Senior Application Security Engineer

Posted Yesterday
Be an Early Applicant
Lisbon, PRT
In-Office
Senior level
Fintech • Software • Financial Services
The Role
Lead application security for Thought Machine by performing threat modeling, design reviews, vulnerability assessments, and security testing. Drive product security strategy, tooling selection and automation, advise development teams, and ensure data privacy and regulatory considerations are integrated across the software development lifecycle.
Summary Generated by Built In

Thought Machine's mission is bold – to properly and permanently rid the world's banks of legacy technology. To achieve this, we have developed the foundations of modern banking through core and payments technology which run natively in the cloud. What we are attempting is hard and means we need great people working together to build great technology.

We have grown rapidly in the past few years – growing our team to more than 550 individuals across offices in London, New York, Singapore, Sydney and our newly established Engineering Hub in Lisbon. We have raised more than £500m in funding and our investors include Molten Ventures, Eurazeo, Intesa Sanpaolo, Temasek, Nyca Partners, JPMorgan Chase Strategic Investments, Standard Chartered Ventures, and more.

We have created a culture that enables our team to produce the best work in the industry while ensuring we have fun along the way. We're regularly cited as having a fantastic workplace culture and have been recognised by Sifted magazine as having one of the highest Glassdoor ratings for a UK fintech company and the industry's most generous employee share package. Named one of the world's most innovative fintechs by Global Finance Magazine, we were also recognised by the Financial Times as one of Europe's fastest-growing companies for two consecutive years—and a UK Best Employer for 2026.

This is a full-time, permanent position based in our Lisbon office, requiring four days a week onsite.

This position plays a key role in ensuring Thought Machine teams are taking all required steps in building a secure product set. You will play a major and leading role in protecting Thought Machine product against security risks, with influence to implement cutting-edge measures to minimise exposures and vulnerabilities.

Whether engineering a system to address a technical security hurdle, protecting our customers' data, or consulting on a wide range of security topics, you are empowered to engage and lead cross-functionally.

A large part of Thought Machine product security function is a greenfield challenge, we are building the bank of tomorrow with cutting edge web technology, no best-practice/of the shelve security frameworks or tools can solve our security challenge. We are building the best security to enable engineering and impress financial service auditors. Key qualities of the ideal candidate would have experience in OWASP top 10 vulns, devsecOps, data privacy protection, passion to mentor and enable devs, creativity, autonomy, ability to work and complete multiple projects simultaneously.

DUTIES

  • Drive improvements to Thought Machines product security posture through strategic planning and collaboration with both development and infrastructure teams, with trust, autonomy and influence.

  • Produce production web scale grade application security design.

  • Review and produce data privacy and financial regulatory functional and nonfunctional designs.

  • Perform design reviews and Threat modeling of Thought Machine services and products.

  • Perform vulnerability assessments and security testing.

  • Providing subject matter expertise on all areas of security and privacy throughout the Software Development lifecycle.

  • Liaison with development teams for design, code reviews & education.

  • To contribute to security strategy, security tooling selection and creation.

  • Conduct regular security assessments and code reviews.

REQUIREMENTS

Essential

  • Expertise with a programming language (e.g. Python, Go or Java)

  • Experience of security in a DevOps environment

  • Experience in web application penetration testing and security tooling (e.g. Burp proxy, Web/Network Scanners, Static code analysers, etc).

  • Coding experience for automating/integrating security tools and creation of security tools.

  • Knowledge of security in distributed systems at scale.

  • Cloud and containers technology knowledge (e.g. AWS, GCP, Kuberbetes, Docker)

  • Experience of performing security design reviews, threat modelling and risk assessments

  • Knowledge of application security issues

Desirable

  • Professional security qualifications are desirable (e.g. CISSP, Offensive Security, Sans Institute, etc.)

  • Contributions to the security community (public research, blogging, presentations, etc)

  • Awareness and experience of the Data Protection Act, ISO 27001 and PCI-DSS

Benefits

  • Highly competitive salary

  • Voluntary Pension Plan (match up to 5%)

  • Private Healthcare Insurance

  • Comprehensive Life Insurance

  • 25 days holiday plus public holidays

  • Two charity days a year

  • Daily Meal Allowance

  • Access to outstanding learning materials and courses

  • Sports and hobby clubs, subsidised by Thought Machine

  • All the latest tech you need

  • Huge range of healthy (and not-so-healthy) snacks, smoothies and drinks

  • A talented and experienced team as your colleagues

  • An environment where we encourage learning and progress

We actively hire candidates who demonstrate technical excellence in their field and welcome people of all ages and backgrounds, providing everyone with equal access to professional development. You are encouraged to apply even if your experience doesn't accurately match the job description. We also encourage applications from those with different abilities, including candidates with ADHD, autism, dyslexia or dyspraxia.

Skills Required

  • Expertise with a programming language (e.g. Python, Go or Java)
  • Experience of security in a DevOps environment
  • Experience in web application penetration testing and security tooling (e.g. Burp proxy, Web/Network Scanners, Static code analysers)
  • Coding experience for automating/integrating security tools and creating security tools
  • Knowledge of security in distributed systems at scale
  • Cloud and containers technology knowledge (e.g. AWS, GCP, Kubernetes, Docker)
  • Experience of performing security design reviews, threat modelling and risk assessments
  • Knowledge of application security issues
  • Experience with OWASP Top 10 vulnerabilities
  • Professional security qualifications (e.g. CISSP, Offensive Security, SANS)
  • Contributions to the security community (public research, blogging, presentations)
  • Awareness and experience of the Data Protection Act, ISO 27001 and PCI-DSS
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: London
617 Employees
Year Founded: 2014

What We Do

Our team’s mission is a bold one – to create technology that can run the world’s banks according to the best designs and software practices of the modern age. In doing so, we will properly and permanently rid the world’s banks of the problems generated by poor technology running on legacy infrastructure. Our solution to this is Vault Core: a complete core banking platform that is capable of being configured easily to suit the needs of any bank. We have built Vault Core from the ground up as a cloud-native, microservices and API-based platform. Thought Machine has a deep culture of engineering excellence, and our approach has engendered a seismic shift in the banking industry. Thought Machine is looking for highly talented individuals to help grow the company and achieve our ambitious goal. We pride ourselves on having an excellent internal culture, where we strive hard to create the best possible working environment; a healthy mix of great technical work, fast pace, a supportive atmosphere, and of course our irreverent sense of fun

Similar Jobs

HiBob Logo HiBob

Customer Success Manager

HR Tech • Information Technology • Professional Services • Sales • Software
Remote or Hybrid
Portugal
1350 Employees

Cloudflare Logo Cloudflare

Business Development Representative

Cloud • Information Technology • Security • Software • Cybersecurity
Hybrid
Lisbon, PRT
4400 Employees
38K-53K Annually

Cloudflare Logo Cloudflare

Business Development Representative

Cloud • Information Technology • Security • Software • Cybersecurity
Hybrid
2 Locations
4400 Employees
38K-53K Annually

Deepgram Logo Deepgram

Account Executive

Artificial Intelligence • Machine Learning • Natural Language Processing • Software • Conversational AI
In-Office or Remote
28 Locations
150 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account