At a Glance
- Tasks: Join our Security team to protect customers and innovate in financial security.
- Company: Monzo, a forward-thinking bank on a mission to simplify finance for everyone.
- Benefits: Competitive salary, performance incentives, flexible working, and a £1,000 learning budget.
- Other info: Diverse and inclusive workplace with excellent growth opportunities.
- Why this job: Make a real impact in cybersecurity while collaborating with diverse teams.
- Qualifications: Experience in security risk assessment and strong communication skills.
The predicted salary is between 57000 - 70000 £ per year.
We’re on a mission to make money work for everyone. We’re waving goodbye to the complicated and confusing ways of traditional banking. After starting as a prepaid card, our product offering has grown a lot in the last 10 years in the UK. As well as personal and business bank accounts, we offer joint accounts, accounts for 16-17 year olds, a free kids account and credit cards in the UK, with more exciting things to come beyond. Our UK customers can also save, invest and combine their pensions with us. With our hot coral cards and get-paid-early feature, combined with financial education on social media and our award-winning customer service, we have a long history of creating magical moments for our customers! We’re not about selling products - we want to solve problems and change lives through Monzo.
At Monzo, our mission is to make money work for everyone. Central to this is making sure the bank is safe and secure for our customers. We’re always keen to hear from people who believe in our mission and want to join us on this journey. We’re looking for a proactive, curious, technically-minded and organised Senior Security Analyst to join Monzo's Security team. Our team is Monzo’s front door to Security, helping the whole business operate securely. This means you’ll get exposure to a wide range of business context and a broad mix of information security work. One day you might be assessing the security of a new supplier; the next you could be supporting an audit or assurance review, assessing the risks of a new product or technology change, updating a policy, or helping a team turn regulatory requirements into practical action.
You’ll work closely with security specialists, engineers, product teams, third party risk, procurement, and colleagues from across Monzo to solve interesting problems and strengthen how we effectively manage security risk as we grow. We want security to protect Monzo without creating unnecessary friction or compromising user experience. You’ll have the opportunity to make a notable impact in an environment where security is both a priority and an opportunity for innovation!
You’ll play a key role by:
- Delivering third party security and supplier security assurance: assess new and existing suppliers, reviewing questionnaires, certifications, and other evidence to understand their security posture. Use your judgement to identify risks, translate technical findings into recommendations, and work with teams across Monzo to manage them throughout the supplier lifecycle.
- Delivering security assurance activities: lead and contribute to control testing, PCI DSS assessments, regulatory reviews, and internal and external audits. Evaluate evidence, identify gaps and work with teams across Monzo to see findings and remediation through to completion.
- Strengthening our governance: improve security policies, procedures and controls so they’re practical, proportionate, and reflect how things work in reality.
- Supporting our Security Front Door: work alongside our other analysts to respond to security questions and requests from across Monzo, bringing in specialists when needed and finding ways to make the experience better for other Monzonauts.
- Taking ownership and running with it: turn loosely defined security problems into clear outcomes, work out the best way forward, and bring in the right people to make it happen.
- Helping teams build and change safely: work with engineers, product teams and other colleagues to understand what they’re trying to achieve. Review new products and technology or business changes, identify security risks and control gaps, and turn security and regulatory expectations into requirements that work in practice.
- Improving how we work: use data, automation and AI to make our processes simpler and more scalable, while exploring new ways technology can help us work smarter.
- Raising the bar for security: bring fresh perspectives to real-world security challenges, keep developing your own skills and knowledge, and help less experienced analysts grow.
We’d love to hear from you if:
- You understand security risk: you’re comfortable identifying and assessing security risks, and can recommend proportionate ways to manage them. Experience in third party security or supplier security assurance would be a bonus!
- You can evaluate security evidence: you can review supplier questionnaires, security policies, penetration test reports and assurance evidence, and know when to dig deeper.
- You have strong security fundamentals and technical curiosity: you understand core security concepts and good practice, are comfortable getting into technical detail, and ask thoughtful questions to get to the heart of a problem.
- You think beyond the task in front of you: you look for patterns and root causes, use evidence and data to prioritise and look for ways to make things work better.
- You’re proactive: you can make progress independently, seek out the information you need, and are comfortable challenging assumptions to move things forward.
- You can manage competing priorities: you can juggle different pieces of work, keep people informed, and make sensible decisions about what needs attention or escalation.
- You’re a clear communicator: you can explain security risks and recommendations to technical and non-technical audiences in a way that works for them.
- You enjoy collaborating: you like working with people across different disciplines, building strong relationships, and helping make security easier to do well.
- You’re passionate about security: you’re excited by the challenges and opportunities in cyber security, keep up with an evolving industry, and are motivated to continue developing your knowledge and skills.
It would be great if:
- You’ve worked in financial services, fintech, or another highly regulated environment.
- You’ve supported PCI DSS, ISO 27001, SOC 2 or NIST-aligned assurance, regulatory reviews, or internal and external audits.
Not ticking every box? That’s totally okay! Studies show that women and people of colour might hesitate to apply unless they meet every single requirement. At Monzo, we’re dedicated to creating a diverse and welcoming team. If you’re passionate about this role and keen to learn and grow with us, we encourage you to apply— even if you don’t have everything that's listed just yet. Drop us your application, we’d love to hear from you!
What’s in it for you:
- 57,000 - 70,000 Incentive Awards tied to your performance.
- This role can be based in our London office, but we're open to distributed working within the UK (with ad hoc meetings in London). We offer flexible working hours and trust you to work enough hours to do your job well, and at times that suit you and your team.
- 1,000 learning budget each year to use on books, training courses and conferences.
- We will set you up to work from home; all employees are given Macbooks and for fully remote workers we will provide extra support for your work-from-home setup.
The application journey has 3 key steps:
- Intro call with the recruiter
- 30 min call with the hiring manager
- 2 hours of technical and behavioural interviews
This process should take around 4-5 weeks - your schedule is really important to us, so we promise to be as flexible as possible! We have some guidelines on using Artificial Intelligence (AI) to ace an application and interview at Monzo.
We’ll only close this role once we have enough applications for the next stage. Please submit your application as soon as possible to make sure you don’t miss out.
Equal opportunities for everyone. Diversity and inclusion are a priority for us and we’re making sure we have lots of support for all of our people to grow at Monzo. At Monzo, we’re embracing diversity by fostering an inclusive environment for all people to do the best work of their lives with us. This is integral to our mission of making money work for everyone.
We’re an equal opportunity employer. All applicants will be considered for employment without attention to age, ethnicity, religion, sex, sexual orientation, gender identity, family or parental status, national origin, or veteran, neurodiversity or disability status. If you have a preferred name, please use it to apply. We don't need full or birth names at application stage.
Senior Security Analyst in London employer: Monzo Bank
Monzo is an exceptional employer that prioritises innovation and collaboration, making it a fantastic place for a Remote CRM Executive to thrive. With a strong focus on employee growth, we offer a generous learning budget and flexible working hours, ensuring you can develop your skills while maintaining a healthy work-life balance. Our commitment to diversity and inclusion fosters a supportive environment where every team member can contribute to meaningful change in the financial sector.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Security Analyst in London
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Monzo Bank, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Monzo Bank
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Monzo Bank. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Senior Security Analyst in London
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Monzo Bank insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Monzo Bank that you’re committed to staying ahead in the game.
How to prepare for a job interview at Monzo Bank
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Monzo Bank to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Monzo Bank.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.