-
Funding Circle
- London
- Funding Circle - London
Our core product is a two-sided marketplace where we connect small businesses looking for funding with investors via our scalable online platform. Our engineering team is the driving force behind our marketplace business model and is integral in building sustainable and scalable infrastructure. It is our competitive advantage and core to our business – if we can’t excel at it then the model doesn’t work. This is where you come in!
Our mission: to build a better financial world.
- Performing technical security assessments on our web applications and mobile applications
- Tracking and responding to issues detected during internal reviews or reported via our Vulnerability Assessment and Penetration Testing
- Maintaining and creating secure development practices and programs for our engineering teams
- Seeking out opportunities to automate processes when appropriate
- Communicating risks effectively to engineering staff through training and technical demonstration of vulnerabilities
- Identifying risk in code, applications, processes, and architecture
- Familiarity with common web application testing tools such as Burp Suite, Fortify, Brakeman Pro, etc.
- Knowledge of common security flaws and resolution as published by OWASP, SANS, etc.
- Ability to learn new technologies quickly and provide appropriate security advice
- Good understanding of web application architecture and design principles
- Strong written and verbal communication skills and communicate with empathy when delivering constructive feedback regarding security matters to engineers and product designers
- Should have knowledge or keen to learn how to test code and applications across various platforms for security
- Current or former security training or certifications such as SANS GWAPT, GPEN, OSCP or similar is a plus
- Experience with manual secure code review in languages such as: Java, JavaScript, Ruby
- Background in software engineering and common development practices in a collaborative and dynamic environment
- Experience with AWS services
*The stated experience level is a guide and does not preclude applications from candidates with more or less experience, provided the requisite skills can be demonstrated.
Note: This role will be part of an on call rota.
We’d love to find out more about you, so send us a link to your Github, Stackoverflow & LinkedIn profile.
Please note – you must have proof of eligibility to work in the UK