Security Engineer
RemoteTallinn, Harjumaa, EstoniaseniorFull-time
- Posted
- today
- Source
- LinkedIn (remote, Europe)
- Field
- Engineering, Security
Skills
SecurityPythonREST APIsAWSAI
Description
Location: Tallinn, Estonia
Entity: Monese Estonian entity, supporting both Monese and Pockit
Team: Security
Reports to: Head of Security
Level: Mid-level, 3 to 5 years of relevant experience
Employment type: Full time, permanent
About Pockit and Monese
Pockit and Monese are all-in-one money apps that make it easier for people to access and manage the financial tools they need to take control of their money.
We provide vital financial services, from accounts and cards to income advance solutions. In October 2024, Pockit acquired Monese, bringing together two complementary businesses and creating a leading fintech company focused on serving people who are underserved by traditional banks.
Together, we serve more than three million customers across the UK and Europe.
We're a diverse, international and energetic team, with colleagues based across London, Newcastle, Tallinn and remote teams across Central Europe. We value curiosity, ambition, accountability and resilience, and we want everyone to feel at home, have a voice and know that their contribution matters. We give people the trust and space to take ownership, share ideas, influence decisions, and make a real impact on our customers and our business.
The role
We are hiring a Security Engineer who will be part of the Security Team. This is not a policy-writing desk job and it is not a pure infrastructure role. You will implement and operate the technical controls that our regulatory obligations demand, prove those controls work with real evidence, and help engineering teams build in a way that keeps us compliant by default.
The job splits roughly three ways: finding and fixing vulnerabilities with our engineering teams, hardening our cloud and access controls, and turning DORA, PCI DSS, ISO 27001, FCA and GDPR requirements into controls that actually work rather than documents that merely exist.
What you will do
- Find the vulnerabilities. Run scanning across cloud, endpoints, containers, code and dependencies, cut through the noise, and prioritise by real exploitability rather than raw CVSS score.
- Get them fixed. Work directly with engineering teams to agree fixes and dates, track remediation SLAs, chase what slips, and provide reporting and visibility..
- Harden the platform. Improve our AWS security posture, close misconfigurations, put guardrails into infrastructure as code, and keep secrets and pipelines secure.
- Own access. Run identity and access governance end to end: joiners, movers and leavers, SSO and SCIM coverage, privileged access and periodic reviews.
- Make compliance real. Implement and evidence the controls behind DORA, PCI DSS, ISO 27001, FCA expectations and UK/EU GDPR, and automate the evidence so audits are a query rather than a fire drill.
- Support detection and response. Work with our managed detection and response provider on alert quality and escalation, and play your part in incidents and the reviews that follow.
- Tune log sources and detection rules, write new detection use cases, and keep alert quality high enough that what reaches us is worth looking at.
- Assess third parties. Run security due diligence on vendors, keep the ICT and supplier access register current, and handle inbound security questionnaires.
What you will bring
- 3-5 years in security engineering, security operations or technical security, ideally with some exposure to fintech, payments or another regulated environment.
- Hands-on vulnerability management: running the tools, triaging the output, and persuading engineers to ship the fix.
- Practical cloud security experience, ideally AWS: IAM, networking, logging, encryption, and the misconfigurations that keep coming back.
- Identity and access management in practice: SSO, SCIM provisioning, role design and access reviews.
- Scripting and automation (Python, Bash or similar) to query APIs, gather evidence and remove manual toil.
- Working familiarity with at least one of DORA, PCI DSS, ISO 27001, NIS2 or SOC 2, and the appetite to get fluent in the rest.
- The ability to explain the same technical risk to an auditor and to a software engineer without changing the facts.
- Hands-on SIEM and SOC experience: working with log sources, writing or tuning detection rules, triaging alerts, and running incidents through to resolution.
Why Join Us?
- Make a real difference: Work at the intersection of technology and financial inclusion, helping people take greater control of their money.
- Have a voice: Your ideas and perspective matter. You'll have the opportunity to influence decisions, take ownership and shape how we work.
- Make an impact: Work on initiatives that reach millions of customers across the UK and Europe.
- Work with great people: Join a diverse, international and ambitious team where collaboration and curiosity are encouraged.
- Grow with us: Be part of a fast-moving fintech where you'll have plenty of opportunities to learn, develop and make your mark.
What benefits we offer
We want you to feel supported, valued and able to do your best work - both in and outside the office.
- 25 days annual leave + public holidays, with an extra day for every year worked
- Healthcare: Private medical with Confido, sports compensation with Stebby or discount from a gym.
- 10 paid sick days per year
- Hybrid working + up to 30 days working abroad each year
- L&D budget + 10 paid learning days per year
- Annual eyecare allowance
- Enhanced maternity, paternity and shared parental leave
- VIP Pockit & Monese accounts
- Extra paid days off for your birthday and wedding
- Regular social events and team activities
- Monthly recognition awards and Team of the Quarter
- Share options, depending on role and level
- Employee referral bonus
- Free office parking
The use of AI tools or applications during interviews is not permitted.
We value a fair, transparent, and authentic recruitment process. Candidates are expected to participate in all stages of the interview process personally and to represent themselves accurately.
The use of AI interview proxies, real-time AI co-pilots or answer-generation tools, deepfakes, impersonation, synthetic identities, or any other technology intended to misrepresent a candidate’s identity, skills, experience, or responses during the interview process is strictly prohibited.
Any candidate found to be using such methods will be automatically disqualified from the recruitment process.
We kindly ask all candidates to respect the time and effort invested by both sides and to approach the interview process with honesty, professionalism, and integrity. If you are genuinely interested in the opportunity, we look forward to meeting you and learning about your own experience, skills, and perspective.
JobMatch aggregates public listings. Always apply through the original posting.