Senior Security Engineer - Contract
What is Flagstone?
A feel for our culture
About the team
Does this sound like you?
You're a senior security engineer who operates credibly across cloud security, detection tooling, and incident response, without being narrowly specialised. You own meaningful parts of the security stack, contribute hands-on to Azure cloud hardening, and show up reliably when incidents need investigating or pen test cycles need coordinating. You're energised by visible impact, your work matters, and your voice is heard.
What you’ll do:
- Own and operate our alerting and monitoring capability through a transition period, keeping detection and response steady.
- Maintain and improve our Microsoft Sentinel deployment: writing and tuning detection rules, managing data connectors, and reducing alert noise.
- Operate and optimise Defender XDR and Defender for Cloud, including policy management and posture recommendations.
- Maintain and extend automated security checks in our delivery pipelines (shift-left).
- Drive down time-to-fix on known vulnerabilities, coordinating remediation with engineering squads.
- Support data-loss-prevention controls that reduce the risk of sensitive data leaving the business.
- Support safeguards around how the business accesses and uses AI, including securing AI workloads and their data exposure.
- Investigate suspicious activity surfaced through Sentinel and Defender: triage, escalate, or contain as appropriate.
- Support incident response, including containment, evidence gathering, and post-incident review.
- Contribute to detection-as-code and infrastructure-as-code (Terraform or Bicep) for security tooling.
- Coordinate penetration test engagements (scope, logistics, findings review) and work with engineering teams to prioritise remediation.
What you’ll bring:
- Hands-on SIEM experience, ideally Microsoft Sentinel; equivalent platforms (Splunk, Chronicle, QRadar) considered.
- Practical Azure security experience across Defender for Cloud, Entra ID, Azure networking, and cloud security posture management.
- Experience writing infrastructure-as-code using Terraform or Bicep in a security engineering context.
- Experience driving vulnerability remediation cycles with engineering squads.
- Familiarity with data-loss-prevention controls.
- Familiarity with AI security considerations (securing AI workloads, data exposure risks) and/or using AI tooling to augment security engineering workflows.
- Ability to contribute to threat modelling and communicate security risk clearly to engineering and product audiences.
- A growth mindset and genuine curiosity to keep learning.
- SC-200 (Microsoft Security Operations Analyst) certification.
- KQL proficiency for detection rule authoring and threat hunting.
- Experience working in a similar fintech or financial services environment
All are welcome
Not included in the source posting: what you'll do, qualifications, benefits.
Skills
Who can apply
The employer didn't state any visa, work authorization, citizenship or clearance requirements in this posting. Confirm with the employer before applying.
Read automatically from the employer's posting text. Always confirm with the employer — requirements can change after a job is published.