Platform Security Engineer

Bondsmith
London
4 weeks ago
Applications closed

Related Jobs

View all jobs

Platform Security Engineer London

Senior Security Engineer

SIEM Security Engineer- SC cleared

Senior Cloud Security Engineer

Senior Cloud Security Engineer

Senior Cyber Security Engineer

About us

Bondsmith is a fast growing platform focused on helping customers make the most of their savings by offering access to a wide range of deposit products.

We work with financial institutions like wealth managers, fintechs, banks, and advisors, providing them with tools to get better returns on cash, engage more effectively with clients, and simplify their operations. Our goal is to help savers get the most out of their cash.

At Bondsmith, our core values are rapid and continuous improvement, delivering good customer outcomes, and taking end to end ownership. Our team is made up of experienced professionals who are passionate about delivering excellent service and finding new ways to solve challenges in financial services. Joining us means working in a fast-paced environment where you will be making an impact on the financial lives of thousands of savers.

Were regulated by the Financial Conduct Authority in the UK.

We are looking for a skilled and proactive DevSecOps Engineer to take ownership of our security frameworks, testing, and hands-on implementation of secure systems. You will join our Engineering team to play a pivotal role in integrating security practices into the development lifecycle, ensuring that our software development processes are secure by design.

You will work closely with Development and Platform teams to embed robust security practices across the software development lifecycle (SDLC). This is a hands-on role that requires expertise in security testing, framework design, and automation, as well as a commitment to building a secure, scalable infrastructure.

This is a hybrid role - you will be required to work from the London office at least 3 days a week.

Key Responsibilities:

  • Design, build and maintain secure CI/CD pipelines by embedding security tools and practices into the development workflow.
  • Integrate and manage security tools for code analysis, vulnerability scanning, container security, and dependency management.
  • Manage and implement security controls in cloud infrastructure (AWS/Azure), leveraging IaC tools like Terraform with a security first approach.
  • Perform regular automated security assessments, including vulnerability scans, assist penetration testing, and remediation planning.
  • Automate security testing processes, including SAST, DAST, and IAST tools, to identify and remediate vulnerabilities earlier in the SDLC.
  • Work closely with Development and Platform teams to promote a DevSecOps culture and ensure security best practices are followed.
  • Establish and maintain monitoring systems for detecting threats and anomalies. Provide actionable insights to mitigate risks.
  • Build security monitoring and alerting capabilities using SIEM tools or cloud-native monitoring solutions like Elastic Cloud.
  • Ensure adherence to compliance frameworks and standards (e.g., GDPR, ISO 27001).
  • Participate in incident response efforts, including root cause analysis and post mortem reviews.

Requirements:

  • Strong hands-on experience with CI/CD tools (e.g., Jenkins, GitLab CI, GitHub Actions, CircleCI).
  • Hands-on experience with IaC tools like Terraform, CloudFormation.
  • Expertise in securing cloud platforms (AWS, Azure) and containerisation technologies (Docker, Kubernetes) with a focus on security.
  • Knowledge in scripting and automation using Bash, Python, or similar programming languages.
  • Understanding of secure coding practices, application security principles, and compliance frameworks.
  • Expertise in implementing security tools (e.g., SAST, DAST, vulnerability scanners, OWASP ZAP, SonarQube, Snyk, Elastic Security, tfsec AWS Inspector or Trivy).
  • Experience with monitoring and logging tools like ELK or cloud-native solutions like Elastic Cloud, Datadog.
  • Hands-on experience with SIEM systems and threat detection.
  • Strong problem-solving skills and attention to detail.
  • Excellent communication and collaboration skills.
  • Ability to work in a fast-paced, agile environment.
  • Proficient in English.

Education and Certifications:

  • 3+ years of experience in DevSecOps or Security Engineering roles.
  • Bachelors degree in Computer Science, Information Security, or a related field (or equivalent experience).
  • Proven experience in Security, with a strong understanding of Security and processes.
  • Preferred certifications: AWS/Azure/GCP Security certifications, Certified Kubernetes Security Specialist (CKS), Certified Information Systems Security Professional (CISSP).
  • (Desirable) Exposure to machine learning or AI-driven security solutions.
  • (Desirable) Experience working in fintech.

About You:

Were looking for someone who is:

  • Confident & Motivated:You take initiative and are eager to tackle new challenges.
  • Independent:Youre comfortable working on tasks autonomously but enjoy collaborating with a team.
  • Quick to Learn:Youre excited to dive into new technologies and constantly improve your skills.
  • Team-Oriented:You value working with a high-performance team and contributing to a positive culture.
  • Dedicated & Resourceful:You bring a strong work ethic and a solutions-oriented mindset.
  • Customer-Focused:Youre driven by the chance to create solutions that make a difference for our customers.

