At a Glance
- Tasks: Lead security initiatives and shape architecture across AWS and on-premises environments.
- Company: Join a dynamic tech company revolutionising payment solutions for SMBs and fintech startups.
- Benefits: Enjoy competitive salary, remote work, flexible hours, and generous holiday allowance.
- Other info: Be part of a culture that values diversity, innovation, and employee wellbeing.
- Why this job: Make a real impact in security while working with cutting-edge technology and diverse teams.
- Qualifications: Extensive experience in security engineering and cloud security, especially with AWS.
The predicted salary is between 90000 - 130000 £ per year.
We are seeking a Senior Staff Information Security Engineer to help shape and advance security across our hybrid technology estate.
Our environment spans AWS and on-premises infrastructure hosted in colocation facilities.
You will provide senior technical leadership across both environments, defining secure architecture patterns, building scalable controls, and partnering with Engineering, Product, SRE, and Infrastructure teams to reduce risk without creating unnecessary barriers to delivery.
This is a senior individual-contributor role.
You will remain hands-on while acting as a trusted technical authority for complex security architecture and engineering decisions.
You will lead initiatives that cross teams and technologies, address systemic security challenges, and improve how security is designed and implemented across the organisation.
The role is primarily remote, with occasional in-person responsibilities at our Bristol, UK office and, where necessary, our colocation facilities.
What you'll do
- Lead Infrastructure Security Architecture
- Define and evolve security architecture across AWS and our colocation estate.
- Establish secure reference architectures, engineering standards, and reusable control patterns.
- Provide technical leadership for major infrastructure, platform, and product initiatives.
- Identify systemic risks and lead practical, sustainable programmes to address them.
- Strengthen Cloud and Hybrid Security
- Design and improve security across cloud accounts, networks, identities, workloads, and shared services.
- Establish effective controls for identity and access management, segmentation, encryption, secrets, logging, monitoring, and workload protection.
- Develop preventative guardrails through infrastructure-as-code, policy-as-code, automation, and cloud-native security services.
- Improve consistency across the enterprise including cloud, on-premises infrastructure, and the connectivity between them.
- Partner with Engineering and Product
- Engage early in the design of new products, platforms, services, and integrations.
- Lead threat modelling, security architecture reviews, and technical risk assessments.
- Translate security risks into clear, practical engineering recommendations.
- Help teams adopt secure-by-design principles through reusable patterns, tooling, and documentation.
- Build, Automate, and Apply AI
- Design and implement security tooling, integrations, and automated controls.
- Embed security capabilities into infrastructure provisioning, engineering workflows, and CI/CD pipelines.
- Use AI-assisted tooling to improve scripting, detection development, alert analysis, vulnerability triage, threat modelling, and technical documentation.
- Validate AI-generated outputs and ensure AI tools are used with appropriate controls for confidentiality, accuracy, access, and human oversight.
- Improve Risk Reduction and Resilience
- Provide technical direction for vulnerability and exposure management across AWS and on-premises infrastructure.
- Identify recurring patterns across incidents, penetration tests, vulnerabilities, and control assessments.
- Act as a senior technical escalation point during significant security incidents.
- Ensure investigations and lessons learned result in durable architectural and engineering improvements.
- Provide Senior Technical Leadership
- Lead complex security initiatives spanning multiple teams and planning cycles.
- Mentor security engineers and provide guidance to engineers in adjacent teams.
- Raise the standard of security architecture, automation, documentation, and technical decision-making.
- Communicate security risks and recommendations clearly to technical teams, product leaders, and senior stakeholders.
What you'll bring
- Significant experience in security engineering, infrastructure security, cloud security, security architecture, or platform engineering.
- Deep, hands-on experience securing AWS environments.
- Strong knowledge of AWS identity and access management, network architecture, account governance, encryption, logging, monitoring, secrets management, and workload protection.
- Experience designing or securing on-premises, data-centre, or colocation-hosted infrastructure.
- Strong knowledge of enterprise networking, segmentation, firewalls, secure remote access, privileged administration, and hybrid connectivity.
- Experience with infrastructure-as-code, CI/CD security, containerised environments, and cloud-native platforms.
- Demonstrated experience designing and implementing automated security controls and engineering solutions.
- Proficiency with scripting or software development using Python, Go, or a comparable language.
- Practical experience using AI-assisted tooling to improve security engineering and operational workflows.
- Experience leading complex initiatives across multiple engineering, infrastructure, or product teams.
