Senior Security Engineer LocationLondon; London OfficeEmployment TypeFull timeLocation TypeHybridDepartmentEngineeringWhat is Flagstone?Flagstone is many things. An online savings platform, reinventing how individuals, businesses, and charities manage, protect, and grow their cash. A diverse group of people, bound by a collaborative spirit, and shared purpose. And lastly, a thriving, profitable business – where smart people do their best work.Each definition shares a common thread: our unique culture. It’s our pride and joy. And our competitive advantage.A feel for our culture:To revolutionise the savings market, we need to be at our best. But high performance takes more than talent – it takes a culture of kindness, respect, and growth.That’s why we’re building a diverse, inclusive community, where your voice is heard and valued. Where, with close support and room to develop, you can surpass even your own expectations. And be rewarded for it.We may not change the world, but we can change the world of financial technology. And all it takes is a winning mix of drive, talent, and empathy. Our culture celebrates all three.But enough about us. Let’s talk about you.About the TeamSecurity Engineering is a team of five covering cloud security, detection, and security operations. They work directly in the Azure estate and are close to the infrastructure, not abstracted behind a policy layer. The team runs Microsoft Sentinel, Defender XDR, and Defender for Cloud, and manages tooling through IaC. They run a quarterly penetration test programme and are continuously building out our detection and response capability. It's a small team with broad scope, which means your work is visible, your opinions are heard, and there are meaningful problems for our engineers to work on.Does this sound like you:You're a Senior Security Engineer who operates credibly across cloud security, detection tooling, and incident response, without being narrowly specialised. You own meaningful parts of the security stack, contribute hands on to Azure cloud hardening, and show up reliably when incidents need investigating or pen test cycles need coordinating. You're energised by visible impact, your work matters and your voice is heard.What you’ll do:Maintain and improve our Microsoft Sentinel deployment - writing and tuning detection rules, managing data connectors, and reducing alert noiseOperate and optimise Defender XDR and Defender for Cloud, including policy management and posture recommendationsHarden our Azure environment across identity, access management, networking, storage, WAF configuration, and logging pipelinesContribute to infrastructure-as-code (Terraform or Bicep) for security tooling deployments and configuration drift managementInvestigate suspicious activity surfaced through Sentinel and Defender - triage, escalate, or contain as appropriateSupport incident response activities including containment, evidence gathering, and post-incident reviewParticipate in security risk assessments and threat modelling exercises across new and existing systemsCoordinate penetration test engagements (scope, logistics, findings review) and work with engineering teams to prioritise remediationWhat we’re looking for Hands-on SIEM experience, ideally Microsoft Sentinel; equivalent platforms (Splunk, Chronicle, QRadar) consideredPractical Azure security experience across Defender for Cloud, Entra ID, Azure networking, and cloud security posture managementExperience writing infrastructure-as-code using Terraform or Bicep in a security engineering contextAbility to contribute to threat modelling and communicate security risk clearly to engineering and product audiencesExperience supporting or coordinating penetration testing programmes, including managing remediation cyclesFamiliarity with AI security considerations (securing AI workloads, data exposure risks) and/or using AI tooling to augment security engineering workflowsA growth mindset and genuine curiosity to...
Want jobs like this matched to you?
Swoopd scores fresh postings against your résumé so you only see the matches that matter.