About the role
We’re looking for a Senior Cyber Security Specialist to join our Information Security team, working closely with the Head of Information Security. You’ll play a pivotal role in shaping Lendable’s cyber security strategy and enhancing its security architecture.
Your responsibilities will span across the business, supporting internal teams and external stakeholders. You’ll focus on developing and implementing security architecture, tooling, and best practices, as well as contributing to audits (ISO/IEC 27001 and SOC2), risk management, and incident response. The primary goal is to improve Lendable’s security posture while staying ahead of evolving cybersecurity trends.
This is an exciting opportunity to leave your mark by driving key initiatives, such as shaping our Secure Software Development Lifecycle (SDLC) and implementing cutting-edge security solutions like EDR, IAM, MDR, Zero Trust networking, and Vulnerability Management. You’ll also ensure our policies and procedures comply with standards like NIST, CIS, NCSC, and SSAE 18, while supporting certifications and audits.
The role requires a strong understanding of financial regulations in the UK and the USA, ensuring Lendable remains compliant and secure. This is your chance to make a real impact and influence the future of Lendable’s security strategy.
Our Tech Stack
Programming Languages: PHP 8, Kotlin, Python, TypeScriptFrameworks & Libraries: Symfony (6 & 7), FastAPI, React, React Native, Streamlit, MobX, Redux, SASSDatabases: MySQL, PostgreSQL, SQLAlchemyDevOps & Infrastructure: AWS, Docker, Kubernetes, GitHub Actions, ArgoCDMessaging & Queueing: RabbitMQTesting Tools: Behat, PHPUnit, Jest, Selenium, Maestro, DetoxServer & Application Tools: uvicornWhat you'll be doing/impact on objectives
Support the definition and implementation of security architecture across the business, creating cyber-security standards, reference architectures, designs, and blueprints to enable Lendable to achieve its ambitions in a safe and controlled manner.Ensure the security architecture aligns with industry standards (e.g., NIST, CIS, NCSC), regulatory requirements, and best practices.Contribute to the evaluation of risks in systems, including reviewing and proposing tactical and strategic remediation plans.Act as the information security expert, aligning security architecture frameworks with the overall security strategy.Promote the adoption of secure-by-design and secure-by-default principles, working with technology and business units to implement appropriate security solutions.Foster innovation and experimentation to solve complex security challenges.Define security requirements and embed them early in the project lifecycle.Provide security assurance for significant changes across the organisation.Stay informed on the evolving cyber-security landscape, researching new technologies, architectures, and products to support Lendable’s technology strategy and future plans.Manage third-party partners and providers as part of the security programme, supervising their deliverables.Align cyber-security measures with business needs, maximising security adoption while minimising operational costs and risks.Develop and monitor metrics to report on the effectiveness and efficiency of security measures.Automate repetitive tasks to improve efficiency within the security team.Support the Security Operations Center (SOC) in investigating incidents and assisting with remediation efforts..Your profile
5+ years of experience as a Security Architect or similar role.Broad expertise in cyber security and domain knowledge in financial services, banking, or insurance.Experience with vendors offering IAM, IDS, IPS, SSO, EDR, MDR, DLP, SIEM, SOAR, Zero Trust networking, SASE, CSPM, and CASB.Involvement in achieving certifications like ISO/IEC 27001 or SOC 2 Type II.Hands-on expertise in cyber security and security architecture.Strong knowledge of Linux, networks, protocols, and authentication/authorization protocols.Basic software engineering skills to work on InfoSec tooling and understand technical challenges.Proven ability to build security dashboards and contribute to reporting.Wide knowledge of security practices, technologies, and conventions.Strong desire to learn, improve, and challenge the status quo.A collaborative approach to enhancing security practices and supporting teams with secure-by-design initiatives.Interview process
A quick phone call with one of the teamA short technical exercise to complete in your own time Onsite or Video Interview Discuss the exercise you completed
Discuss your past experience
Explore how your career aspirations align with the responsibilities and opportunities of this position
Meet the team you’ll work with daily Interview with CPTO