
Abound · London
About Abound We’re redefining consumer lending in the UK, and beyond. Using advanced AI and Open Banking data, we make fair, affordable personal finance availa...
About Abound
We’re redefining consumer lending in the UK, and beyond. Using advanced AI and Open Banking data, we make fair, affordable
personal finance available to more people. While traditional lenders rely almost entirely on credit scores, we look at the full
financial picture - how much you spend, and what you can afford to repay to build a deeper, more accurate understanding of each
customer's unique financial situation.
And we've shown it works at scale. We’ve issued over £1.3bn in loans directly to customers while delivering market-leading credit
performance - for every 10 defaults the industry expects, we see only 3. We also reached profitability just 2.5 years after
launch.
Backed by £2bn+ of funding from top-tier investors including Citi, GSR Ventures, and Deutsche Bank, we’re recognised as one of
Europe’s fastest-growing fintechs (Sifted, CNBC). Now, we’re expanding into new markets and product lines - and we’re looking for
ambitious people who want to learn fast, take ownership, and grow with us.
You won't be sitting in an ivory tower throwing policies over the fence. You will be embedded directly within our Platform team in
a true DevSecOps capacity. Operating as a highly technical individual contributor, you will bridge the gap between product-led
engineering and Corporate IT.
You will play a hands-on role in challenging the security architecture of production and corporate IT infrastructure.
In your first 6–12 months, you will design and implement our next-generation cloud security architecture across AWS and GCP, while
helping to build and mature our internal SOC capabilities, including detection and response.
You will take ownership of Microsoft Sentinel, enhancing our SIEM/SOAR capabilities, and strengthen identity and access management
through improved and automated RBAC across AWS, Microsoft Entra, and internal systems.
You will also drive a shift-left approach to security by embedding controls into GitLab CI/CD pipelines, including scanning, IaC
reviews, and automated policy enforcement across the SDLC.
Cloud & Compute: AWS, ECS Fargate, Aurora, Lambda, GCP
Data Lake: S3, DMS, Glue
Cloud Security Tooling: GuardDuty, Security Hub, Inspector, Security Command Center
Code & IaC: Python, Java, GitLab, AWS CDK, Terraform/CDK-TF
Observability & Incident Management: AMP, Incident.io
security engineering, with hands-on experience elevating the security posture of other organisations.
scratch.
architectures.
security with engineering velocity.
What we offer
Applications deadline: We are conducting interviews actively and aim to fill this role as soon as we find someone suitable. THE OPPORTUNITY We're looking for a senior Security Engineer to own security at Apollo Research from end to end. You'll be the first dedicated security hire at Apollo. Security at Apollo exists to maintain the trust of our frontier AI lab partners and enable our research mission. This role sits within the engineering team and reports directly to the CEO. YOU HAVE THE OPPORTUNITY TO - Build and own Apollo's security programme. Own the security roadmap, conduct risk assessments, and evolve the programme as the org grows. You decide what Apollo's security posture needs to look like given our size, threat model, and partner relationships. - Maintain the trust of our frontier AI lab partners. Become the primary security point of contact for partner security teams. Build relationships with partner CISOs, produce and maintain technical documentation on Apollo's security practices, and demonstrate that our security posture meets the bar required for our ongoing partnerships. - Set security direction for engineering. Define security principles and AppSec strategy which the engineering team implements. Build paved roads that make the secure path easy for engineers. - Define how Apollo uses AI tools, agents, and integrations. Decide what's approved, what data can go where, and how new tools get vetted. This is a live and evolving challenge, and you'll need to balance security with the fact that researchers need to use cutting-edge tools to do their jobs. - Own the security tooling stack and automate security operations. Select, implement, and manage security controls including EDR/MDR, endpoint management, email protection, and identity management. Automate wherever possible: zero-touch deployments, IaC for security tooling, automated provisioning and deprovisioning. - Drive compliance and certification. Lead certification efforts (ISO 27001, SOC 2) as needed to meet partner requirements. Automate where needed and treat compliance as a byproduct of good security practice. - Own IT administration across the organisation. Manage Google Workspace, define access policies, and build secure onboarding and offboarding processes. WHAT WE'RE LOOKING FOR - Engineering mindset. You treat security operations and GRC as engineering problems. You reach for automation and systems solutions over manual processes. - Pragmatism. You understand that security exists to enable Apollo's mission and maintain partner trust, and you tailor your advice to our risk profile. - Leadership. You are capable of building out our security programme from scratch. - Hands-on. In addition to leading the security programme, you are willing and able to drive implementation yourself. - Speed. You make good-enough decisions quickly and execute fast once a decision is made. - Adaptability to new developments. You have a strong base of knowledge that enables you to make decisions under uncertainty as AI tooling and the threat landscape evolve. - Stakeholder credibility. Non-security people trust you internally, and you can credibly represent Apollo to lab partner security teams externally.
