About the job
About Abound
At Abound, we are revolutionizing consumer lending across the UK and beyond. By leveraging advanced AI and Open Banking data, we are committed to making fair and affordable personal finance accessible to a broader audience. Unlike traditional lenders who primarily depend on credit scores, we assess the complete financial landscape—considering spending habits and repayment capacity—to gain a comprehensive understanding of each customer’s unique financial situation.
Our model has proven successful at scale, with over £1.3bn in loans issued directly to customers, achieving market-leading credit performance; for every ten defaults anticipated by the industry, we experience only three. Remarkably, we reached profitability just 2.5 years post-launch.
Supported by over £2bn+ in funding from prestigious investors including Citi, GSR Ventures, and Deutsche Bank, we are recognized as one of Europe’s fastest-growing fintech companies (Sifted, CNBC). As we expand into new markets and product lines, we seek ambitious individuals eager to learn quickly, take on responsibilities, and grow alongside us.
About the Role:
In this role, you will not be confined to a distant office; instead, you will work closely with our Platform team in a genuine DevSecOps capacity. As a highly skilled individual contributor, you will bridge the gap between product-driven engineering and Corporate IT.
You will engage in a hands-on approach to critically assess the security architecture of both production and corporate IT infrastructures.
Within your first 6–12 months, you will be responsible for designing and implementing our next-generation cloud security architecture across AWS and GCP, while also contributing to the development and maturation of our internal SOC capabilities, including detection and response.
You will oversee Microsoft Sentinel, enhancing our SIEM/SOAR capabilities, and improve identity and access management by automating RBAC across AWS, Microsoft Entra, and internal systems.
Additionally, you will promote a shift-left approach to security by integrating controls into GitLab CI/CD pipelines, including scanning, IaC reviews, and automated policy enforcement throughout the SDLC.
Technology Stack:
Cloud & Compute: AWS, ECS Fargate, Aurora, Lambda, GCP
Data Lake: S3, DMS, Glue
Security & Identity: Microsoft Defender (XDR), Microsoft Sentinel (SIEM/SOAR), Defender for Cloud (CSPM), Microsoft 365, Entra, Intune
Cloud Security Tooling: GuardDuty, Security Hub, Inspector, Security Command Center
Code & Infrastructure: Terraform, GitLab CI/CD

