About the job
Lead Principal Security Engineer
Location: London (Hybrid) | Practice Area: Technology & Engineering | Type: Permanent
Shape the future of digital finance by spearheading cutting-edge cybersecurity initiatives
The Role
As a Lead Principal Security Engineer at Capco, you will spearhead the design, implementation, and integration of comprehensive security frameworks across both cloud and on-premise environments. Your primary responsibility will be to collaborate with engineering and client teams to integrate security best practices throughout the Software Development Life Cycle (SDLC), while enhancing our capabilities in vulnerability management, compliance, and secure architecture.
What You’ll Do
Lead enterprise-wide security initiatives utilizing SAST, DAST, SCA, and container scanning tools such as CheckmarxOne and Prisma Cloud.
Design and implement secure cloud infrastructures, endpoint protection measures, and data encryption strategies.
Champion secure-by-design principles and integrate security tools into CI/CD pipelines.
Conduct comprehensive security audits, vulnerability assessments, and threat analyses across all systems.
Mentor engineering teams on secure development practices and help build Capco’s internal security knowledge repository.
What We’re Looking For
Extensive experience in application and cloud security across AWS, Azure, or GCP.
Proven proficiency in integrating SAST, DAST, SCA, and container scanning solutions.
In-depth knowledge of data protection methodologies, including encryption and data masking techniques.
Familiarity with industry standards and frameworks such as ISO 27001, NIST, and OWASP.
Programming skills in languages such as Python, Java, or Go.
Bonus Points For
Relevant certifications, including CISSP, CSSLP, or cloud-specific security credentials.
Experience in mentoring security engineers or contributing to RFPs and thought leadership initiatives.
Exposure to secure DevOps (DevSecOps) practices and compliance frameworks.
Experience with tools like Prisma Cloud, CheckmarxOne, or their equivalents.
Exceptional stakeholder engagement and communication skills.