About us: Causaly is redefining how humans acquire knowledge and develop insights in biomedicine. Our AI-powered platform enables researchers and decision-makers to discover and interpret evidence from millions of scientific publications, clinical trials, regulatory documents, and other complex data sources in minutes. We are building the world’s most advanced biomedical knowledge platform, powered by a high-precision Knowledge Graph and GenAI capabilities. Our technology is already used by leading biopharmaceutical organizations to accelerate drug discovery, improve safety, and drive better decision-making. Backed by top-tier investors including ICONIQ, Index Ventures, Pentech, and Marathon, we are scaling rapidly and expanding our product suite and market presence. About the Role We are looking for a Senior or Staff Security Engineer to join our security team and own our vulnerability management program, collaborate with several Engineering and Product teams as a Security advisor and support SecOps. You will operate with a high degree of autonomy — defining strategy, building processes, and acting as a trusted security advisor to our engineering organisation. What You'll Do * Own the vulnerability management program end-to-end: strategy, tooling, prioritisation, and remediation tracking across dependencies, containers, and cloud environments. * Define and maintain a dependency security strategy, including policies for third-party library adoption and update cadence. * Integrate and maintain security tooling in CI/CD pipelines (SAST, SCA, secrets detection, container scanning). * Act as a security consultant to product and engineering squads — supporting design reviews, architecture decisions, and secure coding practices. * Define and maintain security standards and guidelines practical for development teams. * Manage and continuously improve the Security Champions program — growing security awareness and capability across engineering teams. * Support SecOps in incident triage and response, contributing security engineering context where needed. Requirements * Strong knowledge of cloud security — IAM, network security, secure configuration best practices. * Hands-on experience with security tooling in CI/CD pipelines (SAST, SCA, secrets scanning, container scanning). * Proven experience in a vulnerability management role, through the entire lifecycle. * Passionate and knowledgeable about using LLMs for building robust security practices, including triage, secure code review, threat analysis and tooling * In-depth knowledge of secure coding practices in Node.js, TypeScript, Python, and/or React. * Familiarity with security frameworks and standards (e.g. OWASP, NIST, CIS Benchmarks). * Strong communication skills, with the ability to translate risk for both technical and non-technical audiences. Nice to Have * Experience with Semgrep for static analysis and custom rule authoring. * Experience with Wiz for cloud security posture management. * Experience running or contributing to a Security Champions program. * Experience with threat modelling (e.g. STRIDE). * Familiarity with SOC 2 and ISO 27001. * Relevant certifications are considered a plus (e.g. CISSP, IaaS specific certifications, etc..). Benefits UK: 💰 Competitive compensation package 🩺 Private medical insurance 🦷 Private dental insurance 📔 Life insurance (4 x salary) 🤓 Personal development budget 🧘 Individual wellbeing budget 🌴 25 days holiday plus bank holidays 🥳 Your birthday off! 🚀 Potential to have real impact and accelerated career growth as a member of an international team that's building a transformative AI product. We are on a mission to accelerate scientific breakthroughs for ALL humankind, and we are proud to be an equal opportunity employer. We welcome applications from all backgrounds and fairly consider qualified candidates without regard to race, ethnic or national origin, gender, gender identity or expression, sexual orientation, disability, neurodiversity, genetics, age, religion or belief, marital/civil partnership status, domestic / family status, veteran status or any other difference.
