At a Glance
- Tasks: Join us as a Senior Security Engineer to enhance product security and mitigate risks.
- Company: Ebury is a leading fintech firm empowering global businesses with innovative financial solutions.
- Benefits: Enjoy hybrid work, professional development opportunities, and a clear progression path.
- Why this job: Make a direct impact on security for products used by thousands while collaborating globally.
- Qualifications: 5+ years in application security with strong programming skills and knowledge of OWASP standards.
- Other info: Be part of a diverse team committed to inclusion and innovation in the fintech sector.
The predicted salary is between 43200 - 72000 £ per year.
Senior Security Engineer (Product Security)
Senior Security Engineer (Product Security)
Senior Security Engineer (Product Security)
Ebury is a global fintech firm dedicated to empowering businesses to expand internationally through tailored and forward-thinking financial solutions. Since our founding in 2009, we\’ve grown to a diverse team of over 1,700 professionals across 40+ offices and 29+ markets worldwide. Joining Ebury means becoming part of a collaborative and innovative environment where your contributions are valued. You\’ll play a key role in shaping the future of cross-border finance, while advancing your own career in a dynamic, high-growth industry.
Senior Security Engineer
London Office – Hybrid: 4 days in the office, 1 day working from home
Role Overview
We are seeking a Senior Security Engineer to embed security throughout our product development lifecycle. You\’ll work directly with engineering teams to identify and mitigate security risks through threat modeling, secure code reviews, and integrated security tooling across our web and mobile applications. This role is critical to establishing our secure development practices, implementing industry-standard SSDLC processes, and ensuring our financial products are resilient against evolving threats.
Key Responsibilities
Secure Development Lifecycle (SDLC) Implementation
- Design and implement secure software development practices
- Integrate security gates into CI/CD pipelines following DevSecOps principles
- Establish security quality gates and acceptance criteria
- Develop secure coding standards based on OWASP guidelines
- Create security architecture patterns and reference implementations
Security Code Reviews & Testing
- Conduct in-depth security code reviews for critical features
- Implement automated security testing (SAST, DAST, IAST, SCA)
- Configure and tune security scanning tools (Aquasec, Trivy, Dependabot, etc)
- Review cryptographic implementations against industry standards
- Validate authentication and authorization implementations
- Ensure compliance with OWASP ASVS (Application Security Verification Standard)
Threat Modeling & Risk Assessment
- Lead threat modeling sessions using STRIDE, PASTA, or similar frameworks
- Create threat models for new products and architectural changes
- Identify attack vectors specific to web and mobile platforms
- Develop abuse cases and security test scenarios
- Maintain threat intelligence for fintech-specific risks
- Document security requirements derived from threat models
Platform-Specific Security
- Web Applications: Implement defenses against OWASP Top 10 vulnerabilities
- Mobile Applications: Apply OWASP MASVS and platform-specific guidelines (iOS App Transport Security, Android Network Security Config)
- APIs: Implement API security best practices (rate limiting, authentication, input validation)
- Cross-platform session management and secure data storage
Security Tooling & Automation
- Build and maintain security testing pipelines
- Integrate security tools with GitHub Actions
- Develop custom security linters and pre-commit hooks
- Create automated vulnerability tracking and remediation workflows
- Implement secret scanning and dependency checking
- Build security dashboards and metrics reporting
Developer Enablement & Training
- Create secure coding guidelines for different technology stacks
- Develop a security champions program aligned with OWASP SAMM
- Conduct security training on platform-specific vulnerabilities
- Provide hands-on guidance during security incidents
- Build internal security libraries and frameworks
- Create threat modeling templates and playbooks
Required Qualifications
Technical Expertise
- 5+ years of application security experience
- Strong programming skills in multiple languages (Python, JavaScript/TypeScript, Golang)
- Deep understanding of security vulnerabilities across web and mobile platforms
- Hands-on experience with security testing tools and methodologies
- Expertise in secure coding practices and design patterns
- Experience with modern development frameworks (React, Angular, ReactNative, Flutter)
Security Domain Knowledge
- Expert knowledge of OWASP standards (Top 10, ASVS, SAMM, MASVS)
- Understanding of cryptographic principles and secure implementations
- Experience with threat modeling methodologies
- Knowledge of authentication standards (OAuth2, OIDC, WebAuthn)
- Familiarity with PCI-DSS, PSD2, and Strong Customer Authentication requirements
- Understanding of cloud-native security patterns
Code Review & Analysis Skills
- Ability to identify security vulnerabilities through manual code review
- Experience with static and dynamic analysis tools
- Understanding of common vulnerability patterns across languages
- Knowledge of secure architecture patterns and anti-patterns
- Ability to provide actionable remediation guidance
Professional Requirements
- Experience in financial services or high-security environments
- Strong communication skills to explain security risks to developers
- Ability to balance security requirements with development velocity
- Collaborative approach to working with engineering teams
- Technical writing skills for documentation and guidelines
Preferred Qualifications
- Experience with payment systems and transaction security
- Knowledge of mobile app protection
- Experience building security champions programs
- Background in penetration testing or security research
Key Projects & Initiatives
You\’ll lead critical security initiatives, including:
- Building threat modeling practice for all products
- Establishing automated security testing in CI/CD pipelines
- Creating platform-specific security standards and libraries
- Developing a security training curriculum for 200+ developers
What We Offer
- Direct impact on the security of products used by thousands of businesses
- Work with cutting-edge fintech products across multiple platforms
- Collaborate with talented engineers across 25+ countries
- Modern security tooling and testing infrastructure
- Investment in professional development and certifications
- Clear progression path to Staff/Principal roles
#LI-AT1
#HYBRID
About Us
Ebury is a FinTech success story, positioned among the fastest-growing international companies in its sector.
