UK Fintech Part-Time Security Engineer
Worldwide
About the role We're a UK fintech building the platform behind a large national network of mortgage brokers. As we scale, we're formalising security ownership into a dedicated role. The Security Engineer is not an auditor who visits once a quarter, but the standing owner of our security posture: cloud configuration, the path to production, application security, and the documentation that proves all of it. Much of that documentation is read outside the company, by the firms and auditors who need to trust us with their clients' data. The responsibility is real: our brokers and their clients trust this platform every day. What you'll do Own our cloud security posture on AWS: identity and access, Kubernetes workloads, networking, data stores, logging and alerting. Harden the path to production: CI/CD, secrets management, dependency and supply-chain scanning, container security. Review application changes alongside engineers where they touch authentication, permissions, tenant isolation and sensitive-data handling, and set the standard new code is held to. Own the internal security documentation: policies, runbooks, asset and data registers, incident-response plans. Clear and complete enough that any engineer could operate from it. Own the external security documentation: the security pack that partner firms and auditors review, responses to due-diligence questionnaires, and plain-English answers for brokers about how their clients' data is protected. You also decide what is safe to publish and what stays internal. This is a massive part of the role, not an afterthought. Run the drills: access reviews, backup and restore verification, incident-response exercises, and coordinating penetration tests, then driving remediation of what they find. Be first responder: when something looks wrong (an unusual login, an exposed key, a vulnerable dependency) you triage it, contain it, and fix it at the root. Work AI-natively: we build with Claude Code and expect you to use it daily for auditing configuration, tracing data flows and drafting documentation, while owning every conclusion yourself. How success is measured Risks are found by us before anyone else: identified, prioritised, fixed and evidenced. Every layer of the system has current, accurate security documentation someone else could operate from. Due-diligence questionnaires and partner security reviews are answered quickly from documentation that already exists, not scrambled together each time. Incidents are rare, detected by us rather than reported to us, and handled to a runbook. We pass what we're tested on: penetration tests, client due-diligence questionnaires, certifications. How this role fits in The engineering team owns the platform's application code and infrastructure and implements alongside you. Compliance owns sign-off on data use. You own knowing where the risk is, deciding what gets fixed first, and proving the system is safe: to the team, to the broker network, and to auditors. What you'll need Essential: Hands-on AWS security experience, including Kubernetes-based environments. A track record securing production systems that handle sensitive personal or financial data. Application-security fundamentals: comfortable reading Python and TypeScript and reviewing pull requests through a security lens. CI/CD and supply-chain security experience. Working knowledge of UK GDPR in practice. You document exceptionally well for both technical and non-technical readers: clear, complete and organised. Much of what you write will be read outside the company by partner firms, auditors and brokers, and it has to hold up. You already use AI tools in your work (we use Claude Code). Be ready to show how. UK-based with the right to work in the UK, and willing to undergo background vetting given the nature of the data. (Delete this line if your bureau agreement doesn't require it, but check first.) Desirable: Financial services or other FCA-regulated environment experience. Experience producing client-facing security packs or responding to security due-diligence questionnaires. Certifications: AWS Security Specialty, CISSP, CCSP or OSCP. Experience taking a company through Cyber Essentials Plus, ISO 27001 or SOC 2. Incident-response or penetration-testing background. Practical details Part-time, ongoing: 2-3 days per week. Remote, UK hours. You join our regular team meetings and are reachable when something needs triage. Full details of the company and stack are shared with shortlisted candidates.
- Less than 30 hrs/weekHourly
- 6+ monthsDuration
- ExpertExperience Level
$40.00
-
$70.00
Hourly- Remote Job
- Ongoing projectProject Type
Skills and Expertise
Activity on this job
- Proposals:20 to 50
- Interviewing:0
- Invites sent:0
- Unanswered invites:0
About the client
- United Kingdom5:41 PM
Explore similar jobs on Upwork
How it works
Create your free profileHighlight your skills and experience, show your portfolio, and set your ideal pay rate.
Work the way you wantApply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
Get paid securelyFrom contract to payment, we help you work safely and get paid securely.
About Upwork
- 4.9/5(Average rating of clients by professionals)
- G2 2021#1 freelance platform
- 49,000+Signed contract every week
- $2.3BFreelancers earned on Upwork in 2020
Find the best freelance jobs
Growing your career is as easy as creating a free profile and finding work like this that fits your skills.
Trusted by