Senior Security Engineer

Spendesk

Greater London

On-site

GBP 90,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Spendesk is seeking a senior security engineer to act as the security conscience for engineering, building tooling, training developers, and partnering with Infrastructure on secure‑by‑default solutions. You will own the technical security roadmap and drive remediation across squads from day one.

This is a pure engineering role with an individual contributor track, focusing on technical depth rather than people management.

Qualifications

  • Hands-on experience across security domains including code auditing, infrastructure security and incident response.
  • Ability to own a security roadmap and communicate progress to non‑specialists.
  • Deep understanding of modern web architectures (microservices, cloud‑native, PaaS/SaaS).
  • Strong scripting and automation skills (Python, Bash).
  • Experience mentoring other engineers or security practitioners.
  • Excellent communication: ability to explain CVSS 9.8 risk to a PM and drive prioritisation.

Responsibilities

  • Own and operate vulnerability and incident management processes including triage and post‑mortem actions.
  • Lead detection and SIEM efforts: architecture, rules, indicators of compromise, runbooks.
  • Own IAM implementation and operations for product and infrastructure systems, including SSO/MFA config and access reviews.
  • Embed security into the development lifecycle with threat modelling, secure code patterns, and CI/CD hardening.
  • Coordinate penetration tests and security audits, manage auditor relationships, drive remediation within governance timelines.

Skills

Code auditing
Infrastructure security (AWS/Linux)
Penetration testing
SIEM operations
Incident response

Tools

ElasticSearch
AWS
GCP
Snowflake
Datadog
Okta

Job description

Spendesk is building the leading spend management platform for modern businesses, processing billions of euros across Europe and beyond. Security is at the heart of what we do, and we’re committed to raising the bar for security in fintech.

Your Mission

You’ll be the security conscience for engineering: building tooling, training developers, and partnering with Infrastructure on secure‑by‑default solutions. You own the technical security roadmap: partnering with the compliance team to identify risks, translating findings into actionable engineering‑native tools and processes, driving remediation, and raising the bar across the organization.

This is a pure engineering role, not governance or compliance: a separate team owns policy and risk frameworks. It’s an individual contributor track with high influence, focused on technical depth, not people management. You’ll mentor an Associate Security Engineer, shape practices across squads, and be the go‑to person when engineering teams need security guidance.

You’ll be hands‑on across the full security surface from day one. As the team grows, you’ll move from day‑to‑day operations toward architecture, strategy, and mentoring, acting as the escalation point for the Associate Security Engineer.

Key Responsibilities
Vulnerability & Incident Management
  • Own and operate our bug bounty program: manage the platform, set escalation thresholds, and drive strategic improvements.
  • Act as escalation point for vulnerability triage, taking the lead on complex or high‑severity findings.
  • Lead security incident response: qualification, forensics (including fraud investigations), fix coordination, post‑mortem, and resolution tracking.
Detection & SIEM
  • Own our SIEM platform (ElasticSearch, multi‑node Linux): architecture, detection rules, and indicators of compromise.
  • Build and evolve detection coverage, focusing on signal quality over manual toil.
  • Build and maintain security runbooks and operational documentation.
Identity & Access Management
  • Own IAM implementation and operations for product and infrastructure systems, downstream of corporate IT: SSO/MFA configuration, role and access‑rights implementation, periodic permission reviews, and secrets rotation.
  • Work within the authentication standards set by the security governance team.
Secure Development & Audits
  • Embed security into the development lifecycle: threat modelling, secure code patterns, CI/CD hardening.
  • Conduct technical security reviews of code (TypeScript, Node.js, Python), infrastructure‑as‑code (Terraform), and multi‑tenant AWS environments.
  • Drive security tooling in CI/CD: design and own the automated gate suite (SAST, SCA, container scanning, AI‑generated code risk detection) and ensure pipeline coverage scales with engineering growth.
  • Assess and govern AI tooling adoption across engineering: define security standards for code assistants and LLM‑powered workflows, and conduct AI‑specific threat modelling.
  • Coordinate and execute penetration tests and security audits: prepare environments, manage auditor relationships, drive post‑audit action plans.
  • Drive remediation within the qualification rules and timeframes set by the security governance team.
Education & Influence
  • Coach engineers on secure development through workshops, secure‑code guidance, and design reviews.
  • Surface security risks and recommendations to engineering leadership; own the security backlog and roadmap.
  • Partner with Infrastructure on secure‑by‑default solutions.
Must‑Haves
  • A track record of owning security outcomes end to end, with hands‑on experience across at least three of: code auditing, infrastructure security (AWS/Linux), penetration testing, SIEM operations, incident response.
  • Ability to own a roadmap: identify priorities, build a plan, execute autonomously, and communicate progress to non‑specialists.
  • Deep understanding of modern web architectures (microservices, cloud‑native, PaaS/SaaS) and where they break.
  • Strong scripting and automation ability (Python, Bash, or similar).
  • Experience mentoring other engineers or security practitioners.
  • Excellent communication: explain a CVSS 9.8 to a PM and get them to prioritise it.
Nice‑to‑Haves
  • Experience with ElasticSearch / ELK stack in production.
  • Familiarity with AWS, GCP, Snowflake, Datadog, Okta.
  • Knowledge of security standards and frameworks (ISO 27001, OWASP, SOC 2, PCI‑DSS).
  • Experience in a regulated fintech or payments environment.
  • Reverse engineering and analysis of minified/obfuscated code.

Not ticking every box? We’d still love to hear from you. If this role excites you and you believe you could contribute, we encourage you to apply.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

Atarus • England

On-site
GBP 70,000 - 90,000
Budget for certifications
Opportunities for continuous learning
Clear progression to Staff / Principal Security Engineer
Associate Security Engineer
Associate Security Engineer

Spendesk • Greater London

Hybrid
GBP 45,000 - 65,000
Flexible policy
Apple equipment
Moka.care
+3
Lead Security Engineer
Lead Security Engineer

Winston Fox • Greater London

On-site
GBP 70,000 - 95,000
Senior Security Operations Engineer New London
Senior Security Operations Engineer New London

Risk Ledger • Greater London

Hybrid
GBP 90,000 - 135,000
EMI equity
Healthcare AXA
Hybrid working policy
+3
Security Engineer
Security Engineer

Jobtailor • Greater London

On-site
GBP 70,000 - 110,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Payments & Cards Network • Greater London

On-site
GBP 100,000 - 150,000
Security Lead
Security Lead

Taktile • Greater London

On-site
GBP 110,000 - 190,000
Equity
Self-development budget
Home office setup
+1
Senior DevSecOps Engineer
Senior DevSecOps Engineer

PCN Media • Greater London

On-site
GBP 90,000 - 130,000
Lead Security Engineer
Lead Security Engineer

Eeze • Greater London

Hybrid
GBP 80,000 - 100,000
26 days paid holiday
Hybrid Working
Pension and Life Assurance
+2
Senior Application Security Manager
Senior Application Security Manager

United States Digital Space LLC • Greater London

Hybrid
GBP 120,000 - 180,000
Company card
Lunch provided
Private healthcare
+4