At a Glance
- Tasks: Join our InfoSec team to enhance security across applications and cloud infrastructure.
- Company: Marshmallow, a fintech company dedicated to making migration easy.
- Benefits: Hybrid working, competitive bonuses, flexible benefits budget, and mental wellbeing support.
- Other info: Enjoy 25 days holiday, personal development budgets, and a supportive team culture.
- Why this job: Make a real impact in a dynamic environment while growing your skills.
- Qualifications: Experience in information security within a cloud-based organisation and knowledge of security best practices.
The predicted salary is between 36000 - 60000 £ per year.
About Marshmallow
We exist to make migration easy. A systemic problem of this magnitude requires a team of curious thinkers who relentlessly pursue solutions. Those who constantly challenge the why, dismantle assumptions, and always take action to build a better way. A Marshmallow career is built on a cycle of continuous growth, with learning at its core. You will be challenged to raise the bar on your capabilities and supported with the right tools and guidance to do so. This ensures you can deliver impactful work and drive change.
Engineering at Marshmallow
Our engineers are at the heart of the solutions. They work on product builds from start to finish, solving lots of challenges to help us build fast and scale up! Our engineers cover a range of skills across frontend, backend, full stack, iOS, and Android, and work alongside designers, data scientists, researchers, and product managers within our product teams. Information Security (InfoSec) is an enabling function within this environment. InfoSec works alongside Engineering, IT teams, and other business teams to ensure security controls are embedded pragmatically into systems, processes, and day-to-day operations, in line with regulatory and risk expectations.
About the team you will be joining
You will join the InfoSec team, reporting to the Head of InfoSec & TechOps. The team operates across product engineering, cloud infrastructure, corporate IT, and other business teams to support Marshmallow’s security posture in a regulated fintech environment. This role is execution focused and operational in nature. It covers application, cloud, and corporate security, with responsibility for operating security controls, responding to security alerts, improving processes, and working directly with teams to maintain an appropriate risk posture as Marshmallow scales.
What you’ll be doing
- Acting as a security point of contact for Engineering and IT initiatives impacting applications, cloud infrastructure, employee devices, and internal systems
- Supporting application security through collaboration with development teams and embedding security into SDLC and DevOps processes
- Operating and improving cloud security controls, with a primary focus on AWS
- Monitoring, triaging, and responding to security alerts from tooling such as SIEM, DLP, and endpoint management platforms during business hours
- Supporting vulnerability management through analysis, prioritisation, and remediation guidance
- Contributing to incident response activities, including investigation support, remediation coordination, and post-incident improvements
- Improving information security processes and operational practices to increase consistency, effectiveness, and operational excellence
- Contributing to security policies, standards, and procedures, and supporting their adoption across engineering, IT, and business teams
Who you are
- Pragmatic and delivery-focused, with a risk-based approach grounded in security best practice
- Comfortable working in a regulated environment and applying proportionate controls
- Confident collaborating with engineers, IT teams, and non-security stakeholders
- Able to operate independently on defined workstreams while escalating material risk appropriately
- Calm, methodical, and structured when responding to security alerts and incidents
What we’re looking for from you
- Experience working in an information security role within a cloud-based organisation
- A practical understanding of cloud security concepts (AWS preferred)
- Working knowledge of secure development practices and DevSecOps principles
- Exposure to both technical and operational security domains
- Hands-on experience operating or supporting security tooling (SIEM, MDM/endpoint security, DLP, or similar)
- Familiarity with endpoint, identity, and corporate security controls
- Solid understanding of network and application-level security fundamentals
- Familiarity with security frameworks and standards such as ISO 27001, NIST, and CIS Controls
Perks of the job
- Hybrid working - Spend 3 days a week with your team in our collaborative London office
- Competitive bonus scheme - designed to reward and recognise high performance
- Flexible benefits budget - £50 per month to spend on a Ben Mastercard
- Sabbatical Leave - Get a 4-week fully paid sabbatical after being with us for 4 years
- Work From Anywhere - 4 weeks work from anywhere to use, with no need to come to the office
- Mental wellbeing support – Access therapy and mental health sessions through Oliva
- Learning and development – Personal budgets for books and training courses to help you grow in your role
- Private health care - Enjoy all the benefits Vitality has to offer
- Medical cash plan - To help you with the costs of dental, optical and physio
- Tech scheme - Get the latest tech for less
- Plus all the rest; 25 days holiday (+ bank holidays), pension, cycle to work scheme, monthly team socials and company-wide socials every month!
