> Markdown version of [/jobs/ext/2461724-security-engineer](https://www.wearedevelopers.com/jobs/ext/2461724-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** LemFi - **Location:** London, UK - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Microsoft Azure, Software as a Service, Cloud Computing Security, Cyber Security, Information Leak Prevention, Identity and Access Management, Nagios, PCI Data Security Standards, Security Information and Event Management, Software Vulnerability Management, Scripting, Stack Overflow, Restful APIs, Vulnerability Analysis - **Published:** August 11, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=6c72bd94918033f7 ## About the Role * 2 to 5 years in a security engineering, security operations, or equivalent hands-on technical security role, ideally in fintech, payments, or another regulated industry. * Practical experience across at least some of: cloud security (AWS, Azure, or GCP), endpoint and MDM tooling, DLP platforms, identity and access management, and SIEM or alerting tools. * Scripting ability sufficient to automate workflows and integrate with REST APIs - you write the script, you don't just find it on Stack Overflow. * Working knowledge of at least one major compliance framework (SOC 2, ISO 27001, PCI DSS, or DORA); direct audit-support experience is a strong plus. * A clear written communicator who can produce control narratives, incident summaries, and stakeholder-facing documentation that non-technical people actually understand. * Comfortable with ambiguity and able to shift between hands-on engineering work and compliance or documentation in the same week without losing momentum., * Experience operating or running a Bug Bounty or Vulnerability Disclosure programme. * Exposure to building or contributing to a Security Trust Centre or external-facing security documentation. * Familiarity with DORA (Digital Operational Resilience Act) requirements in a practical, implementation context. ## Description LemFi is building the financial infrastructure for people the world wasn't built to serve - cross-border payments, multi-currency accounts, savings, credit, and eSIMs across 21 countries and growing. Security is not a checkbox here; it is a core part of how we earn trust with customers, regulators, and partners in some of the most scrutinised payment corridors in the world. This role sits at the intersection of security engineering, operations, and compliance. You will monitor and respond to real threats, extend our DLP and identity controls, run vulnerability management, and translate audit requirements (SOC 2, ISO 27001, PCI DSS, DORA) into working technical controls. One day you might be triaging a researcher submission through our Bug Bounty programme; the next you are scripting an automated compliance check or briefing a board-level vulnerability report. If you want to own a broad, meaningful security remit at a fast-scaling fintech rather than a narrow lane at a large bank, this is the role., * Monitor, triage, and respond to security alerts and incidents across cloud, endpoint, and SaaS environments - keeping detection tooling sharp and well-tuned. * Own and extend our Data Loss Prevention controls: policy tuning, coverage gap analysis, and coordinating endpoint rollout across the business. * Manage device compliance and identity workflows via MDM platforms, including scripting for group management, provisioning, and reporting through REST APIs. * Run vulnerability scanning and remediation tracking, and contribute to board-level reporting that gives leadership a clear, honest picture of risk. * Translate SOC 2, ISO 27001, PCI DSS, and DORA requirements into working technical controls, evidence collection processes, and automated compliance checks - and support external auditor engagements directly. * Operate LemFi's Bug Bounty and Responsible Disclosure programme: triage researcher submissions and coordinate remediation with engineering teams. * Build scripts and lightweight tools to cut manual security operations work, improve audit evidence quality, and use AI to accelerate wherever it adds genuine value. ## Related Videos - [Rest API Antipatterns](https://www.wearedevelopers.com/videos/100208-rest-api-antipatterns) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [REST In Peace: Why LLMs Can't CRUD](https://www.wearedevelopers.com/videos/100272-rest-in-peace-why-llms-can-t-crud) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london)