₦ NGN
Language
Currency
arrow_back Back to Jobs

Lead Security Engineer

Encord · London

Full time On site
description Job Description

About us

Encord is the universal data layer for AI that helps 300+ AI teams train and run models on the right data. Our platform indexes, curates, annotates, and evaluates data across the full AI lifecycle, from development through production.

Β 

Trusted by Woven by Toyota, AXA, UiPath, Zipline, and more. We're an ambitious team of 100+ working at the frontier of AI and have raised $60M in Series C funding from Wellington Management, CRV, Next47 and Y Combinator.

About the role

We're looking for a Lead Security Engineer to own and mature how Encord secures its people, identities, devices, and the SaaS and AI tools we run the business on. You'll be hands-on, building and running controls yourself, while also owning the organisation security programme and acting as the go-to security expert across the company.

You'll play a key role in protecting our leadership team from targeted attacks, serve as the technical backbone of our ISO 27001 and SOC 2 programmes, and partner with our DevOps and Platform teams on cloud security. Above all, you'll help us stay safe while keeping our pace.

What you'll do

  • Own identity and access across Encord, including SSO, MFA, conditional access, and automated joiner/mover/leaver processes.

  • Manage our device security, keeping our macOS fleet protected through MDM and EDR.

  • Run SaaS and AI security: discovering shadow IT, reviewing app permissions, assessing new tools before adoption, and setting sensible guardrails for how AI tools are used.

  • Protect our executives and high-risk users from targeted phishing, impersonation, business email compromise, and AI-enabled fraud such as deepfakes.

  • Act as the technical owner of our ISO 27001 and SOC 2 controls, from policies and evidence through to auditor walkthroughs.

  • Lead third-party and vendor risk assessments.

  • Respond to and lead security incidents, and continuously improve how we detect and handle them.

  • Partner with DevOps and Platform to secure our cloud environment.

  • Write clear policies and runbooks, and roll out changes in a way that keeps the employee experience smooth.

What you'll bring

  • Around 7–8 years of hands-on security experience, with a strong focus on organisation security.

  • Experience rolling out or re-architecting SSO, MFA, and conditional access across a company.

  • Experience deploying and managing MDM and EDR across a macOS fleet.

  • A track record of building automated joiner/mover/leaver flows and user access reviews.

  • Experience running SaaS security, including discovering shadow IT, reviewing app permissions, and assessing new tools before adoption.

  • Experience putting guardrails around AI tool usage, such as approved tool lists, data handling rules, and vendor reviews of AI providers.

  • Ownership of, or significant contribution to, ISO 27001 and/or SOC 2 audits, including policies, control evidence, and auditor walkthroughs.

  • Experience defending against targeted phishing ("whaling") and business email compromise, such as fake CEO payment requests, invoice fraud, and gift card scams.

  • Experience leading or supporting security incidents such as phishing compromises, account takeovers, or lost devices.

  • Experience running third-party and vendor risk assessments and advising on the security of new tools before they're adopted.

  • Experience partnering with DevOps/Platform teams to secure cloud environments (ideally GCP), including IAM, network segmentation, secrets management, logging, and CSPM.

  • A habit of writing policies and runbooks that people can easily follow.

  • A thoughtful approach to change: you've rolled out new controls with clear communication, phased approaches, and a focus on keeping the employee experience smooth.

Nice to have

  • Experience with Infrastructure-as-Code (e.g. Terraform).

  • Experience owning vulnerability management across infrastructure, including scanning, prioritisation, remediation tracking, and SLAs.

  • Experience building and improving detection and monitoring, centralising logs into a SIEM and defining meaningful alerts.

  • Experience implementing and tuning SAST, DAST, SCA, and secrets scanning in CI/CD pipelines.

  • Experience coordinating external penetration tests and bug reports, and driving fixes to closure with engineering teams.

  • Experience helping engineers write secure code through guidance, patterns, and lightweight training.

  • Experience supporting sales and customer trust by answering security questionnaires and joining customer security calls.

  • Familiarity with executive digital protection, such as OSINT footprint reviews, impersonation monitoring, and out-of-band verification for sensitive requests.


Why Encord

  • Competitive salary, commission, and meaningful equity in a high-growth startup

  • Strong in-person culture β€” most of the team works from our London office 4+ days/week

  • 25 days annual leave + UK public holidays

  • Annual learning & development budget

  • Travel for customer visits, events, and conferences across the UK and Europe

  • Company lunches twice a week

  • Monthly socials & bi-annual team offsites

Find more English Speaking Jobs in United Kingdom on Arbeitnow

lightbulb_outline Skills Required
EPD
Get the EPELCON App v3.6.0
Invest, Learn & Earn on the go
Download APK
feedback Feedback