Share this job
Head of Security Engineering
Apply for this job

Numi partners with a well-funded UK payments business in the middle of a genuine build. It's a regulated fintech operating within a larger organisation, processing payments at significant scale for SMEs and large corporates, but running like a startup: greenfield platform, flat structure, small teams, and the freedom to do things properly from day one. The platform is being built entirely on AWS, and the security function is being built alongside it. Long-term this will be a roughly 1,500-person company, so people coming in now will have real ownership over what it becomes. The CISO has done this three or four times before at Starling, in large bank transformation programmes, and in fintech environments, and the culture he's built reflects it: deeply technical, outcomes-driven, and with no tolerance for security theatre.

Opportunity

This is a greenfield build. There is no team, no architecture, no tooling. You're starting from zero, alongside a platform that's also being built from scratch. You'll report directly to the CISO and lead a team of four or five engineers that you'll hire yourself. The job is to define the security reference architecture across cloud, network, identity, and data, then make sure those standards are enforced through policy-as-code, automation, and tooling rather than manual oversight. You'll be embedded with the platform and engineering teams, sitting in sprint planning, helping developers understand what security components they need to include as they build. You'll also be building security tooling yourself: automations, integrations, monitoring. This is a doing role with a leadership element, not the other way around. The challenge is operating inside a large organisation while moving at fintech speed, pushing for better ways of doing things, and being able to justify every security decision at a technical level. Simon's rule: if you can't explain why a control exists, you don't implement it.

Skills required

  • Background as both a security architect and a security engineer. Candidates with only one or the other won't fit.
  • Close enough to the stack to challenge at code level and build security tooling (Python, Java, AWS-native services, Kubernetes)
  • Experience building a team from scratch, not inheriting one
  • Fintech or regulated financial services background; comfortable meeting regulatory requirements without overcooking it
  • AWS depth: IAM, GuardDuty, Security Hub, Kubernetes security, service mesh, IaC (Terraform/GitHub Actions)
  • A natural challenger who asks why before doing, persuades with evidence, and doesn't bend to pressure without good reason



Apply for this job
Powered by