National AI Awards 2025Discover AI's trailblazers! Join us to celebrate innovation and nominate industry leaders.

Nominate & Attend

Senior Information Security Engineer

Flagstone Group LTD
London
1 week ago
Create job alert

Flagstone is many things. An online savings platform, reinventing how individuals, businesses, and charities manage, protect, and grow their cash. A diverse group of people, bound by a collaborative spirit, and shared purpose. And lastly, a thriving, profitable business – where smart people do their best work.

Each definition shares a common thread: our unique culture. It’s our pride and joy. And our competitive advantage.

A feel for our culture:

To revolutionise the savings market, we need to be at our best. But high performance takes more than talent – it takes a culture of kindness, respect, and growth.

That’s why we’re building a diverse, inclusive community, where your voice is heard and valued. Where, with close support and room to develop, you can surpass even your own expectations. And be rewarded for it.

We may not change the world, but wecanchange the world of financial technology. And all it takes is a winning mix of drive, talent, and empathy. Our culture celebrates all three.

But enough about us. Let’s talk about you.

Does this sound like you?

You're a forward-thinking Security Engineer with a passion for building secure, scalable systems who’s excited to forge a new way to save! You enjoy shaping the security posture of modern digital environments and bring deep hands-on expertise in cloud and Saas security within the Microsoft ecosystem. You enjoy working collaboratively across teams, influencing secure-by-design thinking, and embedding security into everyday ways of working.

What you’ll do:

  • Lead the design, implementation, and ongoing improvement of our security controls and practices, aligned to ISO/IEC 27001:2022 and ISO/IEC 42001.
  • Proactively identify and mitigate risks across SaaS, cloud, and on-prem environments.
  • Act as a key subject matter expert for security engineering and governance across Microsoft Azure, Microsoft 365, and other third-party platforms.
  • Partner with compliance, legal, IT, and operational teams to embed secure-by-design principles throughout product and service delivery.
  • Strengthen detection and response capabilities through Microsoft Sentinel and related threat intelligence tools.
  • Support audit readiness, compliance automation, and third-party risk management through tools like Vanta, Risk Ledger, and Microsoft Compliance Manager.
  • Contribute to a strong security culture by driving awareness initiatives and influencing behaviour at scale.

What you’ll bring:

  • Deep experience with Microsoft Azure security tooling, including Azure Security Center, Azure Policy, and Microsoft Secure Score.
  • Expertise in identity and cloud-native security using Microsoft Defender for Cloud, Defender XDR, and Entra ID Protection.
  • Hands-on knowledge of security controls in Microsoft 365, AAD, and Purview for data protection and insider risk management.
  • Strong background in threat detection and response using SIEM/SOAR platforms (Microsoft Sentinel desirable), and familiarity with frameworks like MITRE ATT&CK.
  • Solid grasp of ISO/IEC 27001:2022 controls, with exposure to AI security frameworks (e.g., ISO/IEC 42001) a plus.
  • Experience supporting or leading audits and compliance workflows using platforms like Vanta, Ivanti, or Microsoft Compliance Manager.
  • Knowledge of secure endpoint and network management for hybrid/remote environments.
  • Understanding of physical security principles aligned to ISO Annex A.7 and A.11.
  • Ability to influence culture and behaviour, with experience in using tools like CultureAI or equivalent to embed awareness at scale.
  • Proven expertise in applying threat modelling frameworks (e.g. STRIDE, PASTA), and tools (e.g. OpenCTI), identifying attack surfaces and trust boundaries, and integrating threat modelling into secure system design and development processes.
  • Familiarity with Microsoft Purview’s DLP, eDiscovery, and Data Lifecycle Management features.
  • Experience conducting internal audits or ISO/NIST gap assessments.
  • Understanding of privacy regulations such as UK GDPR, DPA 2018, or international equivalents.

