SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Thought Machine is building modern banking technology to replace legacy systems at scale. The company has raised over £500m from top-tier investors including JPMorgan Chase, Standard Chartered, and Temasek, and operates offices across London, New York, Singapore, Sydney, and Lisbon.
As an Application Security Engineer, you will play a leading role in protecting Thought Machine's product against security risks and implementing cutting-edge security measures. This is a greenfield challenge—the company is building next-generation banking infrastructure with modern web technology, requiring custom security solutions rather than off-the-shelf frameworks. You will work cross-functionally with development and infrastructure teams to design, implement, and maintain security controls that satisfy both engineering velocity and financial services regulatory requirements.
Key responsibilities include:
- Drive improvements to product security posture through strategic planning and collaboration with development and infrastructure teams
- Produce production web-scale application security designs
- Review and produce data privacy and financial regulatory designs (functional and non-functional)
- Perform design reviews and threat modeling of services and products
- Conduct vulnerability assessments and security testing
- Provide subject matter expertise across the software development lifecycle
- Liaison with development teams on design, code reviews, and security education
- Contribute to security strategy, tooling selection, and tool creation
- Conduct regular security assessments and code reviews
This is a full-time, permanent position based in the Lisbon office, requiring four days per week onsite.
REQUIREMENTS
Essential:
- Expertise with a programming language (Python, Go, or Java)
- Experience with security in DevOps environments
- Experience in web application penetration testing and security tooling (Burp proxy, web/network scanners, static code analyzers)
- Coding experience for automating/integrating security tools and creating security tools
- Knowledge of security in distributed systems at scale
- Cloud and container technology knowledge (AWS, GCP, Kubernetes, Docker)
- Experience performing security design reviews, threat modeling, and risk assessments
- Knowledge of application security issues (OWASP Top 10)
Desirable:
- Professional security qualifications (CISSP, Offensive Security, SANS Institute)
- Contributions to the security community (public research, blogging, presentations)
- Awareness and experience with Data Protection Act, ISO 27001, and PCI-DSS