# Senior Security Engineer

[Abound](https://gurify.com/jobs?q=Abound) · London · Posted 4 months ago

Senior

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://jobs.ashbyhq.com/Abound/a0764a3a-f53a-4ad2-9502-b6d471361b0d)

## Job description

### About Abound

We’re redefining consumer lending in the UK, and beyond. Using advanced AI and Open Banking data, we make fair, affordable personal finance available to more people. While traditional lenders rely almost entirely on credit scores, we look at the full financial picture - how much you spend, and what you can afford to repay to build a deeper, more accurate understanding of each customer's unique financial situation.

And we've shown it works at scale. We’ve issued over £1.3bn in loans directly to customers while delivering market-leading credit performance - for every 10 defaults the industry expects, we see only 3. We also reached profitability just 2.5 years after launch.

Backed by £2bn+ of funding from top-tier investors including Citi, GSR Ventures, and Deutsche Bank, we’re recognised as one of Europe’s fastest-growing fintechs (Sifted, CNBC). Now, we’re expanding into new markets and product lines - and we’re looking for ambitious people who want to learn fast, take ownership, and grow with us.

### About the role:

You won't be sitting in an ivory tower throwing policies over the fence. You will be embedded directly within our Platform team in a true DevSecOps capacity. Operating as a highly technical individual contributor, you will bridge the gap between product-led engineering and Corporate IT.

You will play a hands-on role in challenging the security architecture of production and corporate IT infrastructure.

In your first 6–12 months, you will design and implement our next-generation cloud security architecture across AWS and GCP, while helping to build and mature our internal SOC capabilities, including detection and response.

You will take ownership of Microsoft Sentinel, enhancing our SIEM/SOAR capabilities, and strengthen identity and access management through improved and automated RBAC across AWS, Microsoft Entra, and internal systems.

You will also drive a shift-left approach to security by embedding controls into GitLab CI/CD pipelines, including scanning, IaC reviews, and automated policy enforcement across the SDLC.

### Our technology stack:

Cloud & Compute: AWS, ECS Fargate, Aurora, Lambda, GCP
Data Lake: S3, DMS, Glue
Cloud Security Tooling: GuardDuty, Security Hub, Inspector, Security Command Center
Code & IaC: Python, Java, GitLab, AWS CDK, Terraform/CDK-TF
Observability & Incident Management: AMP, Incident.io

### Who you are:

- You are a security professional by trade, but a hacker by design. You have a strong track record in DevSecOps and cloud security engineering, with hands-on experience elevating the security posture of other organisations.

- You are a strong Python developer. You know how to script automation, interact with APIs, and build security tooling from scratch.

- You possess a rock-solid understanding of network security fundamentals and how they apply to modern, distributed cloud architectures.

- You are comfortable owning both the build and run aspects of security—designing systems and responding to incidents.

- You thrive in the dynamic, ambiguous, and fast-paced environment of a high-growth startup. You know how to balance rigorous security with engineering velocity.

### What you'll be doing:

- Actively contribute infrastructure-as-Code (AWS CDK, Terraform) for security risks prior to deployment

- Implement best practice network security across AWS and GCP (IAM, VPCs, encryption, logging, monitoring)

- Embed zero-trust policies across the estate

- Actively challenge the security standards of production applications and infrastructure

- Embed security controls into CI/CD pipelines (SAST, dependency scanning, container security)

- Partner with engineering teams on secure architecture and deployment patterns

- Support secure SDLC practices and pre-deployment security reviews

### What we offer

- Everyone owns a piece of the company - equity

- Hybrid with 3 days a week in the office

- 25 days’ holiday a year, plus 8 bank holidays

- 2 paid volunteering days per year

- One month paid sabbatical after 4 years

- Employee loan

- Free gym membership

- Team wellness budget to be active together - set up a yoga class, a tennis lesson or go bouldering

**Live in Abound’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- IN [Senior Infrastructure and Cloud Security Engineer (m/f/d)](https://gurify.com/job/senior-infrastructure-and-cloud-security-engineer-m-f-d-at-3f7722b49cef) Internationalcopyrightenterpriseservices · London · 3 days ago
- CO [Security Engineer](https://gurify.com/job/security-engineer-at-conduct-354c5d006329) Conduct · London, United Kingdom · last week
- HA [Senior Security Engineer, Detection and Response](https://gurify.com/job/senior-security-engineer-detection-and-response-at-hackerone-45f09130ce13) Hackerone · London · last week
- CO [Cloud Native Security Engineer](https://gurify.com/job/cloud-native-security-engineer-at-controlplane-7b45fcfb1a4d) Controlplane · London · 6 days ago
- WR [Security engineer, detection and response (UK)](https://gurify.com/job/security-engineer-detection-and-response-uk-at-writer-f0528fa67725) Writer · London, United Kingdom · 2 weeks ago
- CC [Cyber Security Engineer I](https://gurify.com/job/cyber-security-engineer-i-at-checkout-com-b3744d8ed0a5) Checkout Com · London · 2 weeks ago

