Staff Cyber Security Engineer
17 hours ago
About Lendable Lendable is on a mission to build the world's best technology to help people get credit and save money. We're building one of the world's leading fintech companies and are off to a strong start: One of the UK's newest unicorns with a team of just over 600 people Among the fastest-growing tech companies in the UK Profitable since 2017 Backed by top investors including Balderton Capital and Goldman Sachs Loved by customers with the best reviews in the market (4.9 across 10,000s of reviews on Trustpilot) So far, we've rebuilt the Big Three consumer finance products from scratch: loans, credit cards and car finance. We get money into our customers' hands in minutes instead of days. We're growing fast, and there's a lot more to do: we're going after the two biggest Western markets (UK and US) where trillions worth of financial products are held by big banks with dated systems and painful processes. Join us if you want to Take ownership across a broad remit. You are trusted to make decisions that drive a material impact on the direction and success of Lendable from day 1 Work in small teams of exceptional people, who are relentlessly resourceful to solve problems and find smarter solutions than the status quo Build the best technology in-house, using new data sources, machine learning and AI to make machines do the heavy lifting About The Role We are looking for a hands-on Staff Cyber Security Engineer to join our InfoSec team and help secure our growing platform and products. This role requires an engineer who can bridge the gap between development teams and security governance, ensuring we maintain a high standard of security, operational resilience, and regulatory compliance as we scale. You will be instrumental in the execution of our security strategy, directly contributing to our Application Security programme, advancing our DevSecOps capabilities, and supporting key Governance, Risk, and Compliance (GRC) activities. What You'll Be Doing This is a hybrid role covering both technical security implementation and critical compliance/risk management support: Application Security & DevSecOps Secure Development: Work directly with engineering teams to embed security best practices throughout the SDLC. Automation: Implement, maintain, and tune DevSecOps tools and pipelines (SAST, DAST, SCA) to automatically identify and remediate security flaws in code and infrastructure. Threat Modelling: Conduct and facilitate threat modelling sessions for new features and systems to proactively identify design-level risks. Vulnerability Management: Triage, validate, and track vulnerabilities identified across applications and infrastructure, driving efficient remediation efforts. Security Architecture: Provide technical advice on the secure design and configuration of our cloud environment (AWS/GCP) and associated technologies (Kubernetes, GitOps, Snowflake, Vault). Governance, Risk, & Compliance (GRC) Vendor Security Reviews: Execute vendor security assessments and due diligence reviews for new and existing third-party suppliers, maintaining required documentation for the Vendor Governance Forum. Audit Support: Assist the team in achieving and maintaining compliance with key regulatory and industry frameworks, including GDPR, ISO 27001, SOC2, and PCI DSS, by gathering evidence and documenting controls. Policy & Standards: Help translate high-level security policies into practical, actionable security standards and control requirements for engineering teams. Risk Reporting: Document and track identified risks from AppSec, vendor reviews, and operations, ensuring they are accurately captured and reported. Security Training: Support the delivery of security awareness and training programs tailored for technical and non-technical staff. What We're Looking For Proven, senior experience as a Cyber Security Engineer or similar role Hands-on experience implementing and managing security tooling within CI/CD pipelines Familiarity with modern cloud environments (AWS, GCP, or Azure) and container orchestration technologies (e.g., Kubernetes) Practical experience in conducting vendor security assessments and performing technical due diligence on third parties Good working knowledge of common security frameworks and regulations (e.g., ISO 27001, SOC2, PCI DSS), with experience supporting audit processes A strong understanding of common web application vulnerabilities and effective mitigation strategies Awareness or practical experience with AI-powered security tooling (e.g., AI-driven monitoring, generative AI for code review, or AI defense mechanisms) Excellent communication skills, capable of explaining complex security concepts to both technical and non-technical audiences Desirable Relevant certifications (e.g., OSCP, CISSP, CSSLP, AWS Security Specialty) Experience with Engineering and Automation tooling (e.g., Terraform, CloudFormation, GitHub, Python) Interview process Intro Call with People Team: A brief conversation to get to know you and your background. Call with InfoSec team member: A deeper dive into your experience and how it aligns with our vision. Final Technical and Cultural Interview: A deeper session where you'll meet with several team members and stakeholders to discuss your motivations and expertise, and your approach to delivery and collaboration. Life at Lendable The opportunity to scale up one of the world's most successful fintech companies. Best-in-class compensation, including equity. You can work from home every Monday and Friday if you wish - on the other days, those based in the UK come together IRL at our Shoreditch office in London to be together, build and exchange ideas. Enjoy a fully stocked kitchen with everything you need to whip up breakfast, lunch, snacks, and drinks in the office every Tuesday-Thursday. We care for our Lendies' well-being both physically and mentally, so we offer coverage when it comes to private health insurance We're an equal-opportunity employer and are looking to make Lendable the most inclusive and open workspace in London Check out our blog
-
Cyber Security Engineer
17 hours ago
Slough, Berkshire, United Kingdom JSM Group Services Ltd. Full timeTHE TEAM At JSM Group, we're building the utility and infrastructure networks of the future — delivering power and communications solutions that truly matter. Our IT & Security team plays a critical role in protecting our systems, data and operations from cyber threats, ensuring we continue to deliver safely and reliably across all our business units...
