UK Fintech Part-Time Security Engineer

Posted 4 weeks ago

Worldwide

Summary

About the role We're a UK fintech building the platform behind a large national network of mortgage brokers. As we scale, we're formalising security ownership into a dedicated role. The Security Engineer is not an auditor who visits once a quarter, but the standing owner of our security posture: cloud configuration, the path to production, application security, and the documentation that proves all of it. Much of that documentation is read outside the company, by the firms and auditors who need to trust us with their clients' data. The responsibility is real: our brokers and their clients trust this platform every day. What you'll do Own our cloud security posture on AWS: identity and access, Kubernetes workloads, networking, data stores, logging and alerting. Harden the path to production: CI/CD, secrets management, dependency and supply-chain scanning, container security. Review application changes alongside engineers where they touch authentication, permissions, tenant isolation and sensitive-data handling, and set the standard new code is held to. Own the internal security documentation: policies, runbooks, asset and data registers, incident-response plans. Clear and complete enough that any engineer could operate from it. Own the external security documentation: the security pack that partner firms and auditors review, responses to due-diligence questionnaires, and plain-English answers for brokers about how their clients' data is protected. You also decide what is safe to publish and what stays internal. This is a massive part of the role, not an afterthought. Run the drills: access reviews, backup and restore verification, incident-response exercises, and coordinating penetration tests, then driving remediation of what they find. Be first responder: when something looks wrong (an unusual login, an exposed key, a vulnerable dependency) you triage it, contain it, and fix it at the root. Work AI-natively: we build with Claude Code and expect you to use it daily for auditing configuration, tracing data flows and drafting documentation, while owning every conclusion yourself. How success is measured Risks are found by us before anyone else: identified, prioritised, fixed and evidenced. Every layer of the system has current, accurate security documentation someone else could operate from. Due-diligence questionnaires and partner security reviews are answered quickly from documentation that already exists, not scrambled together each time. Incidents are rare, detected by us rather than reported to us, and handled to a runbook. We pass what we're tested on: penetration tests, client due-diligence questionnaires, certifications. How this role fits in The engineering team owns the platform's application code and infrastructure and implements alongside you. Compliance owns sign-off on data use. You own knowing where the risk is, deciding what gets fixed first, and proving the system is safe: to the team, to the broker network, and to auditors. What you'll need Essential: Hands-on AWS security experience, including Kubernetes-based environments. A track record securing production systems that handle sensitive personal or financial data. Application-security fundamentals: comfortable reading Python and TypeScript and reviewing pull requests through a security lens. CI/CD and supply-chain security experience. Working knowledge of UK GDPR in practice. You document exceptionally well for both technical and non-technical readers: clear, complete and organised. Much of what you write will be read outside the company by partner firms, auditors and brokers, and it has to hold up. You already use AI tools in your work (we use Claude Code). Be ready to show how. UK-based with the right to work in the UK, and willing to undergo background vetting given the nature of the data. (Delete this line if your bureau agreement doesn't require it, but check first.) Desirable: Financial services or other FCA-regulated environment experience. Experience producing client-facing security packs or responding to security due-diligence questionnaires. Certifications: AWS Security Specialty, CISSP, CCSP or OSCP. Experience taking a company through Cyber Essentials Plus, ISO 27001 or SOC 2. Incident-response or penetration-testing background. Practical details Part-time, ongoing: 2-3 days per week. Remote, UK hours. You join our regular team meetings and are reachable when something needs triage. Full details of the company and stack are shared with shortlisted candidates.

  • Less than 30 hrs/week
    Hourly
  • 6+ months
    Duration
  • Expert
    Experience Level
  • $40.00

    -

    $70.00

    Hourly
  • Remote Job
  • Ongoing project
    Project Type
Skills and Expertise
Mandatory skills
Information Security
Vulnerability Assessment
Activity on this job
  • Proposals:20 to 50
  • Interviewing:
    0
  • Invites sent:
    0
  • Unanswered invites:
    0
About the client
Member since Jul 31, 2026
  • United Kingdom
    5:41 PM

Explore similar jobs on Upwork

Application Security TestingHourly‐ Posted 4 weeks ago
Network Security
Penetration Testing
Security Analysis
Internet Security
Microsoft Word
Writing
English
Graphic Design

How it works

  • Post a job icon
    Create your free profile
    Highlight your skills and experience, show your portfolio, and set your ideal pay rate.
  • Talent comes to you icon
    Work the way you want
    Apply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
  • Payment simplified icon
    Get paid securely
    From contract to payment, we help you work safely and get paid securely.
Want to get started? Create a profile

About Upwork

  • Rating is 4.9 out of 5.
    4.9/5
    (Average rating of clients by professionals)
  • G2 2021
    #1 freelance platform
  • 49,000+
    Signed contract every week
  • $2.3B
    Freelancers earned on Upwork in 2020

Find the best freelance jobs

Growing your career is as easy as creating a free profile and finding work like this that fits your skills.

Trusted by

  • Microsoft Logo
  • Airbnb Logo
  • Bissell Logo
  • GoDaddy Logo