SlipstreamJobsFresh Startup & VC-Backed Jobs

Lead Security Engineer

Encord - London, United Kingdom - In-office - posted 2026-10-02

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Encord is a universal data layer for AI that helps 300+ AI teams train and run models on the right data. The platform indexes, curates, annotates, and evaluates data across the full AI lifecycle. Trusted by Woven by Toyota, AXA, UiPath, Zipline, and others, Encord is a 100+ person team that has raised $60M in Series C funding. You will own and mature how Encord secures its people, identities, devices, and the SaaS and AI tools the business runs on. This is a hands-on role where you'll build and run controls yourself while owning the organization's security programme and serving as the go-to security expert across the company. Key responsibilities include: - Own identity and access management across the company, including SSO, MFA, conditional access, and automated joiner/mover/leaver processes - Manage device security, keeping the macOS fleet protected through MDM and EDR - Run SaaS and AI security: discovering shadow IT, reviewing app permissions, assessing new tools, and setting guardrails for AI tool usage - Protect executives and high-risk users from targeted phishing, impersonation, business email compromise, and AI-enabled fraud - Act as technical owner of ISO 27001 and SOC 2 controls, from policies and evidence through auditor walkthroughs - Lead third-party and vendor risk assessments - Respond to and lead security incidents, continuously improving detection and handling - Partner with DevOps and Platform teams to secure the cloud environment - Write clear policies and runbooks, rolling out changes while maintaining smooth employee experience The role is based in London with most of the team working from the office 4+ days per week. REQUIREMENTS: - Around 7–8 years of hands-on security experience with strong focus on organizational security - Experience rolling out or re-architecting SSO, MFA, and conditional access across a company - Experience deploying and managing MDM and EDR across a macOS fleet - Track record of building automated joiner/mover/leaver flows and user access reviews - Experience running SaaS security, including discovering shadow IT, reviewing app permissions, and assessing new tools - Experience putting guardrails around AI tool usage (approved tool lists, data handling rules, vendor reviews) - Ownership of or significant contribution to ISO 27001 and/or SOC 2 audits, including policies, control evidence, and auditor walkthroughs - Experience defending against targeted phishing and business email compromise - Experience leading or supporting security incidents such as phishing compromises, account takeovers, or lost devices - Experience running third-party and vendor risk assessments - Experience partnering with DevOps/Platform teams to secure cloud environments (ideally GCP), including IAM, network segmentation, secrets management, logging, and CSPM - Habit of writing policies and runbooks that people can easily follow - Thoughtful approach to change management with clear communication and focus on employee experience Nice to have: Infrastructure-as-Code experience (e.g., Terraform), vulnerability management ownership, detection and monitoring/SIEM experience, SAST/DAST/SCA/secrets scanning in CI/CD, penetration testing coordination, secure code guidance for engineers, security questionnaire support, executive digital protection familiarity.

Similar roles