Lead Engineer - Infrastructure & Cyber Security
Listed on 2026-08-12
-
IT/Tech
Cloud Computing: Infrastructure & Operations, Cybersecurity, Systems Engineer
Lead Engineer – Infrastructure & Cyber Security | Global Insurance Group | London (Hybrid) | up to £120K + bonus About the Company
Our client is a fast-scaling, global commercial insurance group growing rapidly both organically and through international acquisitions across the UK, Europe, Australia, and Asia. They are completely rebuilding their technology operating model around a modern, identity-centric, cloud-native architecture on the Microsoft stack.
Operating in an incredibly fast-paced, high-growth scale-up environment, they champion absolute autonomy and radical ownership. They move dynamically from start-up flexibility to scale-up discipline, meaning they listen well, move fast, and empower their people to execute without layers of bureaucracy or hand-holding. They are anti-bureaucracy but pro-governance, meaning regulatory compliance is delivered as code and automated platform controls rather than committees and paperwork.
If a candidate is exceptionally bright, thrives in a rapid-iteration culture, and wants the freedom to define a roadmap and see their work directly move the business forward, they will find a massive opportunity here.
The client is completely re-engineering their tech division and hiring three bright, peer Lead Engineers to own and rebuild three brand-new pillars in the business. Reporting directly to the Group CTO with no layers of management in between, the successful candidate will own the Infrastructure & Cyber Security pillar.
This is a hands-on building role, not a legacy people-management position. You will lead a small internal team - which is set to grow - and gain massive operational leverage by directing high-performing external delivery partners. The mandate is to take the "Frictionless Fortress" blueprint - a highly scalable, Zero Trust infrastructure design - and build, run, and keep it honest as the group continues to expand.
You will also own the global M&A integration playbook, systematically pulling acquired environments into the secure cloud landing-zone pattern within a strict Day 1 / Day 30 / Day 90 cadence.
- Own the password-less destination, securing the perimeter utilizing Entra P2, FIDO2 passkeys, Conditional Access policies, PIM, and Identity Protection.
- Architect and manage the Azure tenant, subscriptions, and landing zones PaaS-first; migrate remaining legacy physical office infrastructure into managed cloud services (Azure SQL, App Service, Functions).
- Oversee the endpoint compute model using Intune, configured MAM-first, with MDM enrollment and AVD/App Streaming where required.
- Direct the security stack (Defender XDR and Sentinel) and own detection engineering, playbooks, and the quality of outcomes delivered by the 24/7 external SOC partner.
- Implement infrastructure entirely in Terraform, establishing drift detection, Azure Policy guardrails, and compliance controls directly within deployment gates.
- Hold the total cost of ownership for global infrastructure and security, using tagging, rightsizing, and auto-suspension to drive down per-head costs as the business scales.
- Deep, current, hands‑on-keyboard command of the Microsoft security, identity, and Azure platform stacks (Entra , Intune, Defender, Purview, Sentinel, Terraform).
- Real Azure platform engineering experience, with the technical scars to prove they can transition physical assets to cloud PaaS without just recreating legacy VMs.
- Treats cloud consumption as an engineering problem to instrument and optimize, rather than a bill to accept.
- Measures success by what they build and how they upskill the wider team and partners, rather than hoarding knowledge or building a personal fiefdom.
- Genuinely strong, hands-on engineering capabilities. They are hiring for trajectory and technical instinct rather than arbitrary years of tenure.
- Proven track record of shipping and running production systems in a cloud-native environment.
- Experience working within an FCA-regulated or structured environment, demonstrating that security and compliance can be delivered cleanly through code and platform architecture.
- Desirable:
Prior experience wrangling acquired IT estates, executing data center exits, or managing multi-jurisdiction data residency guardrails. - Note:
Certifications (SC-300, SC-200, AZ-104, AZ-305) are valued as evidence of depth, but are not used as a hiring gate.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: