At a Glance
- Tasks: Join our Security Team to enhance application security and protect customer data.
- Company: Funding Circle, a leading FinTech supporting small businesses with innovative finance solutions.
- Benefits: Flexible hybrid working, competitive salary, health insurance, and professional development opportunities.
- Why this job: Make a real impact in securing cutting-edge technology for small businesses.
- Qualifications: 3+ years in application security, AWS expertise, and a passion for secure coding.
- Other info: Diverse team culture with excellent career growth and support for personal development.
The predicted salary is between 48000 - 84000 £ per year.
We are seeking an experienced Senior Application Security Engineer to join our dynamic Security Team. This is a key role where you will be a primary contributor to Funding Circle's security posture, with a strong focus on Application Security. You will leverage your deep expertise in secure software development lifecycle (SSDLC) practices and CI/CD security to act as a subject matter expert and mentor, collaborating closely with engineering and product teams to embed security seamlessly into our development processes. You will also apply your knowledge of AWS to secure the underlying cloud infrastructure. Join us to protect our platform and customer data in a fast-paced FinTech environment.
The role includes:
- Defining, championing, and embedding secure software development lifecycle (SSDLC) practices and secure coding standards across engineering teams through collaboration, training, and tooling.
- Performing threat modelling exercises for cloud-native applications, microservices, and infrastructure components.
- Managing internal and external penetration testing engagements for Funding Circle applications, services, and cloud infrastructure.
- Collaborating closely with Cloud Platform Engineers, DevX and Product Engineering to ensure security requirements are integrated into system designs and technology choices from the outset.
- Acting as a subject matter expert on DevSecOps, application security, and cloud security (AWS), providing guidance and mentorship to other engineers.
- Contributing to drive implementation of security automation across cloud infrastructure configuration, vulnerability management, and compliance monitoring.
- Designing, implementing, and supporting the adoption of robust security architectures, controls, and best practices within our AWS cloud environment.
What we’re looking for:
- Over 3 years of information security experience with a deep focus on application/product security, complemented by strong expertise in securing AWS environments and Infrastructure as Code (IaC).
- Proven track record of defining, implementing, and driving the adoption of secure software development lifecycle (SSDLC) practices and secure coding standards within engineering teams.
- Hands-on experience architecting and integrating a suite of security tools (SAST, DAST, SCA, IAST, secrets management) and automated controls directly into CI/CD pipelines like GitLab CI, Jenkins, or GitHub Actions.
- Deep understanding of web application vulnerabilities (OWASP Top 10) and experience contributing to vulnerability management programs.
- Solid knowledge of container security best practices and securing container orchestration platforms, specifically Kubernetes and AWS EKS.
- Strong knowledge of key security frameworks (NIST CSF, MITRE ATT&CK) and standards (CIS Benchmarks, OWASP ASVS), with experience managing external penetration testing and coordinating remediation efforts.
Nice to have:
- Experience with specific security platforms/tools (e.g., Wiz, Snyk, Checkmarx, Veracode).
- Relevant advanced security certifications (e.g., AWS Certified Security - Specialty, CISSP, CCSP, OSCP/OSWE).
- Proficiency in security automation using scripting languages (e.g., Python).
- Experience working in FinTech or other highly regulated environments.
- Experience with mobile application security principles and testing.
At Funding Circle we are committed to building diverse teams so please apply even if your past experience doesn’t align perfectly with the requirements.
Why join us? At Funding Circle, we celebrate and support the differences that make you, you. We’re proud to be an equal-opportunity workplace and affirmative-action employer. We truly believe that diversity makes us better. As a flexible-first employer we offer hybrid working at Funding Circle, and we’ve long believed in a 'best of both' approach to in-office collaboration and non-office days. We expect our teams to be in our London office two times a week, where you can take advantage of our newly refurbished hybrid working space, barista made coffee and subsidised lunches (via JustEat) every day!
We back our Circlers to build their own incredible career, making a difference to small businesses every day. Our Circler proposition is designed to support employees both in and out of work, and it is anchored around four pillars: Health, Wealth, Development & Lifestyle.
A Few Highlights:
- Health: Private Medical Insurance through Aviva, Dental Insurance through Bupa, MediCash, access to free online therapy sessions and exclusive discounts with Hertility for reproductive health support.
- Wealth: Octopus Money Coach, free mortgage advisor partnership and discounts across numerous retailers through Perks at Work.
- Development: Dedicated annual learning allowance and full access to internal learning platform.
- Lifestyle: Wellhub (for fitness discounts), Electric Car Scheme and more!
And finally, we have award winning parental leave policies supporting parents through enhanced maternity, partner and adoption leave, as well as additional leave for parental bereavement and for fertility treatments.
Ready to make a difference? We’d love to hear from you.
Senior Security Engineer in London employer: Funding Circle UK
Contact Detail:
Funding Circle UK Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Security Engineer in London
✨Tip Number 1
Network like a pro! Reach out to your connections in the industry, especially those who work at Funding Circle or similar companies. A friendly chat can open doors and give you insider info on the role.
✨Tip Number 2
Prepare for the interview by brushing up on your knowledge of AWS and secure software development practices. Be ready to discuss how you've implemented SSDLC in past roles – real examples will make you stand out!
✨Tip Number 3
Show off your passion for security! During interviews, share your thoughts on the latest trends in application security and how you stay updated. This shows you're not just qualified, but genuinely interested in the field.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re keen on joining the Funding Circle team!
We think you need these skills to ace Senior Security Engineer in London
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience in application security and AWS. We want to see how your skills align with our mission at Funding Circle!
Showcase Your Expertise: Don’t hold back on sharing your knowledge of secure software development lifecycle (SSDLC) practices. We’re looking for someone who can champion these standards, so let us know how you’ve done this in the past.
Be Clear and Concise: When writing your application, keep it straightforward and to the point. We appreciate clarity, especially when discussing your experience with CI/CD security and vulnerability management.
Apply Through Our Website: We encourage you to submit your application through our website. It’s the best way for us to receive your details and get the ball rolling on your journey with Funding Circle!
How to prepare for a job interview at Funding Circle UK
✨Know Your Stuff
Make sure you brush up on your knowledge of secure software development lifecycle (SSDLC) practices and AWS security. Be ready to discuss how you've implemented these in past roles, as this will show you're not just familiar with the concepts but have real-world experience.
✨Showcase Your Collaboration Skills
Since this role involves working closely with engineering and product teams, prepare examples of how you've successfully collaborated in the past. Highlight any mentoring experiences you’ve had, especially in driving security practices within teams.
✨Be Ready for Technical Questions
Expect to dive deep into technical topics like threat modelling, vulnerability management, and CI/CD integration. Brush up on the OWASP Top 10 vulnerabilities and be prepared to discuss how you would address them in a cloud-native environment.
✨Ask Insightful Questions
Prepare thoughtful questions about Funding Circle's current security posture and future initiatives. This shows your genuine interest in the role and helps you gauge if the company aligns with your values and career goals.