-
Cyber Security Specialist
3 days ago
Slough, Berkshire, United Kingdom CBSbutler Full timeSC Cleared SIEM/EDR Engineer Contract – Hybrid Reading (3 days onsite) – Immediate Start We've just been awarded a high priority, long term rolling cyber programme (major global consultancy, household name end client) and we need an experienced SIEM/EDR Engineer to start, ideally before Christmas / early Jan. Key highlights: Rolling contract for 12–24...
-
Cyber Security
17 hours ago
Slough, Berkshire, United Kingdom Legal & General Full timeLegal & General (L&G) is a leading UK financial services group and major global investor. We’ve been safeguarding people’s financial futures since 1836, and strive to build a better society, while improving the lives of our customers and creating value for shareholders. We are one of the world’s largest asset managers and provide powerful asset...
-
Presales Engineer
3 weeks ago
Reading, Berkshire, United Kingdom Areti Group | B Corp™ Full timePresales Engineer – Cyber Security Reading HQ | Hybrid Working (1-2 Days in Reading per month). £120,000-£130,000 Package (Base Salary, Car Allowance, & Bonus). Excellent Training, Certifications, and, Career Progression. Areti are delighted to be supporting a rapidly expanding technology business in their search for a Cyber Security Presales Engineer to...
-
Cyber Security Associate Director
18 hours ago
Slough, Berkshire, United Kingdom Oliver James Full timeOliver James are partnered with a leading global professional services organisation in their search for a Cyber Advisory & Assurance Associate Director. The role is based in London (on a hybrid basis) and pays up to c£100,000 depending on experience. Oliver James are partnered with a leading global professional services organisation in their search for a...
-
Cyber Security Incident Response
18 hours ago
Slough, Berkshire, United Kingdom Thomas Miller Full timeCyber Security Incident Response & Threat Intelligence Analyst Team Overvie wThe Cyber Security Operations Team is responsible for monitoring, detecting, and responding to cyber threats across Thomas Millers estate. We ensure the protection of digital assets and safeguard confidentiality, integrity and availability of systems. Working in a fast-paced...
-
Cyber Security Engineer
3 days ago
Pangbourne, Berkshire, United Kingdom XP Power Full timeWe are committed to our culture that values Customer Focus, Flexibility, Knowledge, Speed and Integrity. Joining our team means you will work in a high performing global company where employees collaborate and strive for excellence. As a Cyber Security Engineer, you will design, implement, and maintain security solutions to protect XP Power's global...
-
Cyber Security Engineer
3 days ago
Pangbourne, Berkshire, United Kingdom XP Power Full timeWe are committed to our culture that values Customer Focus, Flexibility, Knowledge, Speed and Integrity. Joining our team means you will work in a high performing global company where employees collaborate and strive for excellence. As a Cyber Security Engineer, you will design, implement, and maintain security solutions to protect XP Power's global...
-
Cyber Security Specialist
2 weeks ago
Slough, Berkshire, United Kingdom IP-People Full timeCyber Security Solutions Consultant – Hybrid (Reading / Remote) - Up to £100k Package A leading, award-winning, and rapidly expanding Cyber Security & Networking Consultancy is seeking a Cyber Security Solutions Consultant to join their high-performing team. This is a presales-focused, customer-facing role that bridges the gap between technology and...
-
Cyber Security Engineer
3 days ago
Berkshire, United Kingdom XP Power Full timeMonitor company infrastructure systems networks and cloud platforms for security events and vulnerabilities and triage security incidents and alerts Design implement and manage security solutions for cloud (primarily Azure) and on-premises environments Lead and participate in Incident Response and Disaster Recovery programs including regular testing and...