Thought Machine

Fintech

ApplicationSecurityEngineer

Lisbon, Portugal FULL TIME
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Mid+ candidates.

The Brief

“Application Security Engineer at Thought Machine. Skills: Application security, DevSecOps, Cloud security, Penetration testing. Drive improvements to product security posture. Produce production web scale grade application security design”

What You'll Achieve.

Protecting Thought Machine product against security risks; Minimise exposures and vulnerabilities; Protecting customers' data; Enable engineering; Impress financial service auditors

Industry & Context.

Fintech
Problems you'll solve

Address a technical security hurdle

Eligibility Requirements

Four days a week onsite in Lisbon office

What They're Looking For.

Must Have

OWASP top 10 vulns, devsecOps, data privacy protection, Expertise with a programming language (e.g. Python, Go or Java), Experience of security in a DevOps environment, Experience in web application penetration testing and security tooling, Coding experience for automating/integrating security tools and creation of security tools, Knowledge of security in distributed systems at scale, Cloud and containers technology knowledge, Experience of performing security design reviews, threat modelling and risk assessments, Knowledge of application security issues

Nice to Have

Professional security qualifications, Contributions to the security community, Awareness and experience of the Data Protection Act, ISO 27001 and PCI-DSS

What You'll Do.

Drive improvements to product security posture

Produce production web scale grade application security design

Review and produce data privacy and financial regulatory designs

Perform design reviews and Threat modeling

Perform vulnerability assessments and security testing

Provide subject matter expertise

Contribute to security strategy

Conduct regular security assessments and code reviews

How You'll Work.

Team & Collaboration

Collaboration with development and infrastructure teams; Liaison with development teams for design, code reviews & education; Engage and lead cross-functionally

Process & Methodology

Ability to work and complete multiple projects simultaneously

Full Job Description

Thought Machine's mission is bold – to properly and permanently rid the world's banks of legacy technology. To achieve this, we have developed the foundations of modern banking through core and payments technology which run natively in the cloud. What we are attempting is hard and means we need great people working together to build great technology. We have grown rapidly in the past few years – growing our team to more than 550 individuals across offices in London, New York, Singapore, Sydney and our newly established Engineering Hub in Lisbon. We have raised more than £500m in funding and our investors include Molten Ventures, Eurazeo, Intesa Sanpaolo, Temasek, Nyca Partners, JPMorgan Chase Strategic Investments, Standard Chartered Ventures, and more. We have created a culture that enables our team to produce the best work in the industry while ensuring we have fun along the way. We're regularly cited as having a fantastic workplace culture and have been recognised by Sifted magazine as having one of the highest Glassdoor ratings for a UK fintech company and the industry's most generous employee share package. Named one of the world's most innovative fintechs by Global Finance Magazine, we were also recognised by the Financial Times as one of Europe's fastest-growing companies for two consecutive years—and a UK Best Employer for 2026. This is a full-time, permanent position based in our Lisbon office, requiring four days a week onsite. This position plays a key role in ensuring Thought Machine teams are taking all required steps in building a secure product set. You will play a major and leading role in protecting Thought Machine product against security risks, with influence to implement cutting-edge measures to minimise exposures and vulnerabilities. Whether engineering a system to address a technical security hurdle, protecting our customers' data, or consulting on a wide range of security topics, you are empowered to engage and lead cross-functionally. A large

Free ATS check

Applying for this Application Security Engineer role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Ashby

  • Ashby is a fast modern ATS — most applications take under 3 minutes.
  • The resume parser is strong; verify parsed experience dates and job titles.
  • Custom screening questions are often scored algorithmically — answer completely.
  • Location field affects geo-based screening; use your actual metro area.

ANONYMOUS · UNFILTERED

What do employees actually say about Thought Machine?

Real rants from real employees. Read before you apply.

Read Company Rants →