The Role & The Challenge
We are seeking an exceptional, highly proactive Senior Cyber Security Engineer to drive an engineering-led security transformation for a major financial and payments ecosystem.
This is not a tick-the-box, paper-pushing compliance security role. We are looking for a hands-on technical practitioner to help anchor an elite, engineering-led security program. You will take complete technical ownership of hardening mission-critical digital perimeters, designing enterprise Web Application Firewalls (WAF), advanced DDoS protection, and modern Identity and Access Management (IAM/CIAM) ecosystems.
If you are content with waiting for rigid audit specs or manual security reviews, this is not the role for you. You will step into a high-trust, empowered environment where you will architect robust security controls, secure high-volume API gateways, and automate threat defences from the ground up.
Access to AI Tooling: We believe in removing friction so you can focus on solving hard problems. You will have full access to enterprise AI tooling, including Claude Code, to assist you in accelerating security log analysis, policy tuning, script automation, and vulnerability remediation.
Key Responsibilities
- Network & Application Defence: Design, deploy, and support enterprise-grade WAF, DDoS protection, and bot management services across complex cloud, hybrid, and on-premises environments.
- Identity & Access Modernisation: Architect and enhance secure customer identity (CIAM) capabilities, supporting modern authentication controls, multi-factor authentication (MFA), and federated identity protocols (OAuth 2.0, OpenID Connect, SAML).
- API & Perimeter Security: Secure web applications and high-volume APIs against OWASP Top 10 threats, malicious traffic, and protocol-layer attacks.
- Security Automation & Infrastructure as Code: Develop automation scripts using Python or PowerShell and leverage modern CI/CD pipelines to enforce security configurations continuously.
- AI-Assisted Operations: Utilise modern AI tooling and Claude Code to assist in automating threat detection analysis, streamlining incident response playbooks, and optimizing security rulesets.
- Cross-Functional Collaboration: Partner closely with network, cloud, application development, and DevOps squads to embed security-by-design principles natively into the delivery lifecycle.
What You Bring (Attitude & Mindset)
- Thrives in Ambiguity: You are exceptionally comfortable walking into complex, ambiguous security environments. Rather than waiting for a rigid checklist, you take the initiative to rapidly distill requirements and map out robust defense paths.
- Fearless Continuous Learner: When faced with a novel threat vector, an unfamiliar protocol, or a complex integration gap, you do not freeze—you lean in, rapidly upskill, bridge the divide, and master the domain.
- The Desire for a Challenge: You actively seek out difficult security constraints and thrive when protecting high-scale, mission-critical financial systems.
- Radical Communication & Ownership: You communicate transparently, collaborate openly with engineering squads, challenge security blind spots early, and take uncompromising personal accountability for protecting the platform.