Senior Security Engineer - Contract
Flagstone
<p style="min-height:1.5em"><strong>What is Flagstone?</strong></p><p style="min-height:1.5em">Flagstone is many things. An online savings platform, reinventing how individuals, businesses, and charities manage, protect, and grow their cash. A diverse group of people, bound by a collaborative spirit, and shared purpose. And lastly, a thriving, profitable business – where smart people do their best work.</p><p style="min-height:1.5em">Each definition shares a common thread: our unique culture. It’s our pride and joy. And our competitive advantage.</p><p style="min-height:1.5em"><strong>A feel for our culture:</strong></p><p style="min-height:1.5em">To revolutionise the savings market, we need to be at our best. But high performance takes more than talent – it takes a culture of kindness, respect, and growth.</p><p style="min-height:1.5em">That’s why we’re building a diverse, inclusive community, where your voice is heard and valued. Where, with close support and room to develop, you can surpass even your own expectations. And be rewarded for it.</p><p style="min-height:1.5em">We may not change the world, but we <em>can </em>change the world of financial technology. And all it takes is a winning mix of drive, talent, and empathy. Our culture celebrates all three.<br /><br />But enough about us. Let’s talk about you.</p><p style="min-height:1.5em"><br /><strong>About the team</strong><br />Security Engineering is a team of five covering cloud security, detection, and security operations. They work directly in the Azure estate and are close to the infrastructure, not abstracted behind a policy layer. The team runs Microsoft Sentinel, Defender XDR, and Defender for Cloud, and manages tooling through infrastructure-as-code. They run a quarterly penetration test programme and are continuously building out our detection and response capability. It's a small team with broad scope, which means your work is visible, your opinions are heard, and there are meaningful problems for our engineers to work on.</p><p style="min-height:1.5em">This is a contract role, so we're looking for someone who can hit the ground running. You'll bring immediate impact and add value from day one, working independently without a long ramp-up. Your work will be visible, and the problems you solve will matter.</p><p style="min-height:1.5em"><br /><strong>Does this sound like you?</strong><br />You're a senior security engineer who operates credibly across cloud security, detection tooling, and incident response, without being narrowly specialised. You own meaningful parts of the security stack, contribute hands-on to Azure cloud hardening, and show up reliably when incidents need investigating or pen test cycles need coordinating. You're energised by visible impact, your work matters, and your voice is heard.</p><p style="min-height:1.5em"><strong> </strong></p><p style="min-height:1.5em"><strong>What you’ll do:</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Own and operate our alerting and monitoring capability through a transition period, keeping detection and response steady.</p></li><li><p style="min-height:1.5em">Maintain and improve our Microsoft Sentinel deployment: writing and tuning detection rules, managing data connectors, and reducing alert noise.</p></li><li><p style="min-height:1.5em">Operate and optimise Defender XDR and Defender for Cloud, including policy management and posture recommendations.</p></li><li><p style="min-height:1.5em">Maintain and extend automated security checks in our delivery pipelines (shift-left).</p></li><li><p style="min-height:1.5em">Drive down time-to-fix on known vulnerabilities, coordinating remediation with engineering squads.</p></li><li><p style="min-height:1.5em">Support data-loss-prevention controls that reduce the risk of sensitive data leaving the business.</p></li><li><p style="min-height:1.5em">Support safeguards around how the business accesses and uses AI, including securing AI workloads and their data exposure.</p></li><li><p style="min-height:1.5em">Investigate suspicious activity surfaced through Sentinel and Defender: triage, escalate, or contain as appropriate.</p></li><li><p style="min-height:1.5em">Support incident response, including containment, evidence gathering, and post-incident review.</p></li><li><p style="min-height:1.5em">Contribute to detection-as-code and infrastructure-as-code (Terraform or Bicep) for security tooling.</p></li><li><p style="min-height:1.5em">Coordinate penetration test engagements (scope, logistics, findings review) and work with engineering teams to prioritise remediation.<br /><strong> </strong></p></li></ul><p style="min-height:1.5em"><strong>What you’ll bring:</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Hands-on SIEM experience, ideally Microsoft Sentinel; equivalent platforms (Splunk, Chronicle, QRadar) considered.</p></li><li><p style="min-height:1.5em">Practical Azure security experience across Defender for Cloud, Entra ID, Azure networking, and cloud security posture management.</p></li><li><p style="min-height:1.5em">Experience writing infrastructure-as-code using Terraform or Bicep in a security engineering context.</p></li><li><p style="min-height:1.5em">Experience driving vulnerability remediation cycles with engineering squads.</p></li><li><p style="min-height:1.5em">Familiarity with data-loss-prevention controls.</p></li><li><p style="min-height:1.5em">Familiarity with AI security considerations (securing AI workloads, data exposure risks) and/or using AI tooling to augment security engineering workflows.</p></li><li><p style="min-height:1.5em">Ability to contribute to threat modelling and communicate security risk clearly to engineering and product audiences.</p></li><li><p style="min-height:1.5em">A growth mindset and genuine curiosity to keep learning.</p></li><li><p style="min-height:1.5em">SC-200 (Microsoft Security Operations Analyst) certification.</p></li><li><p style="min-height:1.5em">KQL proficiency for detection rule authoring and threat hunting.</p></li><li><p style="min-height:1.5em">Experience working in a similar fintech or financial services environment<br /> </p></li></ul><p style="min-height:1.5em"><strong>All are welcome:</strong></p><p style="min-height:1.5em">At Flagstone, we’re assembling a diverse team that defies our industry’s norms. Think this role could suit you? We encourage you to apply, no matter your background.</p><p>Find <a href="https://www.arbeitnow.co.uk">Jobs in United Kingdom</a> on Arbeitnow</a>