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Senior Security Engineer","description":"\u003Ch3\u003EAbout Abound\u003C/h3\u003E\u003Cp\u003EWe\u2019re redefining consumer lending in the UK, and beyond. Using advanced AI and Open Banking data, we make fair, affordable personal finance available to more people. While traditional lenders rely almost entirely on credit scores, we look at the full financial picture - how much you spend, and what you can afford to repay to build a deeper, more accurate understanding of each customer\u0026#39;s unique financial situation.\u003C/p\u003E\u003Cp\u003EAnd we\u0026#39;ve shown it works at scale. We\u2019ve issued over \u0026#163;1.3bn in loans directly to customers while delivering market-leading credit performance - for every 10 defaults the industry expects, we see only 3. We also reached profitability just 2.5 years after launch.\u003C/p\u003E\u003Cp\u003EBacked by \u0026#163;2bn\u002B of funding from top-tier investors including Citi, GSR Ventures, and Deutsche Bank, we\u2019re recognised as one of Europe\u2019s fastest-growing fintechs (Sifted, CNBC). Now, we\u2019re expanding into new markets and product lines - and we\u2019re looking for ambitious people who want to learn fast, take ownership, and grow with us.\u003C/p\u003E\u003Ch3\u003EAbout the role:\u003C/h3\u003E\u003Cp\u003EYou won\u0026#39;t be sitting in an ivory tower throwing policies over the fence. You will be embedded directly within our Platform team in a true DevSecOps capacity. Operating as a highly technical individual contributor, you will bridge the gap between product-led engineering and Corporate IT.\u003C/p\u003E\u003Cp\u003EYou will play a hands-on role in challenging the security architecture of production and corporate IT infrastructure.\u003C/p\u003E\u003Cp\u003EIn your first 6\u201312 months, you will design and implement our next-generation cloud security architecture across AWS and GCP, while helping to build and mature our internal SOC capabilities, including detection and response.\u003C/p\u003E\u003Cp\u003EYou will take ownership of Microsoft Sentinel, enhancing our SIEM/SOAR capabilities, and strengthen identity and access management through improved and automated RBAC across AWS, Microsoft Entra, and internal systems.\u003C/p\u003E\u003Cp\u003EYou will also drive a shift-left approach to security by embedding controls into GitLab CI/CD pipelines, including scanning, IaC reviews, and automated policy enforcement across the SDLC.\u003C/p\u003E\u003Ch3\u003EOur technology stack:\u003C/h3\u003E\u003Cp\u003ECloud \u0026amp; Compute: AWS, ECS Fargate, Aurora, Lambda, GCP\u003Cbr /\u003EData Lake: S3, DMS, Glue\u003Cbr /\u003ECloud Security Tooling: GuardDuty, Security Hub, Inspector, Security Command Center\u003Cbr /\u003ECode \u0026amp; IaC: Python, Java, GitLab, AWS CDK, Terraform/CDK-TF\u003Cbr /\u003EObservability \u0026amp; Incident Management: AMP, Incident.io\u003C/p\u003E\u003Ch3\u003EWho you are:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EYou are a security professional by trade, but a hacker by design. You have a strong track record in DevSecOps and cloud security engineering, with hands-on experience elevating the security posture of other organisations.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYou are a strong Python developer. You know how to script automation, interact with APIs, and build security tooling from scratch.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYou possess a rock-solid understanding of network security fundamentals and how they apply to modern, distributed cloud architectures.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYou are comfortable owning both the build and run aspects of security\u2014designing systems and responding to incidents.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYou thrive in the dynamic, ambiguous, and fast-paced environment of a high-growth startup. You know how to balance rigorous security with engineering velocity.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EWhat you\u0026#39;ll be doing:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EActively contribute infrastructure-as-Code (AWS CDK, Terraform) for security risks prior to deployment\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EImplement best practice network security across AWS and GCP (IAM, VPCs, encryption, logging, monitoring)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EEmbed zero-trust policies across the estate\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EActively challenge the security standards of production applications and infrastructure\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EEmbed security controls into CI/CD pipelines (SAST, dependency scanning, container security)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPartner with engineering teams on secure architecture and deployment patterns\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESupport secure SDLC practices and pre-deployment security reviews\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EWhat we offer\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EEveryone owns a piece of the company - equity\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHybrid with 3 days a week in the office\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003E25 days\u2019 holiday a year, plus 8 bank holidays\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003E2 paid volunteering days per year\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EOne month paid sabbatical after 4 years\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EEmployee loan\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFree gym membership\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ETeam wellness budget to be active together - set up a yoga class, a tennis lesson or go bouldering\u003C/li\u003E\u003C/ul\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"senior-security-engineer-at-abound-96df7e278dc8"},"url":"https://gurify.com/job/senior-security-engineer-at-abound-96df7e278dc8","datePosted":"2026-04-24","validThrough":"2026-11-04T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Abound","sameAs":"https://jobs.ashbyhq.com/Abound"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"GB","addressLocality":"London"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"United Kingdom","item":"https://gurify.com/jobs/united-kingdom"},{"@type":"ListItem","position":3,"name":"Senior Security Engineer","item":"https://gurify.com/job/senior-security-engineer-at-abound-96df7e278dc8"}]}
```
