{"id":1178908,"url":"https://alion.io/job/thought-machine-application-security-engineer-3","title":"Application Security Engineer","company":{"id":7206,"name":"Thought Machine","domain":"thoughtmachine.net","url":"https://alion.io/company/thought-machine","size_band":"51-200","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Ashby","truth_index":{"grade":"A","score":91,"open_postings":23,"ghost_share":0,"stale_share":0.174,"repost_share":0,"time_to_fill_p50_days":62,"computed_at":"2026-09-26T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":null,"employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Lisbon, Portugal"],"countries":["PT"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":50000,"max":75000,"currency":"EUR","period":"year","gross":null,"usd_annual":86097},"salary_estimate":null,"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Burp Suite","optional":false},{"name":"Docker","optional":false},{"name":"GCP","optional":false},{"name":"Java","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"Python","optional":false},{"name":"Threat Modeling","optional":false},{"name":"ISO 27001","optional":true},{"name":"PCI DSS","optional":true}],"status":"live","first_seen_at":"2026-09-24T12:30:54Z","employer_posted_date":"2026-09-24","last_verified_at":"2026-09-27T00:56:11Z","board_verified":true,"closed_at":null,"days_open":2,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":2},"description":"Thought Machine's mission is bold - to properly and permanently rid the world's banks of legacy technology. To achieve this, we have developed the foundations of modern banking through core and payments technology which run natively in the cloud. What we are attempting is hard and means we need great people working together to build great technology.\nWe have grown rapidly in the past few years - growing our team to more than 550 individuals across offices in London, New York, Singapore, Sydney and our newly established Engineering Hub in Lisbon. We have raised more than £500m in funding and our investors include Molten Ventures, Eurazeo, Intesa Sanpaolo, Temasek, Nyca Partners, JPMorgan Chase Strategic Investments, Standard Chartered Ventures, and more.\nWe have created a culture that enables our team to produce the best work in the industry while ensuring we have fun along the way. We're regularly cited as having a fantastic workplace culture and have been recognised by Sifted magazine as having one of the highest Glassdoor ratings for a UK fintech company and the industry's most generous employee share package. Named one of the world's most innovative fintechs by Global Finance Magazine, we were also recognised by the Financial Times as one of Europe's fastest-growing companies for two consecutive years-and a UK Best Employer for 2026.\nThis is a full-time, permanent position based in our Lisbon office, requiring four days a week onsite.\nThis position plays a key role in ensuring Thought Machine teams are taking all required steps in building a secure product set. You will play a major and leading role in protecting Thought Machine product against security risks, with influence to implement cutting-edge measures to minimise exposures and vulnerabilities.\nWhether engineering a system to address a technical security hurdle, protecting our customers' data, or consulting on a wide range of security topics, you are empowered to engage and lead cross-functionally.\nA large part of Thought Machine product security function is a greenfield challenge, we are building the bank of tomorrow with cutting edge web technology, no best-practice/of the shelve security frameworks or tools can solve our security challenge. We are building the best security to enable engineering and impress financial service auditors. Key qualities of the ideal candidate would have experience in OWASP top 10 vulns, devsecOps, data privacy protection, passion to mentor and enable devs, creativity, autonomy, ability to work and complete multiple projects simultaneously.\nDUTIES\nDrive improvements to Thought Machines product security posture through strategic planning and collaboration with both development and infrastructure teams, with trust, autonomy and influence.\n\nProduce production web scale grade application security design.\n\nReview and produce data privacy and financial regulatory functional and nonfunctional designs.\n\nPerform design reviews and Threat modeling of Thought Machine services and products.\n\nPerform vulnerability assessments and security testing.\n\nProviding subject matter expertise on all areas of security and privacy throughout the Software Development lifecycle.\n\nLiaison with development teams for design, code reviews & education.\n\nTo contribute to security strategy, security tooling selection and creation.\n\nConduct regular security assessments and code reviews.\n\nREQUIREMENTS\nEssential\nExpertise with a programming language (e.g. Python, Go or Java)\n\nExperience of security in a DevOps environment\n\nExperience in web application penetration testing and security tooling (e.g. Burp proxy, Web/Network Scanners, Static code analysers, etc).\n\nCoding experience for automating/integrating security tools and creation of security tools.\n\nKnowledge of security in distributed systems at scale.\n\nCloud and containers technology knowledge (e.g. AWS, GCP, Kuberbetes, Docker)\n\nExperience of performing security design reviews, threat modelling and risk assessments\n\nKnowledge of application security issues\n\nDesirable\nProfessional security qualifications are desirable (e.g. CISSP, Offensive Security, Sans Institute, etc.)\n\nContributions to the security community (public research, blogging, presentations, etc)\n\nAwareness and experience of the Data Protection Act, ISO 27001 and PCI-DSS\n\nBenefits\nHighly competitive salary\n\nVoluntary Pension Plan (match up to 5%)\n\nPrivate Healthcare Insurance\n\nComprehensive Life Insurance\n\n25 days holiday plus public holidays\n\nTwo charity days a year\n\nDaily Meal Allowance\n\nAccess to outstanding learning materials and courses\n\nSports and hobby clubs, subsidised by Thought Machine\n\nAll the latest tech you need\n\nHuge range of healthy (and not-so-healthy) snacks, smoothies and drinks\n\nA talented and experienced team as your colleagues\n\nAn environment where we encourage learning and progress\n\nWe actively hire candidates who demonstrate technical excellence in their field and welcome people of all ages and backgrounds, providing everyone with equal access to professional development. You are encouraged to apply even if your experience doesn't accurately match the job description. We also encourage applications from those with different abilities, including candidates with ADHD, autism, dyslexia or dyspraxia.","description_format":"text","description_chars":5289,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Life insurance","Professional development"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Application Security","Financial Software & Embedded Finance"],"lifecycle":[{"event":"open","at":"2026-09-24T12:33:03Z"}],"liveness":{"score":99,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.993,"p_room":1,"age_days":1,"expected_fill_days":62,"reasons":["conf:1","wave","velocity","win:early"],"computed_at":"2026-09-26T05:45:00Z"},"pay":{"stated_usd_annual":86097,"is_top_pay":false},"html_url":"https://alion.io/job/thought-machine-application-security-engineer-3","json_url":"https://alion.io/job/thought-machine-application-security-engineer-3.json","meta":{"generated_at":"2026-09-27T01:22:27Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1208,"day_limit":5000,"remaining_today":3792,"minute_limit":60,"resets_at":"2026-09-28T00:00:00Z"}}}