What is Flagstone?
Flagstone is many things. An online savings platform, reinventing how individuals, businesses, and charities manage, protect, and grow their cash. A diverse group of people, bound by a collaborative spirit, and shared purpose. And lastly, a thriving, profitable business – where smart people do their best work.
Each definition shares a common thread: our unique culture. It’s our pride and joy. And our competitive advantage.
A feel for our culture:
To revolutionise the savings market, we need to be at our best. But high performance takes more than talent – it takes a culture of kindness, respect, and growth.
That’s why we’re building a diverse, inclusive community, where your voice is heard and valued. Where, with close support and room to develop, you can surpass even your own expectations. And be rewarded for it.
We may not change the world, but we can change the world of financial technology. And all it takes is a winning mix of drive, talent, and empathy. Our culture celebrates all three.
But enough about us. Let’s talk about you.
Does this sound like you?
We're hiring a Senior Security Engineer to design, build, and continually improve the controls that protect our Azure platform, our paths to production, and our corporate estate.
This is a 6 month contract role, so we're looking for someone who can hit the ground running. You'll bring immediate impact and add value from day one, working independently without a long ramp-up. Your work will be visible, and the problems you solve will matter.
This is a hands-on role where you'll spend most of your time building, and the rest designing and advising on how security should work across the business.
You're an engineer at heart, someone who'd rather ship the control than write the recommendation. You're also the person engineering and technology teams turn to for pragmatic security advice.
What you'll do
Design, strengthen, and maintain our Microsoft Entra ID configuration, including Conditional Access, Privileged Identity Management (PIM), authentication methods, and identity governance
Build and enforce guardrails across the Azure estate using Azure Policy and Defender for Cloud, and drive remediation of posture gaps
Secure our golden paths to production so the secure route is the easiest route, including pipeline controls and secrets management with automated credential rotation
Deliver security tooling and controls as code, and build automation in Python and PowerShell that makes security work faster and less manual
Secure and harden the workforce estate (Intune and Jamf, Microsoft 365, SaaS, and browser security) and implement data loss prevention (DLP) with Microsoft Purview, balancing protection with the way people actually work
Threat model new cloud and platform designs, and turn findings into practical controls that teams can implement
Help deliver AI-assisted security capabilities, and make sure the business's own AI adoption is secure by design, with clear boundaries on where human judgement stays in the loop
What we're looking for
5+ years in security engineering, cloud security, or a closely related role
Strong hands-on experience securing Azure and Entra ID, including Conditional Access and privileged access design
Practical experience with Azure Policy and Defender for Cloud, building guardrails, not just reviewing recommendations
Experience delivering controls as code with Terraform or Bicep, and strong scripting in Python and PowerShell applied to real security work
Experience securing continuous integration and delivery (CI/CD) pipelines and managing secrets, including credential rotation
Ability to threat model systems and translate findings into proportionate controls
A pragmatic, build-focused mindset, with the communication skills to influence engineering teams without direct authority
Nice to have
Experience with DLP in Microsoft Purview, Apple device management (Jamf, Kandji, or Intune for macOS), or SaaS and browser security tooling
Practical experience building AI or large language model (LLM) assisted security automation, with a clear-eyed view of where it helps and where it introduces risk
Familiarity with software supply chain security, such as software bills of materials (SBOMs), artefact signing, and dependency scanning
Experience in a regulated financial services environment (FCA, DORA, or ISO 27001)
AZ-500, SC-200, SC-100, CISSP, or equivalent
About the team
You'll sit within Security Engineering, reporting to the Security Engineering Team Lead. You'll join a small team covering detection engineering, automation, threat intelligence, pipeline security, identity security, and GRC (governance, risk, and compliance).
You'll work closely with Platform Engineering, IT, and Technology, embedding security into how they build and run things rather than bolting it on afterwards.
All are welcome:
At Flagstone, we’re assembling a diverse team that defies our industry’s norms. Think this role could suit you? We encourage you to apply, no matter your background.
Discovering Direct IT Contract Opportunities for Contract Spy members.