LemFi

Security Engineer

LemFi London, England, United Kingdom

Financial Services · 201-500 employees

Yesterday
Remote security Mid (2-5 yrs) Full-time United Kingdom
Log in to apply, save this posting, or score it against your profile with AI.

About the role

You will monitor and respond to security incidents while managing vulnerability assessments and compliance controls across cloud and endpoint environments. Additionally, you will automate security workflows and coordinate with engineering teams to remediate findings from bug bounty programs.

What they look for

Security Engineering Cloud Security DLP Identity And Access Management Vulnerability Management Compliance SOC 2 ISO 27001 PCI DSS DORA Scripting REST APIs Incident Response MDM Bug Bounty Risk Assessment

Requirements

Candidates must have 2 to 5 years of hands-on experience in security engineering or operations within a regulated industry. Proficiency in cloud security, identity management, and scripting for automation is required, along with a working knowledge of major compliance frameworks.

Full description

LemFi (Series B) is building the go-to financial app for the Global South.

Moving to a new country shouldn’t mean starting from zero. That's why our team of 400+ spanning 20+ countries is building a financial ecosystem that helps immigrants stay connected to home, build stability, and create wealth regardless of where they are from or where they live.

What began as fast, affordable remittances is now evolving into a complete platform for multi-currency accounts, payments, credit, and long-term financial growth.

With millions of users across the globe, we process over $1B in monthly transactions to 30+ countries, proving that borders shouldn't limit financial opportunity.

About the role

LemFi is building the financial infrastructure for people the world wasn't built to serve - cross-border payments, multi-currency accounts, savings, credit, and eSIMs across 21 countries and growing. Security is not a checkbox here; it is a core part of how we earn trust with customers, regulators, and partners in some of the most scrutinised payment corridors in the world. This role sits at the intersection of security engineering, operations, and compliance. You will monitor and respond to real threats, extend our DLP and identity controls, run vulnerability management, and translate audit requirements (SOC 2, ISO 27001, PCI DSS, DORA) into working technical controls. One day you might be triaging a researcher submission through our Bug Bounty programme; the next you are scripting an automated compliance check or briefing a board-level vulnerability report. If you want to own a broad, meaningful security remit at a fast-scaling fintech rather than a narrow lane at a large bank, this is the role.

What you'll build and own

  • Monitor, triage, and respond to security alerts and incidents across cloud, endpoint, and SaaS environments - keeping detection tooling sharp and well-tuned.
  • Own and extend our Data Loss Prevention controls: policy tuning, coverage gap analysis, and coordinating endpoint rollout across the business.
  • Manage device compliance and identity workflows via MDM platforms, including scripting for group management, provisioning, and reporting through REST APIs.
  • Run vulnerability scanning and remediation tracking, and contribute to board-level reporting that gives leadership a clear, honest picture of risk.
  • Translate SOC 2, ISO 27001, PCI DSS, and DORA requirements into working technical controls, evidence collection processes, and automated compliance checks - and support external auditor engagements directly.
  • Operate LemFi's Bug Bounty and Responsible Disclosure programme: triage researcher submissions and coordinate remediation with engineering teams.
  • Build scripts and lightweight tools to cut manual security operations work, improve audit evidence quality, and use AI to accelerate wherever it adds genuine value.

Your experience

  • 2 to 5 years in a security engineering, security operations, or equivalent hands-on technical security role, ideally in fintech, payments, or another regulated industry.
  • Practical experience across at least some of: cloud security (AWS, Azure, or GCP), endpoint and MDM tooling, DLP platforms, identity and access management, and SIEM or alerting tools.
  • Scripting ability sufficient to automate workflows and integrate with REST APIs - you write the script, you don't just find it on Stack Overflow.
  • Working knowledge of at least one major compliance framework (SOC 2, ISO 27001, PCI DSS, or DORA); direct audit-support experience is a strong plus.
  • A clear written communicator who can produce control narratives, incident summaries, and stakeholder-facing documentation that non-technical people actually understand.
  • Comfortable with ambiguity and able to shift between hands-on engineering work and compliance or documentation in the same week without losing momentum.

Nice to have

  • Experience operating or running a Bug Bounty or Vulnerability Disclosure programme.
  • Exposure to building or contributing to a Security Trust Centre or external-facing security documentation.
  • Familiarity with DORA (Digital Operational Resilience Act) requirements in a practical, implementation context.

Why Join LemFi?

Love shouldn’t be expensive, yet those working hardest for their families often face predatory fees and banking exclusion. We're changing this.

At LemFi, you won’t be just a cog in a machine. Whether designing products, scaling operations, or telling our story, you’ll tackle complex challenges with real, immediate impact. Your work goes beyond metrics - it puts money back in families’ pockets and offers access to the previously excluded. Join us to make a meaningful difference, where high performance is a lifeline for millions.

You can connect with us on LinkedIn and Instagram and if you haven't already, download the app on the App Store or Google Play.

Similar roles