Shape the Future of AIJoin one of the UK's fastest-growing companies and become a Professional Development Expert in Artificial Intelligence.

View Roles

Senior Security Engineer (Product Security)

eFinancialCareers
Greater London
6 days ago
Create job alert

Responsibilities



Secure Development Lifecycle (SDLC) Implementation
Design and implement secure software development practices Integrate security gates into CI/CD pipelines following DevSecOps principles Establish security quality gates and acceptance criteria Develop secure coding standards based on OWASP guidelines Create security architecture patterns and reference implementations
Security Code Reviews & Testing
Conduct in-depth security code reviews for critical features Implement automated security testing (SAST, DAST, IAST, SCA) Configure and tune security scanning tools (Aquasec, Trivy, Dependabot, etc) Review cryptographic implementations against industry standards Validate authentication and authorization implementations Ensurepliance with OWASP ASVS (Application Security Verification Standard)
Threat Modeling & Risk Assessment
Lead threat modeling sessions using STRIDE, PASTA, or similar frameworks Create threat models for new products and architectural changes Identify attack vectors specific to web and mobile platforms Develop abuse cases and security test scenarios Maintain threat intelligence for fintech-specific risks Document security requirements derived from threat models
Platform-Specific Security
Web Applications:Implement defenses against OWASP Top 10 vulnerabilitiesMobile Applications:Apply OWASP MASVS and platform-specific guidelines (iOS App Transport Security, Android Network Security Config)APIs:Implement API security best practices (rate limiting, authentication, input validation) Cross-platform session management and secure data storage
Security Tooling & Automation
Build and maintain security testing pipelines Integrate security tools with GitHub Actions Develop custom security linters and premit hooks Create automated vulnerability tracking and remediation workflows Implement secret scanning and dependency checking Build security dashboards and metrics reporting
Developer Enablement & Training
Create secure coding guidelines for different technology stacks Develop a security champions program aligned with OWASP SAMM Conduct security training on platform-specific vulnerabilities Provide hands-on guidance during security incidents Build internal security libraries and frameworks Create threat modeling templates and playbooks
Required Qualifications

Technical Expertise
5+ years of application security experience Strong programming skills in multiple languages (Python, JavaScript/TypeScript, Golang) Deep understanding of security vulnerabilities across web and mobile platforms Hands-on experience with security testing tools and methodologies Expertise in secure coding practices and design patterns Experience with modern development frameworks (React, Angular, ReactNative, Flutter)
Security Domain Knowledge
Expert knowledge of OWASP standards (Top 10, ASVS, SAMM, MASVS) Understanding of cryptographic principles and secure implementations Experience with threat modeling methodologies Knowledge of authentication standards (OAuth2, OIDC, WebAuthn) Familiarity with PCI-DSS, PSD2, and Strong Customer Authentication requirements Understanding of cloud-native security patterns
Code Review & Analysis Skills
Ability to identify security vulnerabilities through manual code review Experience with static and dynamic analysis tools Understanding ofmon vulnerability patterns across languages Knowledge of secure architecture patterns and anti-patterns Ability to provide actionable remediation guidance
Professional Requirements
Experience in financial services or high-security environments Strongmunication skills to explain security risks to developers Ability to balance security requirements with development velocity Collaborative approach to working with engineering teams Technical writing skills for documentation and guidelines
Preferred Qualifications
Experience with payment systems and transaction security Knowledge of mobile app protection Experience building security champions programs Background in penetration testing or security research
Key Projects & Initiatives

You'll lead critical security initiatives, including:
Building threat modeling practice for all products Establishing automated security testing in CI/CD pipelines Creating platform-specific security standards and libraries Developing a security training curriculum for 200+ developers
What We Offer
Direct impact on the security of products used by thousands of businesses Work with cutting-edge fintech products across multiple platforms Collaborate with talented engineers across 25+ countries Modern security tooling and testing infrastructure Investment in professional development and certifications Clear progression path to Staff/Principal roles
#LI-AT1
#HYBRID

About Us

Ebury is a FinTech success story, positioned among the fastest-growing internationalpanies in its sector.

