Security Engineer

Remote: 
Full Remote
Contract: 
Work from: 

Offer summary

Qualifications:

Hands-on experience in Security Operations Centre, Product/Application Security, or Cloud Infrastructure Security., Proficient in at least one mainstream programming language, with a preference for Go and Javascript., Experience with Cloud security and implementing a Zero Trust security strategy is advantageous., Solid understanding of software engineering best practices, including Agile SDLC and CI/CD..

Key responsabilities:

  • Develop and implement the security strategy in collaboration with the Head of Engineering.
  • Operate and enhance security infrastructure, including SIEM, WAFs, and Firewalls.
  • Ensure best practices in secure development and vulnerability remediation with engineering teams.
  • Maintain certifications and identify automation opportunities in Governance, Risk, and Compliance.

Thirdfort logo
Thirdfort Legaltech: Legal + Technology Scaleup https://www.thirdfort.com
51 - 200 Employees
See all jobs

Job description

We’re on a mission to protect society from fraud and money laundering. Fraud and regulation are rising, costing the UK economy over £100bn every year; this makes it more difficult for businesses to protect themselves and their clients - individuals like you and me - from fraud and money laundering.

Our co-founders Olly and Jack were led to this area when a friend was defrauded of £25K when buying their first property. At the time, anti-fraud technology didn’t exist, which meant that completing the anti-fraud checks required in these processes was largely manual. These big life moments should be exciting, but instead are often confusing and scary due to the painful process of completing these paper-based checks and the risk of fraud.

Thirdfort helps businesses to facilitate these anti fraud checks so that individuals know they can transact safely and seamlessly with professionals during these big transactions.

Our anti-fraud platform provides a secure way for professionals in regulated sectors like Lawyers, Estate Agents and Accountants to transfer funds and verify sensitive information through app based document checks, facial recognition and open banking.

Over 1500 businesses now trust Thirdfort to verify their clients. We are FCA regulated and have raised over $25m in capital from leading Fintech investors Breega and Element Ventures, as well as the founders of Zoopla, Funding Circle, Comply Advantage, Tessian, Fenergo and Fidel.

The Role:
  • You will be responsible for information security at Thirdfort, leveraging your expertise to help us live our Build on Trust company value. By improving the coverage and efficiency of our security controls, you will help reduce our security risk whilst also allowing us to give best in class answers to clients, regulators and auditors about our security practices. You will report directly to the Head of Engineering.
  • You will oversee critical security infrastructure and operations, automate security workflows, and work closely with technical and business stakeholders to ensure effective, efficient and appropriate security controls are in place across all parts of the business.
  • This is a great opportunity to across all aspects of security, and help shape how security is done at Thirdfort. Working in a fast paced, cloud native environment, you will be involved in everything from security operations to application security, cloud security and supply chain security.
  • You will thrive in this role if you are an experienced and curious technologist, and enjoy finding pragmatic and effective solutions to business problems. A breadth of knowledge across security and software engineering fields, with the ability to deep dive on areas as needed, will set you up well for success
  • Our Product and Tech teams are remote first and so you can be based anywhere in the UK. This does not mean though that our remote first team aren’t welcome in our offices as we value the times when we can come together in person. Ultimately we trust our team to work in the way that suit them best.

  • You will achieve your mission as our Security Engineer by:
  • Working with the Head of Engineering to develop the security strategy and ensure appropriate security governance is in place
  • Operating and improving/implementing security infrastructure including SIEM, WAFs, Firewalls and EDR/AV
  • Working with engineering teams to ensure best practices including secure development, security testing, vulnerability remediation and supply chain security
  • Working with DevOps on our Cloud Security Posture, ensure appropriate IAM structures are in place, and review, triage and remediate (or coordinate remediation of) cloud infrastructure threats and findings
  • Work closely with on Governance, Risk and Compliance to maintain certifications (e.g. ISO 27001), and identify opportunities for automation - improving efficiency and coverage.

  • You may be right for this role if you:
  • Have hands-on experience in one or more of the following areas: (Security Operations Centre; Product/Application Security; Cloud Infrastructure Security; Cloud DevOps/Infrastructure Engineering)
  • Have reasonable experience of Cloud security
  • Are a confident writing code in at least one mainstream programming language
  • Are a security generalist - happy to get stuck in to different security specialisms even if you don’t have prior professional experience
  • Have a pragmatic, result and risk oriented approach to security

  • You would be an excellent fit for this role if you:
  • Previously worked with Google Cloud Platform
  • Are confident writing code in Go and Javascript
  • Have been involved in implementing a Zero Trust security strategy
  • Have used Infrastructure as Code solutions such as Terraform
  • Have experience of working closely software engineering teams
  • Have a solid understanding of software engineering best practices, including the Agile SDLC, CI/CD, iterative development, automated testing etc.
  • The ability to set meaningful, business aligned goals and execute independently, utilising your great communication skills
  • Have a solid understanding of Enterprise security, such as experience working with IT teams on MDM, EDR, CASB, and/or SASE configuration and management.

  • Studies show that women and other less represented groups are less likely to apply for roles unless they meet every requirement. We believe in building a diverse team, valuing different skills and experiences and so if you don’t think you have all the requirements listed here but feel this could be a role and environment you’d thrive in, we would still love for you to apply.

    Life at Thirdfort:
  • Driven by our values, our culture promotes a collaborative and open environment where Thirdforters can take ownership, have impact, and feel empowered when it comes to their growth and development. We understand the importance of our teams wellbeing and recognise a one-size fits all approach rarely works, that’s why we aim to provide the flexibility individuals need to work in the way that suits them, and their families, best.

  • Our Benefits:
  • We’ve created our benefits package to reflect Thirdfort’s mission and values. We place a strong focus on Security first given what we do, extending this to our team’s physical, mental and financial security to support them through their big life moments. Our benefits exist to empower our team, ensuring they feel supported and able to work in the way that enables them to do their best work.

  • When you join Thirdfort, you’ll get immediate access to our flexible employee benefits package that aims to support you across these areas:

  • Compensation - £80,000-£100,000 p.a. base salary
  • Flexible Working Hours
  • Enhanced parental leave
  • Customisable wellness budget and £250 WFH Budget
  • Up to 30 days Working from Abroad
  • Uncapped holiday
  • Enhanced sick leave
  • Private healthcare with our provider, AXA
  • Regular company and team socials
  • Uncapped budget for personal development
  • Share options for all employees
  • Regular company and team socials
  • Enhanced employer matching pension scheme with salary sacrifice options
  • Access to our Cycle to Work scheme

  • We’re committed to building an inclusive, equitable and diverse culture where everyone has a chance to make a difference. We’re purposefully building a team of problem-solvers that reflect our values - which is why we hire from all backgrounds. If you're a curious, kind individual who takes ownership, you'll be a great Thirdforter.

    If you require any reasonable adjustments during the application or interview process, please let your dedicated Talent Manager know and we’ll do our best to accommodate.

    Required profile

    Experience

    Industry :
    Legaltech: Legal + Technology
    Spoken language(s):
    English
    Check out the description to know which languages are mandatory.

    Other Skills

    • Governance
    • Collaboration
    • Communication
    • Problem Solving

    Security Engineer Related jobs