Back to search
Broaden Linkedin · Posted 7d ago

Lead Engineer - Infrastructure & Cyber Security

United Kingdom

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

Lead Engineer – Infrastructure & Cyber Security | Global Insurance Group | London (Hybrid) | up to £120K + bonus


About the Company


Our client is a fast-scaling, global commercial insurance group growing rapidly both organically and through international acquisitions across the UK, Europe, Australia, and Asia. They are completely rebuilding their technology operating model around a modern, identity-centric, cloud-native architecture on the Microsoft stack.


Operating in an incredibly fast-paced, high-growth scale-up environment, they champion absolute autonomy and radical ownership. They move dynamically from start-up flexibility to scale-up discipline, meaning they listen well, move fast, and empower their people to execute without layers of bureaucracy or hand-holding. They are anti-bureaucracy but pro-governance, meaning regulatory compliance is delivered as code and automated platform controls rather than committees and paperwork. If a candidate is exceptionally bright, thrives in a rapid-iteration culture, and wants the freedom to define a roadmap and see their work directly move the business forward, they will find a massive opportunity here.


About the Role


The client is completely re-engineering their tech division and hiring three bright, peer Lead Engineers to own and rebuild three brand-new pillars in the business. Reporting directly to the Group CTO with no layers of management in between, the successful candidate will own the Infrastructure & Cyber Security pillar.


This is a hands-on building role, not a legacy people-management position. You will lead a small internal team - which is set to grow - and gain massive operational leverage by directing high-performing external delivery partners. The mandate is to take the "Frictionless Fortress" blueprint - a highly scalable, Zero Trust infrastructure design - and build, run, and keep it honest as the group continues to expand. You will also own the global M&A integration playbook, systematically pulling acquired environments into the secure cloud landing-zone pattern within a strict Day 1 / Day 30 / Day 90 cadence.


Key Responsibilities


  • Own the password-less destination, securing the perimeter utilizing Entra ID P2, FIDO2 passkeys, Conditional Access policies, PIM, and Identity Protection.
  • Architect and manage the Azure tenant, subscriptions, and landing zones PaaS-first; migrate remaining legacy physical office infrastructure into managed cloud services (Azure SQL, App Service, Functions).
  • Oversee the endpoint compute model using Intune, configured MAM-first, with MDM enrollment and AVD/AppStreaming where required.
  • Direct the security stack (Defender XDR and Sentinel) and own detection engineering, playbooks, and the quality of outcomes delivered by the 24/7 external SOC partner.
  • Implement infrastructure entirely in Terraform, establishing drift detection, Azure Policy guardrails, and compliance controls directly within deployment gates.
  • Hold the total cost of ownership for global infrastructure and security, using tagging, rightsizing, and auto-suspension to drive down per-head costs as the business scales.


Skills & Competencies


  • Deep, current, hands-on-keyboard command of the Microsoft security, identity, and Azure platform stacks (Entra ID, Intune, Defender, Purview, Sentinel, Terraform).
  • Real Azure platform engineering experience, with the technical scars to prove they can transition physical assets to cloud PaaS without just recreating legacy VMs.
  • Treats cloud consumption as an engineering problem to instrument and optimize, rather than a bill to accept.
  • Measures success by what they build and how they upskill the wider team and partners, rather than hoarding knowledge or building a personal fiefdom.


Qualifications & Experience


  • Genuinely strong, hands-on engineering capabilities. They are hiring for trajectory and technical instinct rather than arbitrary years of tenure.
  • Proven track record of shipping and running production systems in a cloud-native environment.
  • Experience working within an FCA-regulated or structured environment, demonstrating that security and compliance can be delivered cleanly through code and platform architecture.
  • Desirable: Prior experience wrangling acquired IT estates, executing data center exits, or managing multi-jurisdiction data residency guardrails.
  • Note: Certifications (SC-300, SC-200, AZ-104, AZ-305) are valued as evidence of depth, but are not used as a hiring gate.


Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search