At a Glance
- Tasks: Join our Security Team to enhance cloud and application security for small businesses.
- Company: Funding Circle empowers small businesses with fast, hassle-free funding solutions.
- Benefits: Enjoy a dynamic work environment with opportunities for mentorship and professional growth.
- Why this job: Be a key player in shaping security practices in a cutting-edge FinTech company.
- Qualifications: 3+ years in Information Security with expertise in AWS and secure software development.
- Other info: Diverse candidates are encouraged to apply, regardless of experience alignment.
The predicted salary is between 48000 - 84000 £ per year.
We are seeking an experienced Senior Security Engineer to join our dynamic Security Team. In this key role, you will be a key contributor to Funding Circle's cloud and application security posture. You will leverage your deep expertise in AWS security, secure software development lifecycle (SSDLC) practices, and CI/CD security to implement and champion robust security solutions. You will act as a subject matter expert and mentor, collaborating closely with engineering and product teams to embed security seamlessly into our cloud infrastructure and development processes, ensuring the protection of our platform and customer data in a fast-paced FinTech environment.
The role:
- Define, champion, and embed secure software development lifecycle (SSDLC) practices and secure coding standards across engineering teams through collaboration, training, and tooling.
- Architect, build, and maintain automated security controls, tooling, and "security rails" within CI/CD pipelines to ensure secure and efficient deployments.
- Collaborate closely with Cloud Platform Engineers, DevX and Product Engineering to ensure security requirements are integrated into system designs and technology choices from the outset.
- Perform threat modelling exercises for cloud-native applications, microservices, and infrastructure components.
- Manage internal and external penetration testing engagements for Funding Circle applications, services, and cloud infrastructure.
- Oversee and enhance vulnerability management processes, focusing on strategic remediation, root cause analysis, and preventative measures.
- Contribute to drive implementation of security automation across cloud infrastructure configuration, vulnerability management, and compliance monitoring.
- Design, implement, and support the adoption of robust security architectures, controls, and best practices within our AWS cloud environment.
- Act as a subject matter expert on cloud security (AWS), DevSecOps, and application security, providing guidance and mentorship to other engineers.
- Contribute to the incident response planning for complex cloud and application security events.
- Proactively monitor the threat landscape, evaluate emerging cloud security risks and trends, and translate them into actionable security improvements.
What we’re looking for:
- Significant (3+ years) hands-on experience in Information Security, with a demonstrable deep focus on AWS cloud security and application/product security.
- Deep, demonstrable expertise in designing, implementing, securing, and managing a wide range of AWS security services.
- Proven, hands-on experience architecting, building, and integrating security tooling (SAST, DAST, SCA, secrets management, IAST) and automated security controls within CI/CD pipelines (e.g., GitLab CI, Jenkins, GitHub Actions).
- Strong track record of defining, implementing, measuring, and supporting the adoption of secure software development lifecycle (SSDLC) practices and secure coding standards within engineering organizations.
- Strong understanding of web application security vulnerabilities (OWASP Top 10 and beyond), attack vectors, and mitigation techniques.
- Significant experience securing Infrastructure as Code (IaC), particularly Terraform, and implementing relevant security checks.
- Solid experience with container security and securing container orchestration platforms (Kubernetes/EKS).
- Proven ability contributing significantly to vulnerability management programs, including advanced triaging, root cause analysis, risk assessment, and strategic remediation planning.
- Strong communication and influencing skills, with the ability to articulate complex security concepts clearly to technical audiences.
- Strong knowledge of relevant security frameworks and standards (e.g., NIST CSF, CIS Benchmarks, OWASP ASVS).
- Exposure and knowledge of the MITRE ATT&CK framework.
- Experience effectively coordinating external penetration testing engagements and managing remediation efforts.
Nice to have:
- Relevant advanced security certifications (e.g., AWS Certified Security - Specialty, CISSP, CCSP, OSCP/OSWE).
- Experience with specific security platforms/tools (e.g., Wiz, Snyk, Checkmarx, Veracode).
- Proficiency in security automation using scripting languages (e.g., Python).
- Experience working in FinTech or other highly regulated environments.
- Experience with mobile application security principles and testing.
At Funding Circle we are committed to building diverse teams so please apply even if your past experience doesn’t align perfectly with the requirements.
Senior Cloud & Application Security Engineer employer: Funding Circle UK
Contact Detail:
Funding Circle UK Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Cloud & Application Security Engineer
✨Tip Number 1
Familiarise yourself with AWS security services and best practices. Since the role heavily focuses on AWS, having a solid understanding of its security features will help you stand out during discussions.
✨Tip Number 2
Brush up on your knowledge of secure software development lifecycle (SSDLC) practices. Being able to discuss how you've implemented these in past roles will demonstrate your hands-on experience and commitment to security.
✨Tip Number 3
Prepare to showcase your experience with CI/CD security tooling. Be ready to discuss specific tools you've used and how you've integrated security into deployment pipelines, as this is a key aspect of the job.
✨Tip Number 4
Stay updated on the latest trends in cloud security and emerging threats. Being knowledgeable about current risks and how to mitigate them will position you as a proactive candidate who can contribute to the team's success.
We think you need these skills to ace Senior Cloud & Application Security Engineer
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights your relevant experience in AWS security, secure software development lifecycle (SSDLC), and CI/CD security. Use specific examples that demonstrate your expertise in these areas.
Craft a Compelling Cover Letter: In your cover letter, express your passion for cloud and application security. Mention how your skills align with Funding Circle's mission to support small businesses and how you can contribute to their security posture.
Showcase Relevant Projects: Include details of any projects where you've implemented security controls or worked on vulnerability management. Highlight your hands-on experience with tools like SAST, DAST, and IaC security, particularly with Terraform.
Demonstrate Communication Skills: Since strong communication is key for this role, ensure your application reflects your ability to articulate complex security concepts clearly. Consider including examples of how you've successfully collaborated with engineering teams in the past.
How to prepare for a job interview at Funding Circle UK
✨Showcase Your AWS Expertise
Make sure to highlight your hands-on experience with AWS security services. Be prepared to discuss specific projects where you implemented security measures and how they improved the overall security posture.
✨Demonstrate Your Knowledge of SSDLC
Discuss your understanding of secure software development lifecycle practices. Share examples of how you've defined and implemented these practices in previous roles, and how they benefited the engineering teams.
✨Prepare for Technical Questions
Expect technical questions related to cloud security, application vulnerabilities, and CI/CD security. Brush up on the OWASP Top 10 and be ready to explain mitigation techniques for common vulnerabilities.
✨Emphasise Collaboration Skills
Since the role involves working closely with various teams, be sure to highlight your collaboration and mentoring experiences. Share instances where you successfully communicated complex security concepts to non-technical audiences.