into the developer SDLC, through scanning, posture management and guardrails
  • Experience with securing hybrid cloud infrastructure (Virtualisation, Containers, Kubernetes)
  • Familiarity with cloud security standards and frameworks for assessing compliance, maturity and effectiveness
  • Experience automating testing and monitoring effectiveness of cloud controls using AWS Config, Lambda or equivalent open source/vendor tooling
  • Proficient in navigating dynamic, fast paced and complex environments