At a Glance
- Tasks: Design and implement next-gen cloud security architecture while enhancing internal SOC capabilities.
- Company: Fast-growing fintech revolutionising personal finance with innovative AI solutions.
- Benefits: Hybrid work, competitive salary, generous holiday, paid sabbatical, and free gym membership.
- Other info: Collaborative environment with opportunities for professional growth and innovation.
- Why this job: Join a dynamic team making a real impact in the fintech space with cutting-edge technology.
- Qualifications: Strong background in DevSecOps, cloud security, and Python development.
The predicted salary is between 63000 - 77000 £ per year.
Using advanced AI and Open Banking data, we make fair, affordable personal finance available to more people. While traditional lenders rely almost entirely on credit scores, we look at the full financial picture - how much you spend, and what you can afford to repay to build a deeper, more accurate understanding of each customer's unique financial situation. We’ve issued over £1.3bn in loans directly to customers while delivering market-leading credit performance - for every 10 defaults the industry expects, we see only 3. Backed by £2bn+ of funding from top-tier investors including Citi, GSR Ventures, and Deutsche Bank, we’re recognised as one of Europe’s fastest-growing fintechs (Sifted, CNBC).
You won't be sitting in an ivory tower throwing policies over the fence. Operating as a highly technical individual contributor, you will bridge the gap between product-led engineering and Corporate IT. You will play a hands-on role in challenging the security architecture of production and corporate IT infrastructure.
In your first 6–12 months, you will design and implement our next-generation cloud security architecture across AWS and GCP, while helping to build and mature our internal SOC capabilities, including detection and response. You will take ownership of Microsoft Sentinel, enhancing our SIEM/SOAR capabilities, and strengthen identity and access management through improved and automated RBAC across AWS, Microsoft Entra, and internal systems. You will also drive a shift-left approach to security by embedding controls into GitLab CI/CD pipelines, including scanning, IaC reviews, and automated policy enforcement across the SDLC.
Cloud & Compute: AWS, ECS Fargate, Aurora, Lambda, GCP
Data Lake: S3, DMS, Glue
Security & Identity: Microsoft Defender (XDR), Microsoft Sentinel (SIEM/SOAR), Defender for Cloud (CSPM), Microsoft 365, Entra, Intune
Cloud Security Tooling: GuardDuty, Security Hub, Inspector, Security Command Center
Code & IaC: Python, Java, GitLab, AWS CDK, Terraform/CDK-TF
You are a security professional by trade, but a hacker by design. You have a strong track record in DevSecOps and cloud security engineering, with hands-on experience elevating the security posture of other organisations. You are a strong Python developer. You know how to script automation, interact with APIs, and build security tooling from scratch. You possess a rock-solid understanding of network security fundamentals and how they apply to modern, distributed cloud architectures. You are comfortable owning both the build and run aspects of security—designing systems and responding to incidents. You know how to balance rigorous security with engineering velocity.
Responsibilities:
- Actively contribute infrastructure-as-Code (AWS CDK, Terraform) for security risks prior to deployment
- Implement best practice network security across AWS and GCP (IAM, VPCs, encryption, logging, monitoring)
- Embed zero-trust policies across the estate
- Actively challenge the security standards of production applications and infrastructure
- Embed security controls into CI/CD pipelines (SAST, dependency scanning, container security)
- Partner with engineering teams on secure architecture and deployment patterns
- Support secure SDLC practices and pre-deployment security reviews
Hybrid with 3 days a week in the office ~25 days’ holiday a year, plus 8 bank holidays ~One month paid sabbatical after 4 years ~ Free gym membership
Senior Security Engineer(Hybrid) in London employer: Abound
Abound is an excellent employer that fosters a collaborative and innovative work culture, particularly in the dynamic field of Generative AI. With a hybrid work model based in London, employees benefit from competitive perks such as equity options and generous paid holidays, while also having the opportunity to work on impactful projects that shape the future of consumer lending. The company prioritises employee growth and encourages curiosity and problem-solving, making it a rewarding place for those looking to make a real-world impact.