SlipstreamJobsFresh Startup & VC-Backed Jobs

Application Security Engineer

Thought Machine - Lisbon, Portugal - Hybrid - posted 2026-09-24

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Thought Machine is building modern banking technology to replace legacy systems at global banks. The company has raised over £500m from top-tier investors including JPMorgan Chase, Standard Chartered, and Temasek, and operates offices in London, New York, Singapore, Sydney, and Lisbon. As an Application Security Engineer, you will play a leading role in protecting Thought Machine's product against security risks and implementing cutting-edge security measures. This is a greenfield challenge—the company is building next-generation banking infrastructure with cloud-native technology, requiring custom security solutions beyond off-the-shelf frameworks. You will drive improvements to the product security posture through strategic planning and cross-functional collaboration with development and infrastructure teams. Key responsibilities include: - Produce production web-scale application security designs - Review and produce data privacy and financial regulatory designs - Perform design reviews and threat modeling of services and products - Conduct vulnerability assessments and security testing - Provide subject matter expertise across the software development lifecycle - Liaison with development teams on design, code reviews, and security education - Contribute to security strategy and tooling selection - Conduct regular security assessments and code reviews You will have autonomy, trust, and influence to engage cross-functionally. The ideal candidate combines technical depth with mentoring ability, creativity, and the capacity to manage multiple projects simultaneously. This is a full-time, permanent position based in the Lisbon office, requiring four days per week onsite. **Requirements** Essential: - Expertise with a programming language (Python, Go, or Java) - Experience with security in DevOps environments - Web application penetration testing and security tooling experience (Burp proxy, Web/Network Scanners, Static code analyzers) - Coding experience for automating/integrating security tools and creating security tools - Knowledge of security in distributed systems at scale - Cloud and containers technology knowledge (AWS, GCP, Kubernetes, Docker) - Experience performing security design reviews, threat modeling, and risk assessments - Knowledge of application security issues and OWASP top 10 vulnerabilities Desirable: - Professional security qualifications (CISSP, Offensive Security, SANS Institute) - Contributions to the security community (public research, blogging, presentations) - Awareness and experience with Data Protection Act, ISO 27001, and PCI-DSS

Similar roles