Search...

Senior Security Engineer

Copper logo
Copper

Copper provides custody, trading, and settlement services for digital assets.

Distributed
About Copper

Copper.co is a London-based digital asset infrastructure provider offering custody, trading, and settlement solutions for institutional investors. They launched CopperConnect, a tool that allows institutions to securely access DeFi protocols, including those on the Solana blockchain. Copper uses Multi-Party Computation (MPC) technology to ensure the highest level of security for digital assets.

View jobs by Copper

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will strengthen security posture by designing, implementing, and improving security controls, identity services, cloud security solutions, and governance processes. You will manage identity and access, cloud and endpoint security, vulnerability management, automation, security monitoring, risk assessments, threat modelling, and compliance activities. You will also advise stakeholders, maintain security platforms, and develop infrastructure-as-code and automated security workflows.

Requirements

  • Extensive Microsoft Entra ID and Identity Governance experience
  • Experience securing AWS environments
  • Experience with Microsoft Defender XDR Microsoft Sentinel Microsoft Purview Intune and Azure Security services
  • PowerShell Bash and Python scripting
  • System and application hardening using CIS and STIG standards
  • SaaS security administration using SSO SCIM provisioning Conditional Access entitlement governance and lifecycle management
  • Endpoint security across Windows and macOS environments
  • Enterprise network security using firewalls WAF SWG ZTNA DNS security and cloud-native network controls
  • Experience configuring Secure Web Gateways such as Zscaler iBoss or Netskope
  • Experience with binary execution control solutions such as AppLocker Defender Application Control Santa or ThreatLocker

Responsibilities

  • Design implement and maintain Identity and Access Management solutions
  • Manage permission settings and access controls
  • Configure security systems according to requirements and best practices
  • Assess cloud and endpoint security configurations against CIS STIG SOC2 and internal standards
  • Own the administration configuration and lifecycle management of security platforms
  • Maintain inventories of security tooling and integrations
  • Evaluate technologies and recommend security enhancements
  • Troubleshoot security platform issues with vendors and stakeholders
  • Advise technical teams business stakeholders and senior leadership on security architecture risk reduction and compliance
  • Create and update security policies and procedures
  • Manage vulnerability activities across cloud infrastructure endpoints SaaS applications and identity platforms
  • Prioritise and coordinate remediation efforts
  • Conduct security assessments and threat modelling
  • Produce security posture control effectiveness and remediation reports
  • Develop automation using PowerShell Python Bash and APIs
  • Design implement and support Terraform and cloud-native Infrastructure as Code solutions
  • Integrate security telemetry into Microsoft Sentinel
  • Develop automated governance compliance and incident response workflows

Benefits

  • Hybrid working model
  • 35 days of paid time off per year inclusive of annual leave and public holidays
  • One additional day of annual leave for each year of service
  • Comprehensive medical insurance including dental optical audiology and mental health coverage
  • Life insurance
  • Enhanced pension contributions with employer matching
  • 24/7 Employee Assistance Programme