Now hiring

Senior Security & Compliance Engineer @ Lantern

LondonOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

About Lantern

The trusted data platform for private markets.

Lantern is built by operators who have lived the exact problem we've set out to fix. Our leadership team has founded, scaled, and exited private markets technology and large-scale tech companies through acquisitions, IPOs, and global expansions. We know what GPs, LPs, and administrators actually need because we've sat on their side of the table.

Private markets data today is fragmented, manual, and slow. Every quarter the same story plays out: numbers arrive from disparate places, sources do not agree, and someone spends their week rebuilding trust from scratch in Excel, hoping nothing slipped through the cracks. It's exhausting. It's avoidable. And it's exactly what Lantern was built to end.

Lantern is not another dashboard. We're building the infrastructure that makes private markets data trustworthy, and we're just getting started.

The Role

We're looking for a Senior Security & Compliance Engineer to own and develop Lantern's security programme as we scale.

This is a broad, hands-on role spanning cloud and application security, vulnerability management, identity and access management, incident response, secure software delivery, SOC 2, risk management, and customer security assurance.

You'll be the internal owner for security: maintaining a clear view of our security posture, identifying where we need to improve, and working directly with engineering and leadership to make those improvements happen. You'll turn findings from security tooling, audits, penetration tests, and engineering reviews into clear actions with owners and deadlines, and follow them through to remediation or explicit risk acceptance.

You'll also own our day-to-day SOC 2 programme and audit readiness. That means making sure our controls reflect how Lantern actually operates, maintaining Vanta, coordinating evidence and auditor requests, keeping policies and procedures current, and ensuring our controls are operational rather than just documented.

This isn't a role where security sits outside engineering and produces a list of findings. You'll work closely with our Platform and product engineering teams on GCP, GitHub, CI/CD, identity, infrastructure, application security, and production operations. You'll help design controls that are secure, pragmatic, auditable, and don't unnecessarily slow down the people building the product.

As our dedicated security specialist, you'll have significant scope to define how security works at Lantern and establish the standards and practices we use as the company grows.

What You'll Own

• Security posture and risk. Maintain a clear view of security risks across our applications, cloud infrastructure, endpoints, and third-party services, driving issues through remediation or documented risk acceptance.

• SOC 2 and audit readiness. Own day-to-day SOC 2 readiness, including controls, evidence, audit preparation, auditor requests, findings, and remediation.

• Security tooling and monitoring. Own Vanta and our security integrations, ensuring controls, tests, alerts, and underlying data remain accurate and actionable.

• Vulnerability management. Own vulnerability management across applications and infrastructure, including triage, remediation, penetration testing, and escalation of critical issues.

• Secure engineering and access. Work with engineering on secure software delivery, change management, IAM, privileged access, environment separation, and protection of customer data.

• Incident response. Own and continuously improve our security incident process, from identification and escalation through investigation, documentation, and remediation.

• Policies, vendors, and customer assurance. Maintain our security policies, oversee third-party security, and own responses to customer and prospect security questionnaires.

• Security governance. Provide clear security-risk updates to engineering and company leadership, turning findings into decisions, owners, and deadlines.

About You

• 5+ years of professional security experience, ideally in a cloud-native SaaS or technology environment.

• Hands-on experience securing AWS, GCP, or Azure environments and working directly with engineering teams.

• Experience owning or playing a significant role in a SOC 2 Type II programme, including controls, evidence, auditor interaction, and remediation.

• Experience with compliance or GRC platforms such as Vanta, Drata, or Secureframe.

• Strong understanding of vulnerability management, IAM, application security, secure software delivery, and incident response.

• Comfortable working with modern engineering environments including CI/CD, GitHub, infrastructure as code, and production cloud infrastructure.

• Pragmatic about security: able to distinguish genuine risk from a compliance checkbox and design controls that work in a fast-moving engineering environment.

• Able to communicate clearly with engineers, leadership, auditors, customers, and non-technical teams.

• Comfortable taking ownership where a process doesn't exist yet: defining it, implementing it, and making sure it continues to work.

What You'll Get

• Real ownership. Shape how security works at Lantern and build the standards, controls, tooling, and practices that support us as we grow.

• Security close to engineering. Work directly with the engineers building and operating the platform, solving problems rather than simply reporting them.

• Visible impact. Your work will directly influence our product, engineering practices, customer relationships, and ability to scale.

• A competitive package. A competitive salary and benefits package, including generous annual leave and other benefits appropriate to your location.

Skills

Engineering

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores