Apply Edge Start your job search

Cyber Security Engineer

Privalgo · City Of London, England, United Kingdom

Apply & track with Apply Edge
About UsPrivalgo is an FCA-authorised international payments and foreign exchange specialist, helping businesses send, receive, manage and optimise cross-border payments worldwide. Founded in 2018 and headquartered in London, Privalgo combines innovative payment technology with dedicated relationship management to deliver secure, efficient and tailored global payment solutions. Operating across more than 95 countries and supporting over 140 currencies, we enable organisations to streamline international transactions, manage currency risk and access a seamless multi-currency payment infrastructure.Position OverviewThe Cyber Security Engineer will play a pivotal role in safeguarding the digital assets, systems, and data of our organisation. The successful candidate will provide technical leadership, strategic guidance, and hands-on expertise to ensure that our products, infrastructure, and services remain secure and compliant in a rapidly evolving threat landscape. This role involves close collaboration with technology, compliance, and business teams to embed robust security practices across the business.Key ResponsibilitiesHands On Development / Code Review:Develop, implement, and continuously refine the minimum engineering and architectural security standards for all code and continuously monitor for deficiencies and branches of required practice within the development team.Coaching, mentoring, and education of engineers on and offshore to ensure they understand what secure code looks like and how to produce itSecurity Architecture & Engineering:Design and maintain secure network and application architectures; oversee secure software development lifecycle (SDLC) practices; ensure encryption, authentication, and authorisation controls are robust.Develop Automated Security Testing / Continuous Evaluation:Develop, implement, and continuously refine preferably automated tooling and reporting to perform some level of dynamic penetration testing of systems and reporting of vulnerabilities.Incident Response & Investigation:Lead incident response activities, including detection, containment, eradication, and recovery. Conduct forensic investigations and post-incident reviews, reporting findings to senior management.When we come under new or sustained attack, be front and centre owning our response and mitigation, taking the lead and organising across technology to repel the attempted intrusion.Risk Assessment & Management:Identify, evaluate, and mitigate cyber risks related to PSP operations, including payment processing systems, customer data, and third-party integrations. Conduct regular risk assessments and vulnerability scans.Security Strategy & Leadership:Develop, implement, and continuously refine the cyber security strategy for the organisation, aligning with business goals and regulatory requirements. Advocate for security best practices across all teams.Compliance & Regulatory Adherence:Ensure compliance with relevant regulations (e.g., PCI DSS, GDPR, PSD2), standards, and best practices. Liaise with auditors and regulators as required.Security Awareness & Training:Develop and deliver cyber security awareness programmes for staff. Mentor and guide junior engineers and other stakeholders on security matters.Third-Party & Vendor Security:Evaluate and manage the security posture of third-party vendors and partners, ensuring contractual obligations and technical controls are enforced.Continuous Improvement:Stay abreast of the latest cyber threats, technologies, and regulatory changes. Continuously assess and improve the organisation’s security posture.Required Skills & ExperienceBachelor’s or Master’s degree in Computer Science, Information Security, or related field.Proven experience (5+ years) in cyber security engineering, preferably within fintech, banking, or payment services. Ideally you would be a purple teamer from a midsized business, with strong hands-on experience, looking to take the next step up to owning the function, building a team, and setting a world class standard.Expertise in network security, application security, cloud security, and data protection.Demonstrable experience with security tools (SIEM, IDS/IPS, vulnerability scanners, endpoint protection).Hands-on experience in incident response, threat hunting, and forensic analysis.Excellent communication, leadership, and stakeholder management skills.Relevant certifications (e.g., CISSP, CISM, CEH, PCI Professional) highly desirable.Personal AttributesAnalytical and detail-oriented, with a pragmatic approach to problem-solving.Proactive and adaptable, able to thrive in a fast-paced, high-stakes environment.Strong ethical standards and a commitment to confidentiality.Ability to lead and inspire cross-functional teams.