Founded in 2009, we are headquartered in London and have more than 1700 staff with a presence in more than 29 markets worldwide. Cultural diversity is part of what makes Ebury a special place to be. From Sao Paulo to Dubai, Vancouver to Auckland, we enjoy sharing team experiences and celebrating success across the Ebury family.

Hard work pays off: in 2019, Ebury received a £350 million investment from Banco Santander and has won internationally recognised awards including Financial Times: 1000 Europe's Fastest-Growingpanies.

None of this would have been possible without our proudest achievement: our great people. Enthusiastic, innovative and collaborative teams, always ready to disrupt and revolutionise the fast-paced FinTech sector.

At Ebury, we'remitted to building a workplace where everyone feels valued, supported, and empowered to thrive. We're proud to have active employee networks and ESG initiatives that reflect our inclusive culture, including ourWomen's Network,LGBTQIA+ Network, andVeterans Network. Thesemunities provide spaces for connection, mentorship, advocacy, and collaboration across our global teams.

We believe in inclusion. We stand against discrimination in all forms and have no tolerance for the intolerance of differences that makes us a modern and successful organisation. At Ebury, you can be whoever you want to be and still feel a sense of belonging no matter your story because we want you and your uniqueness to help write our future.

Please submit your application on the careers website directly, uploading your CV / resume in English. Job ID 4643965101

Related Jobs

View all jobs

Senior Security Engineer

Senior Security Engineer

Senior Security Engineer

Senior Security Engineer – London - £55,000

Senior Security Engineer

Senior Security Engineer

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Automate Your Cyber Security Jobs Search: Using ChatGPT, RSS & Alerts to Save Hours Each Week

Cyber roles drop across consultancies, MSSPs, hyperscalers, banks, gov & start-ups every day—often buried in ATS portals or duplicated across boards. The fix is simple: put discovery on autopilot with keyword-rich alerts, RSS feeds & a reusable ChatGPT workflow that triages listings, ranks fit, & tailors your CV in minutes. This copy-paste playbook is built for www.cybersecurityjobs.tech readers. It’s UK-centric, practical, & designed to save you hours each week. What You’ll Have Working In 30 Minutes A role & keyword map spanning SecOps/Detection, DFIR, AppSec, Cloud Security, GRC, Red Team, Threat Intel, IAM/PAM, OT/ICS & Vulnerability Management. Shareable Boolean search strings for Google & job boards to cut noise fast. Always-on alerts & RSS feeds delivering fresh roles to your inbox/reader. A ChatGPT “Cyber Job Scout” prompt that deduplicates, scores fit & outputs tailored actions. A simple pipeline tracker so deadlines & follow-ups never slip.

10 Cyber Security Recruitment Agencies in the UK You Should Know (2025 Job‑Seeker Guide)

UK cyber security hiring remains resilient in 2025, driven by nation-state threats, cloud security investments, and NCSC regulatory pressures. Lightcast reports +42 % YoY growth in UK roles mentioning “SOC”, “cyber risk”, “offensive security” or “GRC”. Yet despite 30,000 active cyber professionals, monthly live vacancies remain in the 2,500–2,900 range. The result: strong demand across public and private sector. We reviewed 50 + consultancies and included only those that: Are registered in the UK (Companies House) Operate a dedicated Cyber Security / InfoSec / Risk & Compliance desk Posted at least 5 UK cyber security roles between March and June 2025 This guide includes 2025 salary ranges, key skills, interview prep tips, and a verified recruiter directory.

Cyber Security Jobs Skills Radar 2026: Emerging Frameworks, Tools & Certifications to Learn Now

Cyber threats are evolving—and so must the people defending against them. As ransomware, AI-enhanced phishing, and supply chain attacks grow more advanced, UK employers are urgently hiring cyber security professionals with the right mix of strategic and hands-on skills. Welcome to the Cyber Security Jobs Skills Radar 2026, your go-to guide for the most in-demand tools, frameworks, certifications, and technologies shaping the UK's cyber workforce. Whether you're a SOC analyst, penetration tester, or cloud security architect, this annual radar is designed to help you stay ahead of the market.