Be at the heart of actionFly remote-controlled drones into enemy territory to gather vital information.

Apply Now

Platform Security Engineer

Bondsmith
London
5 months ago
Applications closed

Related Jobs

View all jobs

Senior Security Architecture & Engineering Manager

Senior Security Engineer - CIAM XDP

Security Engineer (Vlocity/Salesfore Industries)

Head of IT Security and Platform Engineering (Hybrid) Newcastle - To £115k+ Bens

SOAR Engineer - Security Orchestration, Automation & Response

It Support Engineer

About us

Bondsmith is a fast growing platform focused on helping customers make the most of their savings by offering access to a wide range of deposit products.

We work with financial institutions like wealth managers, fintechs, banks, and advisors, providing them with tools to get better returns on cash, engage more effectively with clients, and simplify their operations. Our goal is to help savers get the most out of their cash.

At Bondsmith, our core values are rapid and continuous improvement, delivering good customer outcomes, and taking end to end ownership. Our team is made up of experienced professionals who are passionate about delivering excellent service and finding new ways to solve challenges in financial services. Joining us means working in a fast-paced environment where you will be making an impact on the financial lives of thousands of savers.

Were regulated by the Financial Conduct Authority in the UK.

We are looking for a skilled and proactive DevSecOps Engineer to take ownership of our security frameworks, testing, and hands-on implementation of secure systems. You will join our Engineering team to play a pivotal role in integrating security practices into the development lifecycle, ensuring that our software development processes are secure by design.

You will work closely with Development and Platform teams to embed robust security practices across the software development lifecycle (SDLC). This is a hands-on role that requires expertise in security testing, framework design, and automation, as well as a commitment to building a secure, scalable infrastructure.

This is a hybrid role - you will be required to work from the London office at least 3 days a week.

Key Responsibilities:

  • Design, build and maintain secure CI/CD pipelines by embedding security tools and practices into the development workflow.
  • Integrate and manage security tools for code analysis, vulnerability scanning, container security, and dependency management.
  • Manage and implement security controls in cloud infrastructure (AWS/Azure), leveraging IaC tools like Terraform with a security first approach.
  • Perform regular automated security assessments, including vulnerability scans, assist penetration testing, and remediation planning.
  • Automate security testing processes, including SAST, DAST, and IAST tools, to identify and remediate vulnerabilities earlier in the SDLC.
  • Work closely with Development and Platform teams to promote a DevSecOps culture and ensure security best practices are followed.
  • Establish and maintain monitoring systems for detecting threats and anomalies. Provide actionable insights to mitigate risks.
  • Build security monitoring and alerting capabilities using SIEM tools or cloud-native monitoring solutions like Elastic Cloud.
  • Ensure adherence to compliance frameworks and standards (e.g., GDPR, ISO 27001).
  • Participate in incident response efforts, including root cause analysis and post mortem reviews.

Requirements:

  • Strong hands-on experience with CI/CD tools (e.g., Jenkins, GitLab CI, GitHub Actions, CircleCI).
  • Hands-on experience with IaC tools like Terraform, CloudFormation.
  • Expertise in securing cloud platforms (AWS, Azure) and containerisation technologies (Docker, Kubernetes) with a focus on security.
  • Knowledge in scripting and automation using Bash, Python, or similar programming languages.
  • Understanding of secure coding practices, application security principles, and compliance frameworks.
  • Expertise in implementing security tools (e.g., SAST, DAST, vulnerability scanners, OWASP ZAP, SonarQube, Snyk, Elastic Security, tfsec AWS Inspector or Trivy).
  • Experience with monitoring and logging tools like ELK or cloud-native solutions like Elastic Cloud, Datadog.
  • Hands-on experience with SIEM systems and threat detection.
  • Strong problem-solving skills and attention to detail.
  • Excellent communication and collaboration skills.
  • Ability to work in a fast-paced, agile environment.
  • Proficient in English.