- Strong knowledge of security architecture, threat modelling, vulnerability management, detection, and incident response.
- The ability to operate independently, navigate ambiguity, and influence decisions across technical and leadership audiences.
Desirable experience
- An advanced AWS certification in security, architecture, networking, or cloud engineering.
- Experience in fintech, payments, Saa S, or another regulated technology environment.
- Experience securing large or complex AWS multi-account estates.
- Experience with Kubernetes, container security, software supply-chain security, and policy-as-code.
- Experience with technologies such as CNAPP, CSPM, SIEM, EDR, DLP, WAF, vulnerability-management, network-security, or secrets-management platforms.
- Familiarity with PCI DSS, SOC 2, GDPR, NIST, or ISO 27001.
- Experience supporting significant security incidents, penetration tests, audits, or customer security assessments
As well as being a part of something exciting everyday, you will also receive the following benefits:
- Annual bonus scheme dependent on individual and company performance
- Annual salary of £90,000 - £130,000 depending on experience
- 25 days holiday each year (+ bank holidays + 1 day after each year of service with up to a max. of 30 days)
- Workplace pension scheme
- Private medical insurance (upon 30 days of employment)
- 7 hours per day, 35 hours per week
- A remote first culture
- Great work-life balance with our Flexi-time policy
- Family Friendly policies (Enhanced Maternity and Paternity Pay and Shared Parental Leave).
- A chance to develop with an allocated company training budget
- Bike2Work Scheme
- Lifeworks, an Employee Assistance Programme which offers wellbeing, family and financial support services, such as assessments, resources and even 1:1 counselling sessions.
It also offers interesting perks such as discounts on gyms, restaurants, high street retailers and cinema tickets
- A strong commitment to employee wellbeing including mental health first aiders
- Employee referral scheme with generous financial reward
- Bonusly colleague reward scheme
What we do!
NMI enables our partners with choice, and challenges the one-size-fits-all approach to payments.
You've probably used NMI in the last 24 hours without even realizing it.
We’re the platform that powers success for innovative tech created by SMBs, entrepreneurs and fintech startups.
We’re creative problem solvers who help visionaries smash through boundaries and think beyond what’s possible so they can think about what’s next.
But we’re not just built for the tech savvy.
We democratize the latest payments technology so that everyone can realize the benefits of easy payments across the full spectrum of commerce.
We’re all about enabling more payments in more ways and more places.
We believe that having a diverse group of employees strengthens both our work and our workplace.
We’re focused on making NMI more diverse and welcoming with initiatives like having a dedicated Diversity, Equity & Inclusion action group, diversity goals for hiring, anonymized resume screening, affinity groups such as our Women's network and LGBTQ+ Network, open forums for discussions on diversity and social justice, and measuring inclusion and belonging as part of our regular employee engagement surveys.
Equal Opportunity
NMI is committed to providing equal employment opportunity for all persons regardless of race, color, religion, sex, age, marital status, national origin, sexual orientation or sexual identity, genetic information, citizen status (except those that do not have the legal right to be employed in the United States), disability, military service, service member, veteran status, or any other basis protected by applicable law.
Please be aware that all offers of employment are made subject to receipt of satisfactory background and financial checks.
Attention job applicants: Please note that in compliance with the data protection regulations within your jurisdiction, any personal information submitted with your job application may be collected and used by NMI for the purpose of recruitment and employment-related activities.
By submitting your application, you acknowledge and provide explicit consent to the processing of your personal information as described in our privacy policy found on our website.
For more information on how we process your information, please read our privacy policy here:
- https://www. nmi. com/legal/privacy-policy/
- #LI-Remote
Salary range, depending on experience
- £90,000
- £130,000
- GBP
Senior Staff Information Security Engineer employer: NMI
NMI is an exceptional employer that prioritises employee growth and wellbeing, offering a remote-first culture and a strong commitment to work-life balance. With generous benefits such as an annual bonus scheme, private medical insurance, and a dedicated training budget, NMI fosters a nurturing environment where Software Engineers can thrive both personally and professionally. The company's focus on diversity and inclusion ensures that every team member feels valued, making it a rewarding place to build a meaningful career in the payments industry.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Staff Information Security Engineer
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including NMI, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through NMI
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at NMI. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Senior Staff Information Security Engineer
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at NMI insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to NMI that you’re committed to staying ahead in the game.
How to prepare for a job interview at NMI
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at NMI to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at NMI.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.