ABOUT LENDABLE Lendable is on a mission to build the world's best technology to help people get credit and save money. We're building one of the world’s leading fintech companies and are off to a strong start: * One of the UK’s newest unicorns with a team of just over 700 people * Among the fastest-growing tech companies in the UK * Profitable since 2017 * Backed by top investors including Balderton Capital and Goldman Sachs * Loved by customers with the best reviews in the market (4.9 across 10,000s of reviews on Trustpilot) So far, we’ve rebuilt the Big Three consumer finance products from scratch: loans, credit cards and car finance. We get money into our customers’ hands in minutes instead of days. We’re growing fast, and there’s a lot more to do: we’re going after the two biggest Western markets (UK and US) where trillions worth of financial products are held by big banks with dated systems and painful processes. JOIN US IF YOU WANT TO 1. Take ownership across a broad remit. You are trusted to make decisions that drive a material impact on the direction and success of Lendable from day 1 2. Work in small teams of exceptional people, who are relentlessly resourceful to solve problems and find smarter solutions than the status quo 3. Build the best technology in-house, using new data sources, machine learning and AI to make machines do the heavy lifting About the Role At Lendable, we don’t do box-ticking security. We’re building automated guardrails and high-leverage tooling integrations to keep our business moving fast and safely. We are looking for a practical, execution-focused Security Engineer to manage the configuration, integration, and engineering lifecycle of our internal security tools. This is a highly versatile engineering role for someone who loves to solve security problems with code and automation. You will act as the engineering engine room for the InfoSec team - collaborating closely with our SecOps, AppSec, Architecture, Security GRC and IT Systems leads to translate security requirements into working configurations, automated pipelines, and custom data integrations. Whether it's writing Terraform to roll out a new edge security rule, stitching together SaaS APIs via Python to pull data into a centralised reporting app, or jumping into a web UI for some quick "click-ops" configuration, your focus is entirely on efficiency, posture improvement, and eliminating manual toil. What You’ll Be Doing * Configuration as Code: Drive security configurations across our stack utilising a Terraform and GitOps workflow. * Tooling Optimisation: Get the most out of our InfoSec tooling through proactive setup, tuning, and configuration, ensuring we maximise our defensive utility and continuously improve our security posture. * Platform Integrations: Build and maintain high-leverage integrations between cloud providers, SaaS platforms, and our core security tooling - for example, engineering log pipelines into our SIEM or automating evidence feeds into our compliance platform. * Automation Engineering: Architect and deploy agentic workflows and lean automation scripts to eliminate manual toil, driving productivity and scalability for the InfoSec team. * Frictionless Control Implementation: Design and deploy practical guardrails, CASB, and data loss prevention (DLP) policies across network boundaries and collaboration tools – for example, Google Workspace. Your focus is on safeguarding data and enabling safe tooling usage without creating engineering bottlenecks. What We’re Looking For * Practical Engineering Capabilities: Solid hands-on experience using Python (or similar) to automate tasks, Terraform to manage infrastructure, connect APIs, and manage infrastructure state, balanced with the judgement to use UI configurations when code isn't viable. * Cloud & Infrastructure Literacy: Proven experience configuring or hardening security controls within cloud (AWS/GCP) environments (e.g. IAM and network/identity boundaries) and handling data formats like JSON to parse logs. * AI-First Execution: Enthusiastic about actively leveraging advanced AI coding tools (such as Claude Code, Codex) to exponentially increase your engineering output, script generation, and delivery speed. * Pragmatic Security Mindset: A builder who views security as a business enabler. You focus on building practical defensive posture rather than filling out compliance checklists, with the instinct to identify actual systemic risk based on context. * Bias for Action: An execution-focused operator. When a security control drifts or a peer needs a detection mechanism, you write the script, open the PR, or modify the control to get it done. * Communication & Collaboration: The ability to debate technical IAM architecture details with a Platform Engineer and seamlessly explain to non-technical risk stakeholders why a specific control change matters. Interview Process 1. TA Screening Call 2. Hiring Manager Call 3. Technical Interview 4. Culture Interview LIFE AT LENDABLE * Winning team: the opportunity to scale up one of the world’s most successful fintech companies * Flexible working: flexible approach tailored to each role. Hybrid roles require three days in-office weekly; fully remote roles include regular opportunities for in-person connection through socials and off-sites * Socials & connection: opportunities and events to come together, socialise, and get to know each other beyond the office walls * Health coverage: support for your physical and mental wellbeing, including private health cover * Retirement & savings: long-term financial wellbeing through retirement savings plans * Employee referral programme: earn a competitive bonus when you refer successful new team members * Office meals & snacks: enjoy a fully stocked kitchen, plus complimentary lunches prepared by in-house chefs on in-office days at select locations * Sustainable commuting: cycle-to-work and electric vehicle salary sacrifice schemes available in select locations Please note: The availability and details of specific benefits vary by location and role. For more information, please speak to your Talent Partner. Check out our blog!