Level

Thought Machine

Senior Application Security Engineer

Thought Machine is hiring a Senior Application Security Engineer in Lisbon, Portugal. It pays €75k-€95k a year and Level rates it ; you can apply on Level.

AI in this role

Lead application security engineering efforts to protect cloud-native core banking products from vulnerabilities.

owaspdevsecops
application-securityvulnerability-managementcloud-securitydata-privacythreat-mitigation

Thought Machine's mission is bold – to properly and permanently rid the world's banks of legacy technology. To achieve this, we have developed the foundations of modern banking through core and payments technology which run natively in the cloud. What we are attempting is hard and means we need great people working together to build great technology.

We have grown rapidly in the past few years – growing our team to more than 550 individuals across offices in London, New York, Singapore, Sydney and our newly established Engineering Hub in Lisbon. We have raised more than £500m in funding and our investors include Molten Ventures, Eurazeo, Intesa Sanpaolo, Temasek, Nyca Partners, JPMorgan Chase Strategic Investments, Standard Chartered Ventures, and more.

We have created a culture that enables our team to produce the best work in the industry while ensuring we have fun along the way. We're regularly cited as having a fantastic workplace culture and have been recognised by Sifted magazine as having one of the highest Glassdoor ratings for a UK fintech company and the industry's most generous employee share package. Named one of the world's most innovative fintechs by Global Finance Magazine, we were also recognised by the Financial Times as one of Europe's fastest-growing companies for two consecutive years—and a UK Best Employer for 2026.

This is a full-time, permanent position based in our Lisbon office, requiring four days a week onsite.

This position plays a key role in ensuring Thought Machine teams are taking all required steps in building a secure product set. You will play a major and leading role in protecting Thought Machine product against security risks, with influence to implement cutting-edge measures to minimise exposures and vulnerabilities.

Whether engineering a system to address a technical security hurdle, protecting our customers' data, or consulting on a wide range of security topics, you are empowered to engage and lead cross-functionally.

A large part of Thought Machine product security function is a greenfield challenge, we are building the bank of tomorrow with cutting edge web technology, no best-practice/of the shelve security frameworks or tools can solve our security challenge. We are building the best security to enable engineering and impress financial service auditors. Key qualities of the ideal candidate would have experience in OWASP top 10 vulns, devsecOps, data privacy protection, passion to mentor and enable devs, creativity, autonomy, ability to work and complete multiple projects simultaneously.

DUTIES

  • Drive improvements to Thought Machines product security posture through strategic planning and collaboration with both development and infrastructure teams, with trust, autonomy and influence.

  • Produce production web scale grade application security design.

  • Review and produce data privacy and financial regulatory functional and nonfunctional designs.

  • Perform design reviews and Threat modeling of Thought Machine services and products.

  • Perform vulnerability assessments and security testing.

  • Providing subject matter expertise on all areas of security and privacy throughout the Software Development lifecycle.

  • Liaison with development teams for design, code reviews & education.

  • To contribute to security strategy, security tooling selection and creation.

  • Conduct regular security assessments and code reviews.

REQUIREMENTS

Essential

  • Expertise with a programming language (e.g. Python, Go or Java)

  • Experience of security in a DevOps environment

  • Experience in web application penetration testing and security tooling (e.g. Burp proxy, Web/Network Scanners, Static code analysers, etc).

  • Coding experience for automating/integrating security tools and creation of security tools.

  • Knowledge of security in distributed systems at scale.

  • Cloud and containers technology knowledge (e.g. AWS, GCP, Kuberbetes, Docker)

  • Experience of performing security design reviews, threat modelling and risk assessments

  • Knowledge of application security issues

Desirable

  • Professional security qualifications are desirable (e.g. CISSP, Offensive Security, Sans Institute, etc.)

  • Contributions to the security community (public research, blogging, presentations, etc)

  • Awareness and experience of the Data Protection Act, ISO 27001 and PCI-DSS

Benefits

  • Highly competitive salary

  • Voluntary Pension Plan (match up to 5%)

  • Private Healthcare Insurance

  • Comprehensive Life Insurance

  • 25 days holiday plus public holidays

  • Two charity days a year

  • Daily Meal Allowance

  • Access to outstanding learning materials and courses

  • Sports and hobby clubs, subsidised by Thought Machine

  • All the latest tech you need

  • Huge range of healthy (and not-so-healthy) snacks, smoothies and drinks

  • A talented and experienced team as your colleagues

  • An environment where we encourage learning and progress

We actively hire candidates who demonstrate technical excellence in their field and welcome people of all ages and backgrounds, providing everyone with equal access to professional development. You are encouraged to apply even if your experience doesn't accurately match the job description. We also encourage applications from those with different abilities, including candidates with ADHD, autism, dyslexia or dyspraxia.

How we rate this

Senior Application Security Engineer at Thought Machine rates 0 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.

Classification

Little AI. AI is not part of the work.

  1. ●●●● Builds AI80 to 100
  2. ●●●○ Works on AI60 to 79
  3. ●●○○ Uses AI40 to 59
  4. ●○○○ Little AI0 to 39

Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.

Prepare for this job

A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.

Skills and AI tools this role asks for

Application SecurityVulnerability ManagementCloud SecurityData PrivacyThreat MitigationOwaspDevsecops

Questions you could be asked

  1. Tell me about a project where application security was part of your work. What did you do?
  2. Tell me about a project where vulnerability management was part of your work. What did you do?
  3. Tell me about a project where cloud security was part of your work. What did you do?
  4. Tell me about a project where data privacy was part of your work. What did you do?
  5. Tell me about a project where threat mitigation was part of your work. What did you do?

Adapt your resume

  • List these exact terms on your resume: Application Security, Vulnerability Management, Cloud Security, Data Privacy, and Threat Mitigation. An applicant tracking system matches the wording, not the idea.
  • Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.

Want an expert to read your CV for this job?

Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.

Get a free CV review

Get new cybersecurity jobs by email

One email a week with the new cybersecurity jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.

Free. One email a week. Unsubscribe in one click.

Similar roles

Security roles that involve little AI, at other companies.

What kind of AI work fits you?

Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.

Find my next step

More jobs at Thought Machine

More cybersecurity jobs

Related searches

Same AI level

Jobs by city