Baillie Gifford & Co Logo

Baillie Gifford & Co

Security Engineer

Posted Yesterday
Be an Early Applicant
In-Office
Edinburgh, City of Edinburgh, Scotland, GBR
Entry level
In-Office
Edinburgh, City of Edinburgh, Scotland, GBR
Entry level
Build, integrate, and maintain cybersecurity platforms and controls across cloud, identity, endpoint, vulnerability management, and security operations. Develop automation, APIs, integrations, and self-service tooling using scripting and Infrastructure as Code. Improve cloud security, CI/CD controls, privileged access, and secrets management. Contribute to architecture reviews, threat modelling, control validation, incident response, secure AI adoption, and technical documentation while advising technology teams on practical risk reduction.
The summary above was generated by AI
Job Title

Security Engineer

Department

TSD Information Security-BG-UK

Overview of Department

Purpose of Role

As a Security Engineer at Baillie Gifford, you will be a key member of the Security Engineering team, responsible for building, integrating and maintaining the security capabilities that protect our systems, data and people.
Security Engineering bridges security and technology, creating secure-by-default platforms and controls that enable teams across the organisation to operate securely while continuing to move quickly. The team works closely with Infrastructure, Cloud, Development, DevOps and other security teams to embed security earlier in the technology lifecycle and reduce reliance on manual security processes.
In this role, you will take a hands-on approach to engineering and improving security capabilities across cloud, identity, endpoint, vulnerability management and the wider security technology estate. You will develop integrations, tooling and automation that improve security outcomes while simplifying how security is consumed by other teams.
You will help mature and optimise existing security investments rather than simply introducing new technology, ensuring our platforms are effectively integrated and aligned with business risk. The role offers opportunities to broaden your experience, working across areas such as security architecture, threat modelling, development, continuous control validation and emerging technologies including AI.

Responsibilities

  • Design, build, configure and maintain security platforms and protective controls across our technology environment, including XDR, SIEM, SOAR, cloud security and vulnerability management capabilities.
  • Develop security tooling, integrations and automation using APIs, scripting, SOAR and other engineering approaches, turning repetitive or manual processes into scalable and self-service capabilities where appropriate.
  • Support and improve identity security, privileged access and secrets management capabilities, including their integration across infrastructure and applications.
  • Support the firm to adopt AI securely by understanding emerging risks, contributing to practical guardrails and exploring ways AI can improve how we build, automate and deliver security.
    Work closely with Core Platform teams to embed security earlier in project and development lifecycles, developing secure-by-default patterns, guardrails and security controls that can be adopted consistently.
  • Support and improve our cloud security posture and the integration of security testing and controls into CI/CD and development workflows.
  • Contribute to security architecture, technical design reviews and threat modelling, providing practical security guidance that helps technology teams understand risk and implement proportionate solutions.
  • Develop and maintain security orchestration, platform integrations and data flows that support security operations and incident response. Provide specialist engineering support during incidents where required.
  • Test and continuously validate security controls through configuration testing, attack simulation and Threat Informed Defence, using the results to improve preventative and detective controls.
  • Produce and maintain clear technical documentation for security platforms, integrations, architecture and engineered solutions.
    Continually develop your expertise across security engineering, cloud, identity, application security and other emerging technologies, sharing knowledge and new approaches with the wider team.



What success looks like
  • You build a strong understanding of our environment and use it to make proportionate, risk-based engineering decisions.
  • Security solutions are reliable, maintainable and effective for the teams that use them.
  • Manual effort and unnecessary complexity are reduced through effective automation and simplification.
  • Technology teams receive clear, practical security engineering advice that helps them understand and manage risk.
  • Our existing security capabilities continue to mature as you broaden your knowledge across different security domains.


Your knowledge and experience
  • You will have practical experience working within Cybersecurity, Infrastructure, Cloud Engineering, Identity & Access Management, DevOps, or a closely related technical discipline.

You will bring strong knowledge and practical engineering experience across several of the following areas, with solid technical foundations and the ability to learn and develop across different security domains:


  • Security engineering and architecture principles, vulnerability management, security testing and control validation.
  • Cloud security, particularly Microsoft Azure, alongside a good understanding of Windows and/or Linux environments and enterprise networking.
  • Identity and access management, privileged access, secrets management and associated access-control technologies.
  • Security platforms, including, Endpoint and XDR technologies, particularly CrowdStrike, as well as experience with SIEM, SOAR and other security platforms.
  • Automation and integration skills including scripting or development using PowerShell, Python, Bash or similar, API-based integrations and Infrastructure as Code and configuration automation technologies such as Terraform.
  • CI/CD pipelines, version control and approaches for integrating security controls and testing into development and deployment workflows.
  • An understanding of AI technologies, emerging security risks and appropriate guardrails and how these can be applied to support the firm’s secure adoption of AI and improve security engineering, automation and development.

