Senior Operational Security Engineer (Hiring Immediately)
Company Description
Crown Agents Bank is a vastly growing and regulated UK bank that connects emerging and frontier markets to the rest of the world, using FX and payments technology. We are transforming the way payments and FX move through emerging markets, reducing friction so that more money gets to those who need it. Emerging markets payments are usually challenging, expensive, unreliable and opaque. Our solutions help fix these pain points. Ultimately, we connect traditionally hard-to-reach regions to global financial infrastructure, giving access to the best prices and the fastest, most reliable settlement.
FX and cross-border payments are often complex and expensive, especially when operating in emerging markets. Crown Agents Bank (CAB) wraps its deep and trusted relationships and strength of network around innovative digital capabilities, and cross-border transaction banking solutions to enable fintech, corporates, governments, development organisations and banks to move money to, from, and across often hard-to-reach markets.
Job Description
The Senior Operational Security Engineer owns and operates the firm’s core protective and detective security controls across endpoint, network, identity and data security domains, converting multiple best-efforts operational security activities into sustainable, auditable and scalable services.
Security Operations — Endpoint & Network
- Own and operate Endpoint Detection & Response (EDR) tooling including alert triage, threat containment and endpoint health monitoring across all firm devices.
- Enforce endpoint security baselines, compliance checks and hardening standards across the estate.
- Manage anti-malware controls including policy configuration, update management and alert response.
- Configure and manage firewall and Web Application Firewall (WAF) controls, network segmentation, and remote access security.
- Working closely with the SD and Workspace team to maintain baseline security standards across endpoint environments.
- Own email security controls including anti-spam, anti-phishing, DMARC/DKIM/SPF and attachment scanning.
- Manage web filtering, proxy controls and malicious URL/content blocking.
Identity & Access Management
- Administer and manage multi-factor authentication (MFA) and single sign-on (SSO) solutions across the firm.
- Manage Privileged Access Management (PAM/PIM) controls including PAM/PIM platform administration and privileged session management.
- Own joiner, mover and leaver (JML) processes across all systems, ensuring timely and accurate access changes.
- Run periodic access review and recertification cycles, ensuring least-privilege is maintained across the estate.
- Support customer-facing access controls and authentication governance.
Data Security
- Manage Data Loss Prevention (DLP) controls including policy configuration, alert triage and response for data exfiltration events.
- Oversee data classification, retention, archiving and disposal controls within M365 and across the estate.
- Support insider threat monitoring controls and escalation procedures.
- Manage encryption standards and certificate lifecycle including monitoring, renewal and revocation
Detection & Response
- Triage and analyse security alerts from across the tooling estate, coordinating with the SOC to ensure timely detection and response.
- Lead threat hunting activities using XDR telemetry and threat intelligence to proactively identify attacker activity.
- Own and maintain the XDR platform including rule management, integrations and telemetry quality.
- Investigate security incidents, anomalous activity and SOC escalations, producing clear findings and recommendations.
- Develop and maintain incident response runbooks covering key threat scenarios and response procedures.
- Own ransomware readiness and business resilience testing activities, including backup validation and playbook maintenance.
- Manage security automation and SOAR playbook development to improve detection and response efficiency.
- Provide operational interface with the SOC, supporting SLA management and technical escalation.
Operational Reporting
- Produce clear, accurate and timely reporting covering endpoint health, network control status, DLP alert volumes, IAM control health and incident metrics.
- Contribute security operations data and metrics to the master CISO reporting pack.
Qualifications
Degree or equivalent professional experience in a relevant technical discipline. Relevant industry certification desirable, such as SC-200, AZ-500, CompTIA Security+, GIAC (GCIA, GCED, GCIH) or CISSP. Candidates with strong hands-on experience and demonstrable technical capability will be considered regardless of formal qualification.
- Significant hands-on experience in an operational information security or security engineering role.
- Demonstrable experience managing EDR/AV, SIEM/XDR platforms, and network security controls including firewalls, WAF and segmentation.
- Practical experience with identity and access management including MFA, PAM/PIM and access review processes.
- Experience with the enterprise security solutions suites (Endpoint, Cloud, XDR, Identity, etc) and Purview/DLP.
- Working knowledge of PAM tooling.
- Experience in a regulated financial services environment preferred but not essential; working knowledge of ISO 27001, NIST CSF, DORA or NYDFS Part 500 beneficial.
Ability to produce clear technical documentation, reports and evidence suitable for audit and regulatory review.
Additional Information
Recommended Jobs
Year 2 Teacher | Brent | January 2026
Are you a motivated and enthusiastic Year 2 Teacher looking for an exciting KS1 role from January 2026? Do you want to work in a Brent school that values high academic standards alongside strong pa…
Technical Project Manager
As a Technical Project Manager, you will play a pivotal role in driving critical initiatives that align with our ambitious goals. This is an outstanding opportunity to work in a dynamic environment wh…
HR Assistant Role | Lovely Brent School | Immediate Start
We are working closely with a school who are recruiting for a dedicated HR Assistant to join an Outstanding secondary school in Brent. This part-time role offers the perfect balance for a professiona…
Corporate Tax Assistant Manager, London To £55k + Benefits
Corporate Tax Assistant Manager London To £55,000 + Benefits This is the ideal role for a corporate/business tax specialist looking for high quality work, interesting clients and a positive env…
Occupational Therapist (Gr 8)
Job Category : Allied Health/Psychology Location : London Borough of Sutton Hours Per Week : 36.00 Start Date : Immediate Start Start Time :09:00 End Time :17:00 Salary: £27.92 Hybri…
Sr. Customer Business Manager (d/f/m) - Post Sales
Tue, 05/19/2026 - 00:41 Personio's intelligent HR platform helps small and medium-sized organizations unlock the power of people by making complicated, time-consuming tasks simple and efficient. Our t…
Sales Progression & Customer Care Coordinator
Sales Progression & Customer Care Coordinator Fulham, SW6 Cobalt is working with an established London developer with a strong reputation for delivering design-led residential schemes across the…
Hubspot Operations Executive - 6 month FTC
£35,000 Commercial Team Location: Hybrid (2 / 3 days in the office) native has been building for 10 years, but we're still very much a startup: fast-moving, ambitious, and building with intent.…
GTM Talent Partner
Location: London (3 days a week on-site) Contract Type: 6 months with likely extension You must demonstrate relevant experience supporting Customer Success & Operational functions within a scal…
Legal Counsel
Location: Uxbridge, London Key responsibilities: Draft, review, negotiate and advise on a variety of complex commercial contracts which may include auto finance agreements, fleet sale agreemen…