Staff Security Engineer, Thredd

Salary not provided
AWS
Python
Bash
Powershell
Senior and Expert level
London

More information about location

Thredd

Issuer processing partner

Open for applications

Thredd

Issuer processing partner

201-500 employees

FintechB2BPaymentsFinancial ServicesSaaS

Open for applications

Salary not provided
AWS
Python
Bash
Powershell
Senior and Expert level
London

More information about location

201-500 employees

FintechB2BPaymentsFinancial ServicesSaaS

Company mission

To transform the world through true partnerships and smart payments to revolutionise the future of finance, together.

Role

Who you are

  • Prior experience as cloud security engineer or equivalent within the financial services industry
  • In-depth knowledge of cloud security architecture, best practices, and frameworks (e.g., NIST, CSA, CIS)
  • Experience with security automation, orchestration, and DevSecOps practices
  • Must have in depth exposure to EKS
  • Proficiency in scripting and programming languages (e.g., Python, PowerShell, Bash) for security automation
  • Strong understanding of encryption technologies, identity and access management (IAM), and network security in cloud environments
  • Familiarity with compliance frameworks applicable to the financial services industry (e.g., PCI-DSS, SOX)

What the job involves

  • Thredd is looking for a Staff Security Engineer to join our team! As our Staff Security Engineer, you'll collaborate with Thredd Platform Delivery and InfoSec teams to design secure environments for core production services
  • You'll integrate DevSecOps principles, automate security processes like secret and container scanning, and enhance vulnerability management and threat modeling
  • Serving as both a subject matter expert and hands-on engineer, you'll improve Thredd's security posture, maintain security pipelines, and increase cybersecurity awareness by sharing insights and implementing effective controls
  • Leads technical projects by incorporating client requirements, aligning designs with client needs, and ensuring feedback integration for a client-first approach
  • Develops and maintains security documentation, including architecture diagrams, enhances engineering workflows with data solutions, and establishes robust reporting mechanisms to track performance and outcomes
  • Stay updated on the latest engineering trends and best practices, leveraging insights to influence projects and enhance organizational capabilities through engagement with industry professionals
  • Recommends and implements cloud security best practices, such as CIS Benchmarks, manages security monitoring and incident handling, mentors team members in adopting new technologies and methodologies, and designs scalable engineering solutions that meet both technical and client requirements
  • Prioritizes security tool outputs, develops tactical plans for engineering projects, manages resource allocation, and ensures timely delivery by aligning project timelines with broader engineering objectives
  • Demonstrates advanced technical expertise in multiple domains, leads technical initiatives, contributes to product strategy discussions, and drives the adoption of best practices across engineering teams
  • Implement secure cloud architectures for AWS environments, drives cybersecurity practices like vulnerability management and threat modeling, ensures compliance with regulatory requirements (e.g., PCI-DSS, SOX), and fosters a culture of quality within the engineering team
  • Automate security tasks using modern tools and scripting to improve security posture, streamlines cloud security operations with Cloud SecOps practices, and protects revenue through robust cloud security measures
  • Automate security validation within CI pipelines, including secret scanning and compliance checks, supports multi-cloud design (IaaS, PaaS, SaaS) and hybrid approaches for secure access across co-located and cloud workloads, and contributes to the technical vision by evaluating engineering strategies that align with organizational goals and market demand

Salary benchmarks

Share this job

View 13 more jobs at Thredd

Insights

-7% employee growth in 12 months

Company

Company benefits

  • 25 Days annual leave
  • Option to buy 5 days annual leave
  • Pension scheme
  • Private Medical
  • Life Insurance
  • Green Car Scheme
  • SmartTech
  • Volunteer time
  • Season Ticket Loan
  • Cycle to work Scheme
  • Long Service Awards
  • Retail Discounts
  • Tax-Free Childcare Vouchers
  • Flu Vaccinations
  • Flexible benefits (Better you fund, Revitalise you Fund, Money Coach, Expanded Private Medical, Critical Illness)

Funding (last 2 of 3 rounds)

Jan 2022

$100m

LATE VC

Oct 2021

$300m

LATE VC

Total funding: $449.9m

Our take

Embedded banking, or Banking-as-a-Service, has been a major driver of the fintech explosion. It allows challengers and smaller players to rapidly incorporate novel financial products and infrastructure without building from scratch - and major players to keep pace with increasing consumer demand for fintech services. Thredd (formerly Global Processing Services) focuses on paytech, with a tranche of services including major areas like payments, wallets, fraud prevention, and crypto management.

This diverse offering across high-growth fintech sectors has helped Thredd draw in hefty funding, and key clients across the key fintech markets of Europe, Asia-Pacific, and the Middle East, including Revolut, Curve, Cape, and Starling Bank.

This shows quite how far Thredd has managed to capture significant market penetration, which has given it the resources to continue building out key new products. With more non-fintech businesses looking to leverage the benefits of embedded banking, this could see Thredd expand into further markets such as insurance and loans. Certainly, Thredd has both the momentum and the valuation to take the plunge into other lucrative verticals.

Freddie headshot

Freddie

Company Specialist at Welcome to the Jungle