​The Type of Candidate We’re Looking For


You are a practical and curious engineer who enjoys understanding how things work, solving technical problems and building security solutions that help others work securely. You are comfortable learning and applying your experience to unfamiliar technologies and problems.


You take a pragmatic approach to security and work well with others across technology. You can understand what teams are trying to achieve, identify the security risks that matter and turn them into practical solutions. You naturally look for opportunities to simplify, automate and improve how things are done.


You communicate clearly, exercise good technical judgement and are comfortable challenging existing approaches when you see a better way of doing something. You are motivated to keep developing your skills and enjoy sharing your knowledge and ideas with a wider team.



Critical Skills


  • Data literacy
  • Digital effectiveness (incl. AI)
  • Improvement mindset
  • Systems thinking
  • Team working

Closing Date

October 21, 2026

Should you choose to use AI tools to support your application, we ask that you do this thoughtfully. We encourage you to ensure your application reflects your own voice, experience, and motivations. We value authenticity and want to understand your individual strengths and perspectives.


At Baillie Gifford, we are committed to fostering an inclusive and respectful culture in which each of our colleagues can thrive and develop. We believe that our clients are best served by a diverse workforce with the experiences, ideas and perspectives that this brings.


If you are currently working at Baillie Gifford as an employee or contractor please apply to this job from the firm's Workday internal career site.

HQ

Baillie Gifford & Co Edinburgh, Scotland Office

Edinburgh, United Kingdom

Similar Jobs

17 Days Ago
Hybrid
Entry level
Entry level
Financial Services
Designs, develops, tests, and troubleshoots scalable security systems using Java and Python. Creates secure production code, contributes to architecture and design artifacts, analyzes data to improve security applications, and supports resilient cloud security platforms. Requires software engineering, system design, application development, testing, SDLC, agile, and security expertise, with AWS and Python preferred.
Top Skills: AWSCi/CdJavaPython
2 Days Ago
Remote or Hybrid
United Kingdom
Entry level
Entry level
Enterprise Web • HR Tech • Information Technology • Software • Cybersecurity
Designs, builds, tests, and improves cloud security labs, challenges, and learning content for a cyber resilience platform. The role focuses on AWS, Azure, GCP, Kubernetes, SIEM, CSPM/CNAPP, containers, Terraform, serverless technologies, identity, access, networking, monitoring, and DevSecOps. Responsibilities include creating realistic attack-and-defense simulations, translating technical research into accessible content, collaborating with engineering and product teams, and supporting cloud security content strategy.
Top Skills: AWSAzureCnappCspmDockerGCPGoogle SecopsKubernetesMicrosoft SentinelTerraform
20 Days Ago
Hybrid
Edinburgh, City of Edinburgh, Scotland, GBR
Senior level
Senior level
Artificial Intelligence • Information Technology • Marketing Tech • Software
Lead mobile security architecture, penetration testing, threat modeling, security assessments, and secure solution delivery across Android and iOS platforms. Define technical strategies, identify risks, recommend mitigations, advise clients, and drive security quality and compliance. Collaborate across full-stack mobile teams, improve security practices and tooling, and support Agile delivery. The role also involves mobile security research, reverse engineering, cryptographic controls, and DevSecOps practices.
Top Skills: AdbAndroidAndroid StudioApktoolArm/Arm64 AssemblyBashBurp Suite ProCDevsecopsFridaHopperIda ProiOSJadxJavaJavaScriptKotlinObjectionObjective-CPythonRadareSwiftXcodeYara

What you need to know about the Edinburgh Tech Scene

From traditional pubs and centuries-old universities to sleek shopping malls and glass-paneled office buildings, Edinburgh's architecture reflects its unique blend of history and modernity. But the fusion of past and future isn't just visible in its buildings; it's also shaping the city's economy. Named the United Kingdom's leading technology ecosystem outside of London, Edinburgh plays host to major global companies like Apple and Adobe, as well as a growing number of innovative startups in fields like cybersecurity, finance and healthcare.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account