At a Glance
- Tasks: Lead application security initiatives and mentor teams in secure software practices.
- Company: Join Funding Circle, a dynamic FinTech company supporting small businesses.
- Benefits: Enjoy hybrid working, competitive salary, health perks, and professional development opportunities.
- Why this job: Make a real impact on security in a fast-paced environment while helping small businesses thrive.
- Qualifications: 3+ years in application security with AWS expertise and a passion for secure coding.
- Other info: Diverse team culture with excellent career growth and flexible working options.
The predicted salary is between 48000 - 84000 £ per year.
We are seeking an experienced Senior Application Security Engineer to join our dynamic Security Team. This is a key role where you will be a primary contributor to Funding Circle's security posture, with a strong focus on Application Security. You will leverage your deep expertise in secure software development lifecycle (SSDLC) practices and CI/CD security to act as a subject matter expert and mentor, collaborating closely with engineering and product teams to embed security seamlessly into our development processes. You will also apply your knowledge of AWS to secure the underlying cloud infrastructure. Join us to protect our platform and customer data in a fast-paced FinTech environment.
The role:
- Define, champion, and embed secure software development lifecycle (SSDLC) practices and secure coding standards across engineering teams through collaboration, training, and tooling.
- Perform threat modelling exercises for cloud-native applications, microservices, and infrastructure components.
- Manage internal and external penetration testing engagements for Funding Circle applications, services, and cloud infrastructure.
- Collaborate closely with Cloud Platform Engineers, DevX and Product Engineering to ensure security requirements are integrated into system designs and technology choices from the outset.
- Act as a subject matter expert on DevSecOps, and application security, cloud security (AWS), providing guidance and mentorship to other engineers.
- Contribute to drive implementation of security automation across cloud infrastructure configuration, vulnerability management, and compliance monitoring.
- Design, implement, and support the adoption of robust security architectures, controls, and best practices within our AWS cloud environment.
What we're looking for:
- Application & Cloud Security Expertise: Over 3 years of information security experience with a deep focus on application/product security, complemented by strong expertise in securing AWS environments and Infrastructure as Code (IaC).
- Champion for Secure Development: Proven track record of defining, implementing, and driving the adoption of secure software development lifecycle (SSDLC) practices and secure coding standards within engineering teams.
- Security Automation & CI/CD Integration: Hands-on experience architecting and integrating a suite of security tools (SAST, DAST, SCA, IAST, secrets management) and automated controls directly into CI/CD pipelines like GitLab CI, Jenkins, or GitHub Actions.
- Vulnerability Management & Threat Intelligence: Deep understanding of web application vulnerabilities (OWASP Top 10) and experience contributing to vulnerability management programs.
- Container & Orchestration Security: Solid knowledge of container security best practices and securing container orchestration platforms, specifically Kubernetes and AWS EKS.
- Frameworks & Compliance: Strong knowledge of key security frameworks (NIST CSF, MITRE ATT&CK) and standards (CIS Benchmarks, OWASP ASVS), with experience managing external penetration testing and coordinating remediation efforts.
Nice to have:
- Experience with specific security platforms/tools (e.g., Wiz, Snyk, Checkmarx, Veracode).
- Relevant advanced security certifications (e.g., AWS Certified Security - Specialty, CISSP, CCSP, OSCP/OSWE).
- Proficiency in security automation using scripting languages (e.g., Python).
- Experience working in FinTech or other highly regulated environments.
- Experience with mobile application security principles and testing.
At Funding Circle we are committed to building diverse teams so please apply even if your past experience doesn’t align perfectly with the requirements.
As a flexible-first employer we offer hybrid working at Funding Circle, and we’ve long believed in a 'best of both' approach to in-office collaboration and non-office days. We expect our teams to be in our London office two times a week, where you can take advantage of our newly refurbished hybrid working space, barista made coffee and subsidised lunches (via JustEat) every day!
We back our Circlers to build their own incredible career, making a difference to small businesses every day. Our Circler proposition is designed to support employees both in and out of work, and it is anchored around four pillars: Health, Wealth, Development & Lifestyle.
A few highlights:
- Health: Private Medical Insurance through Aviva, Dental Insurance through Bupa, MediCash, access to free online therapy sessions and exclusive discounts with Hertility for reproductive health support.
- Wealth: Octopus Money Coach, free mortgage advisor partnership and discounts across numerous retailers through Perks at Work.
- Development: Dedicated annual learning allowance and full access to internal learning platform.
- Lifestyle: Wellhub (for fitness discounts), Electric Car Scheme and more!
And finally, we have award winning parental leave policies supporting parents through enhanced maternity, partner and adoption leave, as well as additional leave for parental bereavement and for fertility treatments.
Senior Security Engineer in London employer: Funding Circle Ltd.
Contact Detail:
Funding Circle Ltd. Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Security Engineer in London
✨Tip Number 1
Network like a pro! Reach out to your connections in the industry, especially those who work at Funding Circle or similar companies. A friendly chat can lead to insider info about job openings and even referrals.
✨Tip Number 2
Show off your skills! Prepare a portfolio or a GitHub repository showcasing your projects related to application security and AWS. This gives you a chance to demonstrate your expertise beyond just words.
✨Tip Number 3
Ace the interview! Research common interview questions for Senior Security Engineers and practice your responses. Be ready to discuss your experience with SSDLC practices and how you've integrated security into CI/CD pipelines.
✨Tip Number 4
Apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you're genuinely interested in joining the Funding Circle team.
We think you need these skills to ace Senior Security Engineer in London
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter for the Senior Security Engineer role. Highlight your experience with SSDLC practices and AWS security, as these are key areas we're looking for!
Showcase Your Expertise: Don’t hold back on showcasing your knowledge of application security and CI/CD integration. Use specific examples from your past work to demonstrate how you've implemented security measures effectively.
Be Authentic: Let your personality shine through in your application. We value diversity and want to see the real you, so don’t be afraid to share your unique experiences and perspectives.
Apply Through Our Website: For the best chance of success, make sure to apply directly through our website. This way, we can easily track your application and get back to you quicker!
How to prepare for a job interview at Funding Circle Ltd.
✨Know Your Stuff
Make sure you brush up on your knowledge of secure software development lifecycle (SSDLC) practices and AWS security. Be ready to discuss how you've implemented these in past roles, as well as any specific tools you've used in CI/CD pipelines.
✨Showcase Your Experience
Prepare to share concrete examples of your experience with application security, threat modelling, and vulnerability management. Use the STAR method (Situation, Task, Action, Result) to structure your answers and highlight your contributions.
✨Be a Team Player
Since collaboration is key in this role, think of examples where you've worked closely with engineering or product teams. Emphasise your ability to mentor others and how you've championed security practices within a team setting.
✨Ask Smart Questions
Prepare insightful questions about Funding Circle's security posture and future initiatives. This shows your genuine interest in the role and helps you gauge if the company aligns with your values and career goals.