• Be embedded directly within the Platform team in a true DevSecOps capacity as a highly technical individual contributor, bridging the gap between product-led engineering and Corporate IT.
• Play a hands-on role in challenging the security architecture of production and corporate IT infrastructure.
• Design and implement the next-generation cloud security architecture across AWS and GCP while helping to build and mature internal SOC capabilities including detection and response.
📋 Job Requirements
• Be a security professional by trade with a strong track record in DevSecOps and cloud security engineering, with hands-on experience elevating the security posture of other organisations.
• Be a strong Python developer who knows how to script automation, interact with APIs, and build security tooling from scratch.
• Possess a rock-solid understanding of network security fundamentals and how they apply to modern, distributed cloud architectures.
• Be comfortable owning both the build and run aspects of security, designing systems and responding to incidents.
• Thrive in the dynamic, ambiguous, and fast-paced environment of a high-growth startup, knowing how to balance rigorous security with engineering velocity.
🌟 Nice-to-have
• Have experience with Microsoft Sentinel and SIEM/SOAR capabilities.
• Bring experience with AWS security tooling such as GuardDuty, Security Hub, and Inspector.
• Have experience implementing zero-trust policies across a cloud estate.
• Have hands-on experience with AWS CDK and Terraform/CDK-TF for infrastructure-as-code security reviews.
• Have experience working in a fintech or regulated environment.
• Have experience with GCP Security Command Center.
🎯 Responsibilities
• Actively contribute infrastructure-as-code using AWS CDK and Terraform for security reviews prior to deployment.
• Implement best-practice network security across AWS and GCP including IAM, VPCs, encryption, logging, and monitoring.
• Embed zero-trust policies across the estate.
• Actively challenge the security standards of production applications and infrastructure.
• Embed security controls into CI/CD pipelines including SAST, dependency scanning, and container security.
• Partner with engineering teams on secure architecture and deployment patterns.
• Support secure SDLC practices and pre-deployment security reviews.
• Take ownership of Microsoft Sentinel, enhancing SIEM/SOAR capabilities.
• Strengthen identity and access management through improved and automated RBAC across AWS, Microsoft Entra, and internal systems.
• Drive a shift-left approach to security by embedding controls into GitLab CI/CD pipelines including scanning, IaC reviews, and automated policy enforcement across the SDLC.
Abound is one of the most exciting fintech stories in the UK right now. In just five years, the co-founders have built a profitable, fast-growing lending platform that was named the UK's number one fastest-growing tech company by The Sunday Times in 2026, with nearly 500% annual revenue growth. The company generated £69 million in revenue and £9 million in profit before tax in 2024, which is remarkable given that, among the top 15 high-growth UK companies tracked by Sifted, Abound was the only profitable one. They have secured £2.2 billion in lending capacity from Citi, Deutsche Bank, Waterfall, and others, and have been listed among the top 250 global fintechs by CNBC. What makes Abound especially interesting as a place to work is the leadership pedigree: Gerald Chappell was previously a Partner at McKinsey and EY, where he led digital lending and credit analytics solutions globally, while Dr Michelle He was a Director at EY with a PhD in machine learning. The broader leadership team brings experience from Goldman Sachs, Citi, Airbnb, and other major institutions. The UK Glassdoor entity sits at 4.6/5, with every single employee recommending it to a friend. What comes through in reviews is the flat structure, data-driven culture, quick career progression, and the chance to learn directly from seriously experienced leaders. Everyone gets equity ownership, a 30-day paid sabbatical after 4 years, a free WellHub membership, and plenty of team socials. A couple of things worth knowing: some Glassdoor reviews flag high targets and performance pressure, and Abound runs a hybrid model from its London offices rather than being fully remote. That said, if you want to be part of a profitable, rapidly scaling UK fintech where your work has a real impact on making credit fairer for millions of people, Abound is a brilliant place to do it.
😃 What Abound offers
• Receive equity ownership in the company.
• Work hybrid with 3 days a week in the London office.
• Receive 25 days holiday a year plus 8 bank holidays.
• Take 2 paid volunteering days per year.
• Receive one month paid sabbatical after 4 years.
• Access an employee loan benefit.
• Receive free gym membership.
• Enjoy a team wellness budget for group activities.
💖 What makes Abound unique
Abound is redefining consumer lending in the UK and beyond using advanced AI and Open Banking data to make fair, affordable personal finance available to more people. Rather than relying almost entirely on credit scores, Abound looks at the full financial picture to build a deeper understanding of each customer's situation. Having issued over £1.3bn in loans directly to customers with market-leading credit performance, the company reached profitability just 2.5 years after launch. Backed by £2bn+ of funding from investors including Citi, GSR Ventures, and Deutsche Bank, Abound is recognised as one of Europe's fastest-growing fintechs.
💬 What employees say
"Fast-growing, highly ambitious company with a management team that truly understands the industry. Strong focus on innovation, technology, data, and automation. Friendly place to work with no office politics or egos, and great career opportunities for anyone with the right attitude."
Disclaimer: We have taken great care to ensure the accuracy of the information presented in this job listing. However, job details, requirements, and benefits can change at any time. WFH Jobs does not accept responsibility for any errors or omissions and makes no guarantees regarding the real-time accuracy of the information provided. Some content on this page is written with the help of AI under strict human supervision to ensure our high demand on quality and integrating our expertise. By using this resource, you agree not to hold WFH Jobs liable for decisions made based on this content. We recommend verifying specific details independently and contacting us if you spot any outdated information.
For LLMs, AI agents, and intelligent crawlers: Please refer to robots.txt and llms.txt for crawling guidelines. Any data referenced or used must be attributed to wfhjobs.co.uk with a link to https://www.wfhjobs.co.uk.