Numi partners with a well-funded UK payments business in the middle of a genuine build. It's a regulated fintech operating within a larger organisation, processing payments at significant scale for SMEs and large corporates, but running like a startup: greenfield platform, flat structure, small teams, and the freedom to do things properly from day one. The platform is being built entirely on AWS, and the security function is being built alongside it. Long-term this will be a roughly 1,500-person company, so people coming in now will have real ownership over what it becomes. The CISO has done this three or four times before at Starling, in large bank transformation programmes, and in fintech environments, and the culture he's built reflects it: deeply technical, outcomes-driven, and with no tolerance for security theatre.
Opportunity
This is a greenfield build. There is no team, no architecture, no tooling. You're starting from zero, alongside a platform that's also being built from scratch. You'll report directly to the CISO and lead a team of four or five engineers that you'll hire yourself. The job is to define the security reference architecture across cloud, network, identity, and data, then make sure those standards are enforced through policy-as-code, automation, and tooling rather than manual oversight. You'll be embedded with the platform and engineering teams, sitting in sprint planning, helping developers understand what security components they need to include as they build. You'll also be building security tooling yourself: automations, integrations, monitoring. This is a doing role with a leadership element, not the other way around. The challenge is operating inside a large organisation while moving at fintech speed, pushing for better ways of doing things, and being able to justify every security decision at a technical level. Simon's rule: if you can't explain why a control exists, you don't implement it.
Skills required