Education and Certifications:

  • 3+ years of experience in DevSecOps or Security Engineering roles.
  • Bachelors degree in Computer Science, Information Security, or a related field (or equivalent experience).
  • Proven experience in Security, with a strong understanding of Security and processes.
  • Preferred certifications: AWS/Azure/GCP Security certifications, Certified Kubernetes Security Specialist (CKS), Certified Information Systems Security Professional (CISSP).
  • (Desirable) Exposure to machine learning or AI-driven security solutions.
  • (Desirable) Experience working in fintech.

About You:

Were looking for someone who is:

  • Confident & Motivated:You take initiative and are eager to tackle new challenges.
  • Independent:Youre comfortable working on tasks autonomously but enjoy collaborating with a team.
  • Quick to Learn:Youre excited to dive into new technologies and constantly improve your skills.
  • Team-Oriented:You value working with a high-performance team and contributing to a positive culture.
  • Dedicated & Resourceful:You bring a strong work ethic and a solutions-oriented mindset.
  • Customer-Focused:Youre driven by the chance to create solutions that make a difference for our customers.

What makes Bondsmith unique:

  • Early-stage startup:You will join an early-stage startup with less than 50 members. This means youll have an opportunity to make a real impact and shape the future of Bondsmith.
  • Customer demand:Unlike other startups who are still finding their way and pivoting on products, we have strong demand from our enterprise clients for our products, we just need to keep building them.
  • Next fintech growth story:We are doubling in headcount year on year and hiring across a range of positions.

Company Benefits:

  • Competitive salary.
  • Healthcare.
  • Pension scheme.
  • Share scheme participation.
  • All the right equipment to make sure youre working at your best.
  • Fun and social office in Shoreditch.
  • Deliveroo for working late in the office.

J-18808-Ljbffr

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Why the UK Could Be the World’s Next Cyber Security Jobs Hub

Cyber security has become one of the defining challenges of the digital age. From protecting personal data and financial transactions to defending national infrastructure and corporate systems, the demand for strong cyber defences has never been higher. As businesses, governments, and individuals depend more heavily on digital services, the scale and sophistication of cyber threats have risen dramatically. Ransomware attacks, data breaches, state-sponsored cyber operations, and insider threats are now everyday risks. In response, organisations worldwide are investing heavily in cyber security talent. The United Kingdom is uniquely positioned to become a global cyber security jobs hub. With its strong tech sector, world-class universities, advanced defence capabilities, and established financial markets, the UK already has the foundations. The question is whether it can scale up, attract, and retain the right talent to meet global demand. This article explores why the UK is poised to become the world’s next cyber security jobs hub, the opportunities available, the challenges ahead, and what needs to happen for this vision to be realised.

The Best Free Tools & Platforms to Practise Cyber Security Skills 2025/26

Cyber security is one of the most in-demand career fields in the UK. From preventing data breaches to monitoring networks and defending against ransomware, the role of cyber professionals is critical across every industry. With organisations of all sizes facing increasing threats, demand for skilled professionals continues to rise. But employers don’t just want theory—they want proof that you can analyse systems, detect vulnerabilities, and respond to incidents. The good news is that you don’t need to pay thousands of pounds for training to build practical experience. A wide range of free tools and platforms allow you to practise cyber security skills safely, ethically, and at no cost. This article explores the best free resources available in 2025 to help you gain hands-on skills in ethical hacking, penetration testing, digital forensics, network monitoring, and incident response.

Top 10 Skills in Cyber sScurity According to LinkedIn & Indeed Job Postings

In today’s digital age, cyber security is no longer optional—it’s mission-critical. From financial institutions to healthcare providers, government departments to tech startups, every sector in the UK is under rising cyber threats. As a result, employers are constantly on the hunt for skilled professionals who can defend, detect, and respond effectively. But with cyber threats evolving at pace, what exactly are employers seeking? By analysing job postings on LinkedIn and Indeed, this article reveals the Top 10 cyber security skills UK organisations are demanding in 2025. Read on to discover how to present these skills effectively on your CV, in interviews, and through practical proof of experience.