Senior Security Engineer - Contract

Flagstone

Greater London

On-site

GBP 90,000 - 120,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Flagstone is seeking a senior security engineer to own and evolve cloud security, detection tooling, and incident response across Azure. You’ll operate Microsoft Sentinel, Defender for Cloud, and contribute to detection-as-code while coordinating pen tests and remediation with multiple engineering squads.

You’ll bring hands-on SIEM experience, Azure security expertise, and a proactive mindset. If you enjoy impactful, visible work in a fast-growing fintech environment, apply to join our diverse

Qualifications

  • Hands-on SIEM experience, Microsoft Sentinel preferred; other platforms ok.
  • Azure security across Defender for Cloud, Entra ID, networking, and CSPM.
  • Infrastructure-as-code with Terraform or Bicep in security context.
  • Experience driving vulnerability remediation with engineering teams.
  • Familiarity with data-loss-prevention controls.
  • Awareness of AI security and securing AI workloads or tooling.
  • Ability to articulate security risk via threat modelling to engineers/products.
  • Growth mindset and curiosity to learn continuously.
  • SC-200 certification or equivalent.
  • Proficiency in KQL for detection and hunting.
  • Experience in a fintech/financial services environment.

Responsibilities

  • Own and operate alerting/monitoring during transition and maintain steady detection/response.
  • Maintain and improve Microsoft Sentinel deployment: write/detect rules, manage data connectors, reduce noise.
  • Operate Defender XDR/Defender for Cloud: policy mgmt and posture recommendations.
  • Extend automated security checks in delivery pipelines (shift-left).
  • Drive down time-to-fix on vulnerabilities; coordinate remediation with squads.
  • Support data-loss-prevention controls to reduce data exfiltration risk.
  • Safeguard AI usage: secure AI workloads and data exposure controls.
  • Investigate suspicious activity surfaced by Sentinel/Defender; triage/elevate/contain as needed.
  • Support incident response: containment, evidence gathering, post-incident review.
  • Contribute to detection-as-code and IaC for security tooling (Terraform/Bicep).
  • Coordinate penetration test engagements and work with teams to remediate.

Skills

SIEM experience
Azure security
IaC (Terraform/Bicep)
Vulnerability remediation
DLP controls
AI security
Threat modelling
Growth mindset
SC-200
KQL
Fintech exposure

Job description

What is Flagstone?

Flagstone is many things. An online savings platform, reinventing how individuals, businesses, and charities manage, protect, and grow their cash. A diverse group of people, bound by a collaborative spirit, and shared purpose. And lastly, a thriving, profitable business – where smart people do their best work.

What is Flagstone?

Flagstone is many things. An online savings platform, reinventing how individuals, businesses, and charities manage, protect, and grow their cash. A diverse group of people, bound by a collaborative spirit, and shared purpose. And lastly, a thriving, profitable business – where smart people do their best work.

Each definition shares a common thread: our unique culture. It’s our pride and joy. And our competitive advantage.

A feel for our culture:

To revolutionise the savings market, we need to be at our best. But high performance takes more than talent – it takes a culture of kindness, respect, and growth.

That’s why we’re building a diverse, inclusive community, where your voice is heard and valued. Where, with close support and room to develop, you can surpass even your own expectations. And be rewarded for it.

We may not change the world, but we can change the world of financial technology. And all it takes is a winning mix of drive, talent, and empathy. Our culture celebrates all three.

But enough about us. Let’s talk about you.

About The Team

Security Engineering is a team of five covering cloud security, detection, and security operations. They work directly in the Azure estate and are close to the infrastructure, not abstracted behind a policy layer. The team runs Microsoft Sentinel, Defender XDR, and Defender for Cloud, and manages tooling through infrastructure-as-code. They run a quarterly penetration test programme and are continuously building out our detection and response capability. It's a small team with broad scope, which means your work is visible, your opinions are heard, and there are meaningful problems for our engineers to work on.

This is a contract role, so we're looking for someone who can hit the ground running. You'll bring immediate impact and add value from day one, working independently without a long ramp-up. Your work will be visible, and the problems you solve will matter.

Does this sound like you?

