LemFi Logo

LemFi

Security Engineer

Posted One Month Ago
Be an Early Applicant
Hybrid
London, Greater London, England, GBR
Mid level
Hybrid
London, Greater London, England, GBR
Mid level
Own detection, triage, and response for cloud, endpoint, and SaaS; extend DLP and identity controls; manage MDM/device compliance; run vulnerability scanning and remediation; translate SOC 2/ISO 27001/PCI/DORA requirements into technical controls and automated checks; operate Bug Bounty triage; build scripts and lightweight tools to automate security operations and audit evidence.
The summary above was generated by AI

LemFi (Series B) is building the go-to financial app for the Global South.


Moving to a new country shouldn’t mean starting from zero. That's why our team of 400+ spanning 20+ countries is building a financial ecosystem that helps immigrants stay connected to home, build stability, and create wealth regardless of where they are from or where they live.


What began as fast, affordable remittances is now evolving into a complete platform for multi-currency accounts, payments, credit, and long-term financial growth.


With millions of users across the globe, we process over $1B in monthly transactions to 30+ countries, proving that borders shouldn't limit financial opportunity.

About the role

LemFi is building the financial infrastructure for people the world wasn't built to serve - cross-border payments, multi-currency accounts, savings, credit, and eSIMs across 21 countries and growing. Security is not a checkbox here; it is a core part of how we earn trust with customers, regulators, and partners in some of the most scrutinised payment corridors in the world.

This role sits at the intersection of security engineering, operations, and compliance. You will monitor and respond to real threats, extend our DLP and identity controls, run vulnerability management, and translate audit requirements (SOC 2, ISO 27001, PCI DSS, DORA) into working technical controls. One day you might be triaging a researcher submission through our Bug Bounty programme; the next you are scripting an automated compliance check or briefing a board-level vulnerability report. If you want to own a broad, meaningful security remit at a fast-scaling fintech rather than a narrow lane at a large bank, this is the role.

What you'll build and own
  • Monitor, triage, and respond to security alerts and incidents across cloud, endpoint, and SaaS environments - keeping detection tooling sharp and well-tuned.

  • Own and extend our Data Loss Prevention controls: policy tuning, coverage gap analysis, and coordinating endpoint rollout across the business.

  • Manage device compliance and identity workflows via MDM platforms, including scripting for group management, provisioning, and reporting through REST APIs.

  • Run vulnerability scanning and remediation tracking, and contribute to board-level reporting that gives leadership a clear, honest picture of risk.

  • Translate SOC 2, ISO 27001, PCI DSS, and DORA requirements into working technical controls, evidence collection processes, and automated compliance checks - and support external auditor engagements directly.

  • Operate LemFi's Bug Bounty and Responsible Disclosure programme: triage researcher submissions and coordinate remediation with engineering teams.

  • Build scripts and lightweight tools to cut manual security operations work, improve audit evidence quality, and use AI to accelerate wherever it adds genuine value.

Your experience
  • 2 to 5 years in a security engineering, security operations, or equivalent hands-on technical security role, ideally in fintech, payments, or another regulated industry.

  • Practical experience across at least some of: cloud security (AWS, Azure, or GCP), endpoint and MDM tooling, DLP platforms, identity and access management, and SIEM or alerting tools.

  • Scripting ability sufficient to automate workflows and integrate with REST APIs - you write the script, you don't just find it on Stack Overflow.

  • Working knowledge of at least one major compliance framework (SOC 2, ISO 27001, PCI DSS, or DORA); direct audit-support experience is a strong plus.

  • A clear written communicator who can produce control narratives, incident summaries, and stakeholder-facing documentation that non-technical people actually understand.

  • Comfortable with ambiguity and able to shift between hands-on engineering work and compliance or documentation in the same week without losing momentum.

Nice to have
  • Experience operating or running a Bug Bounty or Vulnerability Disclosure programme.

  • Exposure to building or contributing to a Security Trust Centre or external-facing security documentation.

  • Familiarity with DORA (Digital Operational Resilience Act) requirements in a practical, implementation context.


Why Join LemFi?

Love shouldn’t be expensive, yet those working hardest for their families often face predatory fees and banking exclusion. We're changing this.

At LemFi, you won’t be just a cog in a machine. Whether designing products, scaling operations, or telling our story, you’ll tackle complex challenges with real, immediate impact. Your work goes beyond metrics - it puts money back in families’ pockets and offers access to the previously excluded. Join us to make a meaningful difference, where high performance is a lifeline for millions.
You can connect with us on LinkedIn and Instagram and if you haven't already, download the app on the App Store or Google Play.

HQ

LemFi London, England Office

London, United Kingdom

Similar Jobs

9 Days Ago
Hybrid
Entry level
Entry level
Financial Services
Designs, implements, and maintains enterprise cloud and infrastructure security solutions. Develops secure production code and automation using Python, Bash, and PowerShell; supports IaC, CI/CD, cloud deployments, vulnerability reduction, security controls, and systems integration across Windows and Linux environments. Collaborates with vendors, technical teams, and business leaders to address security needs and improve security protocols.
Top Skills: AWSBashCi/CdInfrastructure As Code (Iac)LinuxPowershellPythonWindows
12 Days Ago
Hybrid
London, England, GBR
Expert/Leader
Expert/Leader
Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Lead enterprise security engineering across cloud and on-premise environments. Design security controls, integrate SAST, SCA, DAST, and container scanning into CI/CD pipelines, conduct vulnerability assessments and audits, develop security standards and data protection strategies, and promote secure development practices. The role also involves responsible use of AI-enabled security workflows, human review, mentoring, and collaboration with engineering and financial-services clients.
Top Skills: AWSAzureBashCi/CdContainer ScanningDastDevsecopsGCPGoIamIso 27001Microsoft Security EcosystemNistOwaspPalo AltoPowershellPythonSastScaSIEMZero Trust Architecture
2 Days Ago
Easy Apply
Remote or Hybrid
London, Greater London, England, GBR
Easy Apply
Senior level
Senior level
Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Operate and improve enterprise endpoint security, visibility, zero trust, and network access systems. Responsibilities include incident triage, anomaly investigation, policy tuning, vulnerability remediation, security documentation, cross-functional collaboration, automation with Python and SOAR platforms, and mentoring security engineers. The role supports security investigations and maintains resilient production security systems at enterprise scale.
Top Skills: Cloud ComputingContainerizationCrowdstrikeDlpEdrEmail SecurityIamMimecast IncydrOsqueryPythonSaseSoarSplunkTerraformThreat Intelligence FeedsZero Trust

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account