What makes Bondsmith unique:

  • Early-stage startup:You will join an early-stage startup with less than 50 members. This means youll have an opportunity to make a real impact and shape the future of Bondsmith.
  • Customer demand:Unlike other startups who are still finding their way and pivoting on products, we have strong demand from our enterprise clients for our products, we just need to keep building them.
  • Next fintech growth story:We are doubling in headcount year on year and hiring across a range of positions.

Company Benefits:

  • Competitive salary.
  • Healthcare.
  • Pension scheme.
  • Share scheme participation.
  • All the right equipment to make sure youre working at your best.
  • Fun and social office in Shoreditch.
  • Deliveroo for working late in the office.

J-18808-Ljbffr

Get the latest insights and jobs direct. Sign up for our newsletter.

By subscribing you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Portfolio Projects That Get You Hired for Cyber Security Jobs (With Real GitHub Examples)

With rising cyber threats and increasingly sophisticated attacks, cyber security has become a critical priority for organisations worldwide. From penetration testers (pentesters) and SOC analysts to cloud security engineers and threat intelligence specialists, the demand for skilled cyber security professionals continues to surge. But how do you stand out in a growing field? Alongside your CV, an impressive cyber security portfolio can be the distinguishing factor that convinces employers you’re the right fit. In this comprehensive guide, you’ll discover: Why a cyber security portfolio is essential for job seekers in this domain. How to align portfolio projects with different cyber security career paths. Real GitHub examples that demonstrate best practices in security-focused projects. Actionable project ideas you can start today, from penetration testing labs to blue-team detection pipelines. Best practices for organising your repos and presenting your work so hiring managers can instantly see your impact. When you’re ready to pursue your next opportunity, remember to upload your CV on CyberSecurityJobs.tech. Our specialised platform connects talented security professionals with employers who need your expertise—exactly what your portfolio will showcase.

Cyber Security Job Interview Warm‑Up: 30 Real Coding & System‑Design Questions

The need for skilled cyber security professionals has never been greater. As organisations rapidly digitise their operations and store increasing amounts of sensitive data online, cyber threats loom large—ranging from sophisticated ransomware attacks to insider threats and state‑sponsored espionage. Against this backdrop, cyber security jobs remain some of the most in‑demand and mission‑critical roles on the market. If you’re preparing for a cyber security interview, expect to be tested on a broad spectrum of topics—from secure coding and incident response to network security architecture and compliance standards. In many cases, companies also include problem‑solving exercises and system design scenarios to gauge how well you can apply theoretical knowledge to real‑world threats. To help you ace these assessments, we’ve compiled 30 real coding & system‑design questions you might encounter. Each reflects a key area of cyber security—whether it’s encryption and key management, threat modelling, or designing a zero‑trust network. Along the way, we’ll offer insights and best practices so you can stand out from the crowd. If you’re on the lookout for exciting cyber security roles in the UK, head to www.cybersecurityjobs.tech. There, you’ll discover a range of positions—covering everything from penetration testing and threat intelligence to compliance management and security operations. Let’s dive into the essentials of interview readiness.

Negotiating Your Cybersecurity Job Offer: Equity, Bonuses & Perks Explained

How to Secure Compensation That Reflects Your Value in the UK’s High-Stakes Cybersecurity Sector Introduction As cyber threats grow more sophisticated and frequent, cybersecurity professionals have never been more in demand. From thwarting ransomware attacks to architecting secure cloud infrastructures, mid‑senior cybersecurity experts play a critical role in safeguarding a company’s data and reputation. Thanks to this growing reliance on cybersecurity, employers in the UK are going above and beyond simple salary offers to attract the top echelon of talent. Although base salary remains a key component of any job offer, the broader package—encompassing equity, bonuses, and perks—can often surpass what you’d gain from a small bump in monthly pay. For cybersecurity specialists working in areas such as threat intelligence, incident response, penetration testing, or compliance, the complexity and risk mitigation you bring to the table is massive. Knowing how to negotiate the entire package ensures you are duly rewarded for keeping an organisation’s data, assets, and operations safe. In this guide, we’ll delve into every aspect of negotiating a cybersecurity job offer. Whether you’re pivoting to a mid‑senior role or cementing your expertise at an established security consultancy, understanding the full range of compensation elements will help you secure an offer that acknowledges the criticality of what you do. Let’s explore equity options, performance bonuses, and the perks that matter most, so you can come out of your next job negotiation confident that you’re getting more than just a salary.