You're a senior security engineer who operates credibly across cloud security, detection tooling, and incident response, without being narrowly specialised. You own meaningful parts of the security stack, contribute hands-on to Azure cloud hardening, and show up reliably when incidents need investigating or pen test cycles need coordinating. You're energised by visible impact, your work matters, and your voice is heard.

What you’ll do:
  • Own and operate our alerting and monitoring capability through a transition period, keeping detection and response steady.
  • Maintain and improve our Microsoft Sentinel deployment: writing and tuning detection rules, managing data connectors, and reducing alert noise.
  • Operate and optimise Defender XDR and Defender for Cloud, including policy management and posture recommendations.
  • Maintain and extend automated security checks in our delivery pipelines (shift-left).
  • Drive down time-to-fix on known vulnerabilities, coordinating remediation with engineering squads.
  • Support data-loss-prevention controls that reduce the risk of sensitive data leaving the business.
  • Support safeguards around how the business accesses and uses AI, including securing AI workloads and their data exposure.
  • Investigate suspicious activity surfaced through Sentinel and Defender: triage, elevate, or contain as appropriate.
  • Support incident response, including containment, evidence gathering, and post-incident review.
  • Contribute to detection-as-code and infrastructure-as-code (Terraform or Bicep) for security tooling.
  • Coordinate penetration test engagements (scope, logistics, findings review) and work with engineering teams to prioritise remediation.
What you’ll bring:
  • Hands-on SIEM experience, ideally Microsoft Sentinel; equivalent platforms (Splunk, Chronicle, QRadar) considered.
  • Practical Azure security experience across Defender for Cloud, Entra ID, Azure networking, and cloud security posture management.
  • Experience writing infrastructure-as-code using Terraform or Bicep in a security engineering context.
  • Experience driving vulnerability remediation cycles with engineering squads.
  • Familiarity with data-loss-prevention controls.
  • Familiarity with AI security considerations (securing AI workloads, data exposure risks) and/or using AI tooling to augment security engineering workflows.
  • Ability to contribute to threat modelling and communicate security risk clearly to engineering and product audiences.
  • A growth mindset and genuine curiosity to keep learning.
  • SC-200 (Microsoft Security Operations Analyst) certification.
  • KQL proficiency for detection rule authoring and threat hunting.
  • Experience working in a similar fintech or financial services environment
All are welcome:

At Flagstone, we’re assembling a diverse team that defies our industry’s norms. Think this role could suit you? We encourage you to apply, no matter your background.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer - Contract
Senior Security Engineer - Contract

jobr.pro • Greater London

On-site
GBP 90,000 - 130,000
Senior Security Engineer - Contract
Senior Security Engineer - Contract

Flagstone Group • Greater London

Hybrid
GBP 90,000 - 120,000
Senior Security Engineer - Contract
Senior Security Engineer - Contract

Flagstone Group Ltd • Greater London

On-site
GBP 70,000 - 100,000
Senior Security Engineer - Contract
Senior Security Engineer - Contract

United States Digital Space LLC • Greater London

On-site
GBP 70,000 - 110,000
Senior Application Security Engineer
Senior Application Security Engineer

Flagstone • Greater London

On-site
GBP 90,000 - 130,000
Bonus scheme
Benefits budget
Salary sacrifice
+9
Staff Engineer
Staff Engineer

Flagstone • Greater London

On-site
GBP 110,000 - 160,000
Hybrid working in London office
Competitive bonus
Personal development budget
+4
Azure Security Engineer — SIEM, XDR & Incident Response (Contract)
Azure Security Engineer — SIEM, XDR & Incident Response (Contract)

jobr.pro • Greater London

On-site
GBP 90,000 - 130,000
Staff Engineer
Staff Engineer

Flagstone Group • Greater London

Hybrid
GBP 90,000 - 120,000
Hybrid work London
Bonus scheme
Benefits budget
+10
Engineering Team Lead - 12 month FTC
Engineering Team Lead - 12 month FTC

Flagstone Group • Greater London

Hybrid
GBP 100,000 - 150,000
Hybrid working
Competitive bonus
Flexible benefits budget
+10
Contract Senior Security Engineer: Cloud, SIEM & IR
Contract Senior Security Engineer: Cloud, SIEM & IR

Flagstone Group Ltd • Greater London

On-site
GBP 70,000 - 100,000