Senior Application Security Engineer

Company: Flagstone
Apply for the Senior Application Security Engineer
Location: London
Job Description:

Overview

As a Senior Security Engineer, you will own meaningful parts of Flagstone’s security stack and help harden our Azure environment. You’ll work within a tight Security Engineering team focused on cloud security, detection, and security operations, directly tying security to the Azure estate. Your work will drive observable security improvements, from detection tuning to incident response coordination. You will collaborate cross-functionally to scale our security capabilities in a fast-paced fintech context.

Pay / Benefits

  • Competitive bonus scheme
  • Flexible benefits budget
  • Salary sacrifice options
  • Around the World work-from-anywhere
  • Mental wellbeing support
  • Learning and development budget 1000

Responsibilities

  • Maintain and improve Microsoft Sentinel deployment with detection tuning and data connectors
  • Operate Defender XDR and Defender for Cloud including policy management and posture recommendations
  • Harden Azure across identity, networking, storage, WAF, and logging pipelines
  • Contribute to IaC for security tooling deployments and drift management (Terraform or Bicep)
  • Investigate suspicious activity surfaced by Sentinel and Defender; triage, escalate, or contain
  • Support incident response activities including containment, evidence gathering, and post-incident review
  • Participate in security risk assessments and threat modeling across systems
  • Coordinate penetration test engagements and work with engineering to prioritize remediation

Key requirements

  • Hands-on SIEM experience, preferably Microsoft Sentinel; equivalents considered
  • Practical Azure security experience across Defender for Cloud, Entra ID, Azure networking, and cloud security posture management
  • Experience writing IaC using Terraform or Bicep in a security context
  • Ability to contribute to threat modelling and communicate risk to engineering and product audiences
  • Experience supporting or coordinating penetration testing programs, including remediation cycles
  • Familiarity with AI security considerations and/or AI tooling to augment security workflows
  • Growth mindset and genuine curiosity to learn
  • growth mindset
  • curiosity
  • clear communication with engineering and product teams
  • Microsoft Sentinel
  • Defender XDR
  • Defender for Cloud

…

Posted: September 30th, 2026