SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Thought Machine is a fintech company on a mission to modernize banking by replacing legacy technology with cloud-native core and payments systems. The company has raised over £500m, operates across London, New York, Singapore, Sydney, and Lisbon, and employs 550+ people. It has been recognized as one of Europe's fastest-growing companies and a UK Best Employer for 2026.
The Security Control Engineer role is based in the Lisbon office (4 days/week onsite) and sits within the Security Control Engineering team. This team designs and implements technical and operational security solutions aligned with Thought Machine's standards, risk assessments, and client/regulatory requirements—ensuring compliance with ISO27001, ISO22301, PCI-DSS, and SOC 2 Type 2.
Key responsibilities:
1. Control Design & Implementation: Participate in the technical and operational design and implementation of security capabilities, tools, and procedures to mitigate security and business continuity risks. Provide process and technical expertise in product security, operational security, and business continuity/disaster recovery planning.
2. Continuous Control Assurance: Develop and implement effective methods (tools, processes) for continuous audits and evidence collection for certification renewals (ISO27001, ISO22301, PCI-DSS, SOC 2 Type 2). Design capabilities and procedures that satisfy these regulatory regimens.
3. Client Support: Respond to client queries about Thought Machine's technical security approach. Develop and present materials that communicate the security posture with technical accuracy and sufficient detail.
4. ISMS and BCMS Stewardship: Keep security and business continuity approaches current by incorporating new threats, technical advances, and standards. Maintain standards, controls, and plans in alignment with Thought Machine and client needs, and technology stack changes.
The role requires strong technical reasoning about complex security problems in distributed cloud and on-premise environments, and the ability to communicate trade-offs between security approaches to internal teams and clients.
REQUIREMENTS
Essential:
- Experience designing and implementing technical solutions to deliver security controls and capabilities in cloud-based infrastructure (AWS, GCP).
- Experience working directly with software engineering teams to design technical solutions meeting security requirements in products.
- Experience with control automation via code (Python, Go).
- Strong technical background with experience in distributed systems, cloud security, and related technologies; passion for creative solutions to difficult problems.
- Knowledge of threat modelling for understanding threat probabilities and frequency.
- Excellent communication skills with ability to translate technical/security jargon into business-relevant insights.
- Ability to collaborate effectively with other departments and external stakeholders.
Desirable:
- Experience in fast-paced tech or fintech environments.
- Knowledge of container security, Kubernetes, Kafka, and emergent technologies.
- Experience obtaining and maintaining security certifications (SOC 2, ISO 27001, PCI-DSS).
- Proficiency leading security risk assessments, preferably with FAIR framework knowledge.