Application Security Engineer
FinUK3w ago
Job description
About the role
Fin is seeking an experienced application security engineer to join our security team based in London, England. This role involves working closely with product development teams to embed security practices into the design and deployment of our AI-powered customer service tools. You will be responsible for building and maintaining critical security services that ensure the safety and integrity of our systems and customer data. The position emphasizes designing secure architectures, automating security defenses, and proactively protecting our global customer base from evolving threats. As part of the team, you will play a key role in shaping security standards and fostering a security-first culture across the organization.
Key facts
What you'll do
- Engineer, develop, and maintain tier-zero security services, including authentication systems, SAML/SSO integrations, audit logging, and malicious URL scanning to protect user access and detect malicious activities.
- Conduct architecture reviews, threat modeling exercises, and comprehensive security assessments for new product features and updates to identify vulnerabilities early in the development lifecycle.
- Develop and implement security tooling and automation solutions to support scalable, repeatable, and effective security practices across the engineering organization.
- Lead security incident response efforts, including investigation, remediation, and post-incident analysis, as part of a shared on-call rotation to ensure rapid response to security events.
- Collaborate with engineering teams to evaluate risks associated with AI-powered products, including large language models, retrieval-based architectures, and agentic systems, ensuring security considerations are integrated into product design.
- Establish and promote secure development standards, guidelines, and best practices across the company, providing training and guidance to engineering teams to foster a security-aware culture.
- Support the adoption and integration of AI-assisted development tools and workflows, ensuring security is maintained as teams new AI capabilities.
- Partner with product managers and engineers to embed security controls into the development lifecycle, from initial design through deployment and maintenance.
- Monitor security controls and defenses continuously, identifying areas for improvement and implementing updates to address emerging threats.
- Provide security expertise during product launches, updates, and incident investigations, ensuring compliance with security policies and standards.
- Assist in the development of security metrics and reporting to track the effectiveness of security initiatives and communicate risks to senior management.
- Stay current with the latest security threats, trends, and best practices, and apply this knowledge to improve the organization's security posture.
Requirements
- Proven experience in application security, product security, or security engineering within a SaaS environment, with a track record of implementing security solutions at scale.
- Strong software engineering background, with experience in building, deploying, and maintaining production systems in a fast-paced environment.
- Deep understanding of modern application security threats, including common attack vectors, secure coding practices, and threat modeling methodologies.
- Experience designing, implementing, or securing identity and access management systems, especially SAML/SSO protocols.
- Hands-on experience leading security incident response efforts, including investigation, containment, and remediation of security breaches.
- Proficiency in programming languages and developing security tools tailored for developers and operations teams.
- Excellent communication skills, with the ability to explain complex security concepts clearly to engineering teams and non-technical stakeholders.
- Ability to work collaboratively across teams, influencing security practices and fostering a security-first mindset.
- Knowledge of cloud security principles, infrastructure security, and distributed systems architecture.
- Familiarity with security automation, scripting, and tooling to support scalable security operations.
- Experience working in high-growth companies or startups, with the agility to adapt security practices to rapidly changing environments.
Nice to have
- Direct experience managing authentication systems, including SAML/SSO, OAuth, or other access management solutions.
- Background in securing AI-powered products, such as large language models, retrieval-based architectures, or agentic systems.
- Experience developing security automation tools and processes at scale to improve efficiency and coverage.
- Knowledge of cloud security best practices across platforms like AWS, Azure, or GCP.
- Familiarity with infrastructure security, container security, and microservices architectures.
- Prior experience working in both startup and large-scale SaaS environments, understanding different organizational security needs.
Skills & tools
- Application Security
- Product Security
- Threat Modeling
- Authentication and Identity Management (SAML/SSO)
- Security Automation
- Incident Response
- AI-assisted development tools
Practical notes
- The role offers a competitive salary package complemented by equity options, with regular performance reviews to recognize contributions.
- Benefits include comprehensive health and dental insurance coverage for employees and their dependents, life assurance, and a pension scheme with up to 4% employer matching contributions.
- The company provides daily catered lunches, a fully stocked kitchen, and flexible paid time off policies to support work-life balance.
- Parental leave policies include paid maternity leave and six weeks of paternity leave, supporting employees during important life events.
- Hardware is typically a MacBook, with Windows options available for specific roles or preferences.
- The organization maintains a neutral stance on social and political topics, fostering a focused and inclusive work environment.
- The company encourages continuous learning and professional development, providing opportunities to stay current with evolving security practices and technologies.