Founded in 2009, we are headquartered in London and have more than 1700 staff with a presence in more than 29 markets worldwide. Cultural diversity is part of what makes Ebury a special place to be. From Sao Paulo to Dubai, Vancouver to Auckland, we enjoy sharing team experiences and celebrating success across the Ebury family.
Hard work pays off: in 2019, Ebury received a £350 million investment from Banco Santander and has won internationally recognised awards including Financial Times: 1000 Europe\’s Fastest-Growing Companies.
None of this would have been possible without our proudest achievement: our great people. Enthusiastic, innovative and collaborative teams, always ready to disrupt and revolutionise the fast-paced FinTech sector.
At Ebury, we\’re committed to building a workplace where everyone feels valued, supported, and empowered to thrive. We\’re proud to have active employee networks and ESG initiatives that reflect our inclusive culture, including our Women\’s Network , LGBTQIA+ Network , and Veterans Network . These communities provide spaces for connection, mentorship, advocacy, and collaboration across our global teams.
We believe in inclusion. We stand against discrimination in all forms and have no tolerance for the intolerance of differences that makes us a modern and successful organisation. At Ebury, you can be whoever you want to be and still feel a sense of belonging no matter your story because we want you and your uniqueness to help write our future.
Please submit your application on the careers website directly, uploading your CV / resume in English.
Boost your career
Find thousands of job opportunities by signing up to eFinancialCareers today.
#J-18808-Ljbffr
Senior Security Engineer (Product Security) | London, UK employer: Ebury
Contact Detail:
Ebury Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Security Engineer (Product Security) | London, UK
✨Tip Number 1
Familiarise yourself with the specific security tools mentioned in the job description, such as Aquasec and Trivy. Having hands-on experience with these tools will not only boost your confidence but also demonstrate your proactive approach to potential employers.
✨Tip Number 2
Engage with the fintech community by attending relevant meetups or webinars. Networking with professionals in the field can provide insights into current trends and challenges, making you a more attractive candidate for the role.
✨Tip Number 3
Prepare to discuss your experience with secure coding practices and how you've implemented them in past projects. Be ready to share specific examples that highlight your ability to integrate security into the development lifecycle.
✨Tip Number 4
Brush up on your knowledge of OWASP standards and be prepared to explain how they apply to both web and mobile applications. This will show your depth of understanding and commitment to maintaining high security standards.
We think you need these skills to ace Senior Security Engineer (Product Security) | London, UK
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in application security, particularly focusing on your programming skills and familiarity with OWASP standards. Use specific examples that demonstrate your expertise in secure coding practices and threat modeling.
Craft a Compelling Cover Letter: In your cover letter, express your passion for fintech and how your background aligns with Ebury's mission. Mention specific projects or initiatives you've led that relate to the role, such as implementing security testing in CI/CD pipelines or developing secure coding guidelines.
Showcase Technical Skills: Clearly outline your technical skills in your application. Highlight your experience with security testing tools, programming languages, and modern development frameworks. Be specific about your hands-on experience with tools like Aquasec, Trivy, and your understanding of cryptographic principles.
Demonstrate Communication Skills: Since strong communication skills are essential for this role, provide examples in your application of how you've effectively communicated security risks to developers or collaborated with engineering teams. This will show that you can balance security requirements with development velocity.
How to prepare for a job interview at Ebury
✨Showcase Your Technical Expertise
Be prepared to discuss your experience with application security, particularly in relation to web and mobile platforms. Highlight your knowledge of OWASP standards and any hands-on experience with security testing tools, as this will demonstrate your capability to fulfil the role effectively.
✨Demonstrate Problem-Solving Skills
During the interview, be ready to tackle hypothetical scenarios related to security vulnerabilities. This could involve discussing how you would approach threat modelling or secure code reviews. Showing your thought process will illustrate your analytical skills and ability to mitigate risks.
✨Communicate Clearly and Collaboratively
Since the role involves working closely with engineering teams, it's crucial to convey your ideas clearly. Practice explaining complex security concepts in simple terms, as this will showcase your communication skills and your ability to collaborate effectively with non-security professionals.
✨Prepare Questions About Company Culture
Ebury values a collaborative and innovative environment. Prepare thoughtful questions about their team dynamics, employee networks, and professional development opportunities. This shows your interest in their culture and your desire to contribute positively to the team.