Senior Security Engineer(Hybrid) in London

Senior Security Engineer(Hybrid) in London

London Full-Time On-site
S

At Spendesk, we're building the leading spend management platform for modern businesses, processing billions of euros across Europe and beyond. Security is at the heart of what we do: our customers trust us to safeguard their financial data, and we're committed to raising the bar for security in fintech. We're creating a dedicated Security Engineering function. You'll be the first senior hire in this space, shaping how we protect our platform, how we respond to threats, and how we build a security-aware engineering culture from the inside. Your MissionYou'll be the security conscience for engineering: building tooling, training developers, and partnering with Infrastructure on secure-by-default solutions. You own the technical security roadmap: partnering with the compliance team to identify risks, translating findings into actionable engineering-native tools and processes, driving remediation, and raising the bar across the organisation. This is a pure engineering role, not governance or compliance: a separate team owns policy and risk frameworks. You'll mentor an Associate Security Engineer, shape practices across squads, and be the go-to person when engineering teams need security guidance. You'll be hands-on across the full security surface from day one. As the team grows, you'll move from day-to-day operations toward architecture, strategy, and mentoring, acting as the escalation point for the Associate Security Engineer. Lead security incident response: qualification, forensics (including fraud investigations), fix coordination, post-mortem, and resolution tracking. Detection & SIEMOwn our SIEM platform (ElasticSearch, multi-node Linux): architecture, detection rules, and indicators of compromise. Build and evolve detection coverage, focusing on signal quality over manual toil. Build and maintain security runbooks and operational documentation. Identity & access managementOwn IAM implementation and operations for product and infrastructure systems, downstream of corporate IT: SSO/MFA configuration, role and access-rights implementation, periodic permission reviews, and secrets rotation. Work within the authentication standards set by the security governance team. Secure development & auditsEmbed security into the development lifecycle: threat modelling, secure code patterns, CI/CD hardening. Conduct technical security reviews of code (TypeScript, Node.js, Python), infrastructure-as-code (Terraform), and multi-tenant AWS environments. Drive security tooling in CI/CD: design and own the automated gate suite (SAST, SCA, container scanning, AI-generated code risk detection) and ensure pipeline coverage scales with engineering growth. Assess and govern AI tooling adoption across engineering: define security standards for code assistants and LLM-powered workflows, and conduct AI-specific threat modelling. Coordinate and execute penetration tests and security audits: prepare environments, manage auditor relationships, drive post-audit action plans. Drive remediation within the qualification rules and timeframes set by the security governance team. Surface security risks and recommendations to engineering leadership; own the security backlog and roadmap. A track record of owning security outcomes end to end, with hands-on experience across at least three of: code auditing, infrastructure security (AWS/Linux), penetration testing, SIEM operations, incident response. Deep understanding of modern web architectures (microservices, cloud-native, PaaS/SaaS) and where they break. Strong scripting and automation ability (Python, Bash, or similar).Experience mentoring other engineers or security practitioners. Familiarity with AWS, GCP, Snowflake, Datadog, Okta. Knowledge of security standards and frameworks (ISO 27001, OWASP, SOC 2, PCI-DSS).Reverse engineering and analysis of minified/obfuscated code. As we are an international team, please submit your application and CV in English. About SpendeskSpendesk is the AI-powered spend management and procurement platform that transforms company spending. Trusted by thousands of companies, Spendesk supports over 200,000 users across brands such as Payfit, Accor, Welcome to the Jungle, Swile, Big Mamma, Malt and Yousign. With offices in the United Kingdom, France, Spain and Germany, Spendesk also puts community at the heart of its mission. Flexible on-site and remote policyLatest Apple equipment β€” the tools you need to excelAccess to Moka.care β€” for emotional and mental health wellbeingGreat office snacks β€” to fuel your dayA positive team to work with daily! We also offer location-specific benefits tailored to each market, including health insurance, wellness allowances, commuter support, meal vouchers, and gym memberships β€” ensuring you're well supported wherever you're based. Diversity & InclusionAt Spendesk, we're committed to fostering an environment where all differences are encouraged, supported and celebrated. We're building our culture for everyone, with everyone.

Senior Security Engineer(Hybrid) in London employer: Spendesk

At Spendesk, we pride ourselves on fostering a collaborative and innovative work culture that empowers our employees to grow and excel in their careers. As an Associate Security Engineer, you will benefit from hands-on mentorship from experienced professionals while working remotely, allowing for a flexible work-life balance. Our commitment to employee development and security excellence makes Spendesk an exceptional place to build a meaningful career in the tech industry.

S

Contact Details:

Spendesk Recruitment Team