How we reward you:

At Flagstone, the benefits extend beyond false gifts like “fruit and snacks”. Instead, we invest in your health, wealth, and professional development. Here’s a selection of our benefits:

  • Competitive bonus scheme - designed to reward and recognise high performance
  • Flexible benefits budget - a pot to fund meaningful benefits for you, whether it's hormone or fertility testing, cancer screening, neuro-diversity coaching or something that matters for you.
  • A range of salary sacrifice options to help you make tax efficient savings on electric cars, nursery schemes, home and tech goods.
  • Around the World scheme - 3 months work from anywhere scheme
  • Mental wellbeing support – Access therapy and mental health sessions through Spill
  • Learning and development – £1,000 personal development budget to help you grow in your role.
  • Private health care - Enjoy all the benefits AXA has to offer, including reduced gym memberships and medical history disregarded
  • Medical cash plan - To help you with the costs of dental and optical expenses
  • Life insurance and Income Protection- four times your annual salary for peace of mind
  • Matched pension contributions up to 5%
  • 25 days holiday - plus bank holidays, well-being days and volunteering days
  • Enhanced Parental Leave – enhanced maternity, paternity and adoption pay

All are welcome.

At Flagstone, we’re assembling a diverse team that defies our industry’s norms. Think this role could suit you? We encourage you to apply, no matter your background.

#LI-Hybrid

Apply for this job

*

indicates a required field

First Name *

Last Name *

Email *

Phone

Resume/CV

Enter manually

Accepted file types: pdf, doc, docx, txt, rtf

Enter manually

Accepted file types: pdf, doc, docx, txt, rtf

LinkedIn Profile

Website

What is your current availability/notice period? *

What are your salary expectations? *

Please confirm if you currently have the legal right to work in the UK? If you are on a visa, please specify your visa type, any restrictions, and whether you will require sponsorship now or in the future. *

I identify my gender as *

Female

Male

Non-Binary

Other

Prefer not to disclose

We're passionate about promoting diversity in the workplace. Which of these best describes your ethnic group? * Select...

Protecting your data is really important to us. Do you consent to us storing your ethnicity and gender data? *


#J-18808-Ljbffr

Related Jobs

View all jobs

Senior Information Security Engineer

Senior Information Security Engineer

Senior Information Security Engineer

Senior Information Security Engineer London

Senior Information Security Engineer

Senior Information Systems Security Engineer (ISSE)

National AI Awards 2025

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Cyber Security Jobs Skills Radar 2026: Emerging Frameworks, Tools & Certifications to Learn Now

Cyber threats are evolving—and so must the people defending against them. As ransomware, AI-enhanced phishing, and supply chain attacks grow more advanced, UK employers are urgently hiring cyber security professionals with the right mix of strategic and hands-on skills. Welcome to the Cyber Security Jobs Skills Radar 2026, your go-to guide for the most in-demand tools, frameworks, certifications, and technologies shaping the UK's cyber workforce. Whether you're a SOC analyst, penetration tester, or cloud security architect, this annual radar is designed to help you stay ahead of the market.

How to Find Hidden Cyber Security Jobs in the UK Using Professional Bodies like BCS, CIISec & More

The demand for skilled cyber security professionals in the UK has never been higher. With threats increasing in sophistication and frequency, organisations are urgently hiring ethical hackers, threat analysts, GRC specialists, and security architects. But many of the most valuable roles—particularly in government, defence, and critical infrastructure—are never publicly advertised. Instead, these jobs are shared behind the scenes through trusted networks, private communities, and professional bodies. In this article, we explore how to uncover hidden cyber security jobs in the UK using organisations like the BCS (The Chartered Institute for IT), CIISec (The Chartered Institute of Information Security), ISACA, and ISC² UK Chapter. We’ll show you how to use membership directories, special interest groups, CPD events and informal networks to gain early access to roles most people never see.

How to Get a Better Cyber Security Job After a Lay-Off or Redundancy

Redundancy is never easy—especially in a fast-moving field like cyber security, where your skills and experience are constantly evolving. But if you’ve recently been made redundant from a cyber security role, know this: the UK cyber workforce remains in high demand, and your expertise is more valuable than ever. Whether you’re a SOC analyst, penetration tester, incident responder, security architect or GRC specialist, there are still thousands of opportunities across sectors including finance, defence, government, retail, and critical infrastructure. This guide will help you turn redundancy into a career relaunch, with a clear action plan tailored to the UK cyber security job market.