Senior Application Security Engineer

Posted One Month Ago
Be an Early Applicant
Office, Lilongwe, Central Region, MWI
Hybrid
Senior level
Financial Services
The Role
Own and improve Azure-focused security tooling (Sentinel, Defender XDR/Cloud), harden cloud infrastructure, author detection rules, investigate incidents, run pen test programmes, contribute IaC (Terraform/Bicep), perform threat modelling, and coordinate remediation across engineering teams.
Summary Generated by Built In

What is Flagstone?

Flagstone is many things. An online savings platform, reinventing how individuals, businesses, and charities manage, protect, and grow their cash. A diverse group of people, bound by a collaborative spirit, and shared purpose. And lastly, a thriving, profitable business – where smart people do their best work.

Each definition shares a common thread: our unique culture. It’s our pride and joy. And our competitive advantage.


A feel for our culture:

To revolutionise the savings market, we need to be at our best. But high performance takes more than talent – it takes a culture of kindness, respect, and growth.

That’s why we’re building a diverse, inclusive community, where your voice is heard and valued. Where, with close support and room to develop, you can surpass even your own expectations. And be rewarded for it.

We may not change the world, but we can change the world of financial technology. And all it takes is a winning mix of drive, talent, and empathy. Our culture celebrates all three.
But enough about us. Let’s talk about you.


About the Team

This is a new AppSec-focused addition to Security Engineering, working closely with product engineering teams across the SDLC. The role sits alongside, not inside, GRC/Compliance — customer security questionnaires and RFP responses are owned by GRC, with this role providing technical input as needed rather than end-to-end ownership.


Does this sound like you:

We're currently hiring a Senior Application Security Engineer to own AppSec end-to-end across our development lifecycle: from design-stage threat modelling through to code review, tooling, and remediation of findings. This is a hands-on engineering role, not a compliance or customer-facing one — you'll work directly with product engineering teams to build security in rather than bolt it on afterwards.

What you’ll do:

  • Own the AppSec programme for Flagstone and report back on its success to relevant stakeholders including leadership

  • Formalise a secure development lifecycle which includes owning threat modelling and secure design review for new features and systems, working directly with engineering teams during design rather than after the fact, introducing security gates and guardrails and ensuring applications are secure even post deployment

  • Run and continuously improve secure code review practices, including SAST/DAST/SCA tooling integrated into CI/CD pipelines and code review (manual and/or AI assisted)

  • Coordinate external and execute internal penetration test engagements — scope, logistics, findings triage — and drive remediation to closure with engineering teams

  • Maintain and evolve secure coding standards, and run a security champions programme to scale AppSec practice across engineering

  • Track and report on vulnerability management across the application estate, prioritising by exploitability and business impact

  • Contribute AppSec expertise to incident response where application-layer issues are involved

  • Run and own a security champions programme

  • Manage application cyber risk according to the internal Flagstone Risk Framework

What we’re looking for 

  • 5+ years in application security or a security engineering role with a strong AppSec component

  • Practical experience embedding security in the SDLC: threat modelling frameworks (e.g. STRIDE), secure design review, and working directly with engineering teams

  • Hands-on experience with SAST/DAST/SCA tooling and CI/CD pipeline integration

  • Strong grasp of OWASP Top 10 and secure coding practices across at least one major language/framework used in a production environment

  • Experience coordinating and running penetration testing programmes, including remediation tracking

  • Comfortable communicating security risk clearly to engineering and product audiences and influencing senior leadership

  • Demonstrable experience with adversarial security testing

  • Demonstrated experience in reviewing, threat modelling and securing agentic and AI systems

  • Great communication skills and stakeholder management, which includes influencing stakeholders and creating relationships

  • Strong critical thinking skills and a curiosity for learning new technologies and frameworks

  • Great at troubleshooting and thinking out of the box

Nice to Have

  • A strong link to the AppSec community and industry which includes conferences, OWASP or other Open-Source contributions, public speaking and engagement in thought leadership

  • OSCP, CSSLP, or equivalent hands-on offensive/AppSec certification

  • Experience in a regulated financial services environment

  • Prior experience running or scaling a security champions programme

  • Exposure to cloud-native application security (containers, serverless, API security)


How we reward you:

At Flagstone, the benefits extend beyond false gifts like “fruit and snacks”. Instead, we invest in your health, wealth, and professional development. Here’s a selection of our benefits:

  • Competitive bonus scheme - designed to reward and recognise high performance

  • Flexible benefits budget - a pot to fund meaningful benefits for you, whether it's hormone or fertility testing, cancer screening, neuro-diversity coaching or something that matters for you.

  • A range of salary sacrifice options to help you make tax efficient savings on electric cars, nursery schemes, home and tech goods.

  • Around the World scheme - 3 months work from anywhere scheme (some exclusions do apply)

  • Mental wellbeing support – Access therapy and mental health sessions through Spill

  • Learning and development – £1,000 personal development budget to help you grow in your role.

  • Private health care - Enjoy all the benefits AXA has to offer, including reduced gym memberships and medical history disregarded

  • Medical cash plan - To help you with the costs of dental and optical expenses

  • Life insurance and Income Protection- four times your annual salary for peace of mind

  • Matched pension contributions up to 5%

  • 25 days holiday - plus bank holidays, well-being days and volunteering days

  • Enhanced Parental Leave – enhanced maternity, paternity and adoption pay.  

All are welcome.

At Flagstone, we’re assembling a diverse team that defies our industry’s norms. Think this role could suit you? We encourage you to apply, no matter your background.

#LI-hybrid

Skills Required

  • Hands-on SIEM experience, ideally Microsoft Sentinel (or Splunk, Chronicle, QRadar)
  • Practical Azure security experience across Defender for Cloud, Entra ID, Azure networking, and cloud security posture management
  • Experience writing infrastructure-as-code for security tooling using Terraform or Bicep
  • Ability to write and tune detection rules, manage data connectors, and reduce alert noise
  • Incident investigation and response experience (triage, containment, evidence gathering, post-incident review)
  • Experience supporting or coordinating penetration testing programmes and remediation cycles
  • Ability to contribute to threat modelling and communicate security risk to engineering and product stakeholders
  • Familiarity with AI security considerations and/or using AI tooling to augment security engineering workflows
  • KQL proficiency for detection rule authoring and threat hunting
  • SC-200 (Microsoft Security Operations Analyst) certification
  • Experience working in fintech or financial services environments
  • Growth mindset and genuine curiosity to keep learning
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: London
245 Employees
Year Founded: 2013

What We Do

Flagstone – the cash deposit platform – gives savers everything they need to manage, protect, and nurture their cash. With a single application, savers can spread their deposits across hundreds of accounts, maximise their interest, and keep their cash secure. Our platform is available to UK individuals, businesses, and charities at www.flagstoneim.com. We are available to international individuals, corporates, funds, and trusts at www.flagstoneim.com/international.

Similar Jobs

Ericsson Logo Ericsson

Techno Commercial Manager RAN CU ENA

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office or Remote
19 Locations
88000 Employees

Invenergy Logo Invenergy

Senior PI Administrator

Greentech • Real Estate • Social Impact • Energy • Industrial • Solar • Renewable Energy
In-Office or Remote
18 Locations
2500 Employees
125K-155K Annually
In-Office
Lilongwe, Central Region, MWI
94 Employees
In-Office
2 Locations
377 Employees
44K-54K Annually

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account