Our Process
We break it up into 4 stages:
- Initial call with a member of our Talent Acquisition team (40 mins)
- A past-experience interview (60 mins)
- A skill-based/technical interview (60 mins)
- A culture interview to check that your work style fits our processes and values (60 mins)
We’ll let you know if you’re invited to an interview or not. But, as a small team with a lot of applications to consider, we can’t give individual feedback on each application.
Background checks
As part of our commitment to maintaining a safe and trustworthy environment, we’ll carry out standard background checks, including a DBS and a Cifas check. These help ensure there are no ongoing criminal proceedings and support the prevention of fraud and other forms of serious misconduct.
Everyone belongs at Marshmallow
At Marshmallow, we want to hire people from all walks of life with the passion and skills needed to help us achieve our company mission. To do that, we’re committed to hiring without judgement, prejudice or bias. We encourage everyone to apply for our open roles.
Recruitment privacy policy
We take privacy seriously here at Marshmallow. Our Recruitment privacy notice explains how we process and handle your personal data.
Information Security Engineer employer: Marshmallow
At Marshmallow, we pride ourselves on fostering a culture of continuous growth and collaboration, making it an exceptional place for Information Security Engineers to thrive. With a hybrid working model in our vibrant London office, competitive benefits including a flexible budget for personal development, and a strong commitment to mental wellbeing, we empower our employees to challenge the status quo and drive meaningful change. Join us to be part of a dynamic team that values innovation and supports your professional journey.
StudySmarter Expert Advice🤫
We think this is how you could land Information Security Engineer
✨Tip Number 1
Get to know the company culture! Dive into Marshmallow's Culture Handbook and Engineering Handbook. Understanding their values and ways of working will help you tailor your conversations during interviews.
✨Tip Number 2
Network like a pro! Connect with current employees on LinkedIn or attend industry events. A friendly chat can give you insights and maybe even a referral, which can really boost your chances!
✨Tip Number 3
Prepare for those technical interviews! Brush up on your cloud security knowledge, especially AWS, and be ready to discuss secure development practices. Practice makes perfect, so run through some mock interviews with friends.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in being part of the Marshmallow team!
We think you need these skills to ace Information Security Engineer
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter for the Information Security Engineer role. Highlight your relevant experience in cloud security and secure development practices, as this will show us you understand what we're looking for.
Show Your Curiosity:We love curious thinkers! In your application, share examples of how you've challenged assumptions or solved complex problems in your previous roles. This aligns perfectly with our mission at Marshmallow.
Be Clear and Concise:When writing your application, keep it straightforward. Use clear language and avoid jargon where possible. We appreciate a well-structured application that gets straight to the point!
Apply Through Our Website:Don’t forget to submit your application through our website! This helps us keep everything organised and ensures your application gets the attention it deserves. We can’t wait to hear from you!
How to prepare for a job interview at Marshmallow
✨Know Your Stuff
Make sure you brush up on your knowledge of cloud security concepts, especially AWS. Be ready to discuss secure development practices and how they fit into the SDLC and DevOps processes. This will show that you're not just familiar with the theory but can apply it in real-world scenarios.
✨Show Your Pragmatic Side
Marshmallow values a risk-based approach to security. During the interview, be prepared to share examples of how you've applied proportionate controls in previous roles. This will demonstrate your ability to think critically and act decisively in a regulated environment.
✨Collaborate Like a Pro
Since you'll be working closely with engineers and IT teams, highlight your experience in cross-functional collaboration. Share specific instances where you successfully communicated security needs to non-security stakeholders, showcasing your ability to bridge the gap between technical and operational domains.
✨Be Calm Under Pressure
When discussing your experience with security alerts and incidents, emphasise your methodical approach. Share how you triaged and responded to alerts in past roles, as this will illustrate your ability to remain composed and effective in high-pressure situations, which is crucial for the InfoSec team.