SlipstreamJobsFresh Startup & VC-Backed Jobs

Application Security Engineer

Thought Machine - Lisbon, Portugal - Hybrid - posted 2026-09-24

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Thought Machine is building modern banking technology to replace legacy systems at scale. The company has raised over £500m from top-tier investors including JPMorgan Chase, Standard Chartered, and Temasek, and operates offices across London, New York, Singapore, Sydney, and Lisbon. As an Application Security Engineer, you will play a leading role in protecting Thought Machine's product against security risks and implementing cutting-edge security measures. This is a greenfield challenge—the company is building next-generation banking infrastructure with modern web technology, requiring custom security solutions beyond off-the-shelf frameworks. You will drive improvements to the product security posture through strategic planning and cross-functional collaboration with development and infrastructure teams. Key responsibilities include: - Produce production web-scale application security designs - Review and produce data privacy and financial regulatory functional and nonfunctional designs - Perform design reviews and threat modeling of services and products - Conduct vulnerability assessments and security testing - Provide subject matter expertise on security and privacy throughout the software development lifecycle - Liaison with development teams for design, code reviews, and security education - Contribute to security strategy, tooling selection, and creation - Conduct regular security assessments and code reviews The ideal candidate has experience with OWASP top 10 vulnerabilities, DevSecOps, data privacy protection, and a passion for mentoring developers. You should demonstrate creativity, autonomy, and the ability to manage multiple projects simultaneously. This is a full-time, permanent position based in the Lisbon office, requiring four days per week onsite. REQUIREMENTS Essential: - Expertise with a programming language (Python, Go, or Java) - Experience with security in a DevOps environment - Experience in web application penetration testing and security tooling (Burp proxy, Web/Network Scanners, Static code analyzers, etc.) - Coding experience for automating/integrating security tools and creation of security tools - Knowledge of security in distributed systems at scale - Cloud and containers technology knowledge (AWS, GCP, Kubernetes, Docker) - Experience performing security design reviews, threat modeling, and risk assessments - Knowledge of application security issues Desirable: - Professional security qualifications (CISSP, Offensive Security, SANS Institute, etc.) - Contributions to the security community (public research, blogging, presentations) - Awareness and experience with Data Protection Act, ISO 27001, and PCI-DSS

Similar roles