SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Application Security Engineer

Thought Machine - Lisbon, Portugal - Hybrid - posted 2026-09-30

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Thought Machine is building modern banking technology to replace legacy systems in banks worldwide. The company has raised over £500m from top-tier investors including JPMorgan Chase, Standard Chartered, and Temasek, and operates offices in London, New York, Singapore, Sydney, and Lisbon with 550+ employees. As Senior Application Security Engineer, you will lead product security initiatives across Thought Machine's cloud-native banking platform. This is a greenfield security challenge—the company is building next-generation banking infrastructure with cutting-edge web technology, requiring custom security solutions beyond off-the-shelf frameworks. You will drive strategic improvements to the product security posture through cross-functional collaboration with development and infrastructure teams. Key responsibilities include: designing production web-scale application security architecture; reviewing and producing data privacy and financial regulatory designs; performing design reviews and threat modeling of services and products; conducting vulnerability assessments and security testing; providing subject matter expertise throughout the software development lifecycle; liaising with development teams on design, code reviews, and security education; contributing to security strategy and tooling selection; and conducting regular security assessments and code reviews. The role requires deep technical expertise, autonomy, and the ability to mentor engineers on security best practices. You will influence architectural decisions and work on multiple complex projects simultaneously in a fast-growing fintech environment. This is a full-time, permanent position based in the Lisbon office, requiring four days per week onsite. REQUIREMENTS Essential: - Expertise with a programming language (Python, Go, or Java) - Experience with security in DevOps environments - Experience in web application penetration testing and security tooling (Burp proxy, web/network scanners, static code analyzers) - Coding experience for automating/integrating security tools and creating security tools - Knowledge of security in distributed systems at scale - Cloud and containers technology knowledge (AWS, GCP, Kubernetes, Docker) - Experience performing security design reviews, threat modeling, and risk assessments - Knowledge of application security issues (OWASP top 10 vulnerabilities) Desirable: - Professional security qualifications (CISSP, Offensive Security, SANS Institute) - Contributions to the security community (public research, blogging, presentations) - Awareness and experience with Data Protection Act, ISO 27001, and PCI-DSS

Similar roles