Join Monzo's Mission: A Revolutionary Approach to Banking and Security
Overview
£45000
London
Expires at anytime
Organisation summary
Monzo is transforming the banking industry with its innovative financial solutions, and commitment to customer service and financial education. With a focus on problem-solving rather than product selling, Monzo uses technology to create a secure, user-friendly banking experience. Join a team that values diversity and aims to make money work for everyone.
Role Summary
- Be part of the Security Operations Squad focused on cybersecurity threat detection and incident response.
- Work within the larger Security Collective, contributing to the overall safety of Monzo's banking environment.
- Utilize security tools to monitor, analyze, and manage risks to the IT estate.
- Develop and produce reports and dashboards to enhance security awareness.
- Investigate security breaches and manage incident responses.
- Advise other teams on best security practices and maintain up-to-date industry knowledge.
- Support the operation of security tools and contribute to the maintenance of security policies.
Role Requirements
- Solid hands-on experience in a SOC environment.
- Knowledge of SIEM, SOAR, IAM, DLP tools, and technologies.
- Familiarity with Cyber Kill Chain, Incident Response Phases, adversarial TTPs, and Mitre ATT&CK.
- Understanding of network attacks, security monitoring tools, and a pragmatic approach to technology application.
- Experience in technology areas such as End-User Computing, Hosting, Networks, Cloud, or Development.
- Knowledge of information security principles, practices, and attacker techniques.
- Ability to communicate complex information effectively to technical and non-technical audiences.
- Enthusiasm for Monzo's mission and vision.
Application Process Details
- Initial call with a Monzo Recruiter.
- Video-call interview with the Hiring Manager (30 mins).
- Interview Loop with two video-interviews.
🚀 We’re on a mission to make money work for everyone.
We’re waving goodbye to the complicated and confusing ways of traditional banking.
With our hot coral cards and get-paid-early feature, combined with financial education on social media and our award winning customer service, we have a long history of creating magical moments for our customers!
We’re not about selling products - we want to solve problems and change lives through Monzo ❤️
Hear from our team about what it's like working at Monzo ✨
📍London OR UK remote | 💰Up to £45,000 + Benefits | Hear from the team ✨
We are looking for a proactive, technically-minded and organised Security Operations Analyst to join us in the bank’s 1st line of defence, which has the ownership, responsibility and accountability for directly assessing, controlling and managing risk.
This role is part of Monzo’s Security Collective which has a wide range of responsibilities, from infrastructure security to application and information security.
⭐Our Security Operations team (SecOps)
For this role you'll be joining the Security Operations Squad at Monzo. We are a squad dedicated to detection and investigation of potential cybersecurity threats to Monzo and its customers, providing effective incident response where necessary.
You will also be joining the wider Security Collective, a group of people passionate about making Monzo a safer place to work and bank with, to make money work for everyone.
As a bank, we are solving diverse, novel problems to ensure that our customers and data are secure, you will have the opportunity to make a direct impact on that.
One of the guiding principles of security at Monzo is that security at the expense of user experience is a last resort. We aim to move mountains in the background such that we can build world-class features without compromising on security.
🔑 What you’ll be working on (key responsibilities)
The goal of the Security Operations squad is to minimise and control the damage resulting from cybersecurity incidents, provide practical guidance for the response, coordinate recovery activities, and work to prevent future incidents from reoccurring.
Additionally, you will be helping with the monitoring of information security controls within Monzo by analysing alerts received in line with our information security policies and practices and dealing with any/all security incidents.
Analytics
- Using raw log sources and other security and operational tools to monitor and analyse the security posture of the IT estate and identify anomalous activity and behaviours.
- Investigating, defining and resolving complex issues.
- Reviewing, updating and creating detection rules
- Producing and developing dashboards and reports to continuously improve security situational awareness.
- Producing incident reports to present activity and outcome of operational security services and activity.
Incident management
- Supporting the investigation of security breaches and coordinating and managing all Incident Responses.
- Ensuring that all security incidents have been correctly prioritised and diagnosed in accordance with agreed procedures.
- Investigating the causes of incidents, document findings and seek resolution.
- Making sure the escalation of any unresolved incidents has been completed according to agreed procedures.
- Overseeing the facilitation of recovery, following the resolution of incidents.
- Making sure security incidents have been documented and closed according to agreed procedures.
Information security
- Acting on security incidents, requests and events to ensure that threats, vulnerabilities and breaches are managed to minimise impact to confidentiality, integrity and availability of systems and data.
- Creating security risk, vulnerability assessments, and business impact analysis as required.
- Reviewing, updating and creating CSIRT policies, playbooks and standard operating procedures documentation.
- Providing advice and guidance to other teams within the business on good practice and maintaining relevant and current industry knowledge.
Security administration
- Oversee the operation or support the operation of tools that contribute to effective security including anti-virus and vulnerability management.
- Making sure that the onboarding of any enhancements to the security tools, including deployment and on-going management and maintenance is completed.
- Undertaking periodic reviews of security policies and baseline control standards, influencing additional and updated controls based on the findings of internal and external audit reports, trends derived from security operations, information from project-based activities and incident resolutions.
🤩We’d love to hear from you if…
- You have solid, hands-on experience in a SOC environment
- You have knowledge of SIEM and SOAR solutions, Identity and Access Management and Data Loss Prevention tools and technologies
- You have working knowledge of the Cyber Kill Chain and/or Incident Response Phases and adversarial tactics, techniques, procedures (TTPs) and industry standard frameworks (Mitre ATT&CK).
- You have experience with the approaches threat actors take when attacking a network, including phishing, port scanning, web application attacks, DDoS, lateral movement.
- You have experience with Security Monitoring tools.
- You can take a pragmatic view of the application of technologies; understanding the business application of them and being able to identify a balance between the management of risk and the capability for the business to continue to operate.
- You have in-depth experience of at least one of the following technology areas; End-User Computing/Hosting/Networks/Cloud/Development.
- You have knowledge of commonly-accepted information security principles and practices, as well as techniques attackers use to identify vulnerabilities, gain unauthorised access, escalate privileges and access restricted information.
- You communicate well and can present complex information to both technical and non-technical audiences.
- You’re excited by what we’re doing at Monzo
🙌 What’s in it for you
💰Up to £45,000 ➕benefits & share options.
📍This role can be based in our London office, but we're open to distributed working within the UK (with ad hoc meetings in London)
⏰ We offer flexible working hours and trust you to work enough hours to do your job well, and at times that suit you and your team.
📚 £1,000 learning budget each year to use on books, training courses and conferences.
🏡 We will set you up to work from home; all employees are given Macbooks and for fully remote workers we will provide extra support for your work-from-home setup.
➕ Plus lots more! Read our full list of benefits.
🌈 The application journey has 3 key steps
- Short call with a Monzo Recruiter
- Initial video-call with the Hiring Manager (30 mins)
- Interview Loop (2 x video-interviews)
This process should take around 2-3 weeks - your schedule is really important to us, so we promise to be as flexible as possible!
You’ll hear from us throughout the application process, but if you’ve got any questions, please reach out to [email removed - click apply for more details] You can also use this email address to let us know if there’s anything we can do to make the process easier for you because of disability, neurodiversity or anything else.
⏳The closing date for applications is 6pm on 24th July
#LI-REMOTE
#CM-1
Equal opportunities for everyone
Diversity and inclusion are a priority for us and we’re making sure we have lots of support for all of our people to grow at Monzo. At Monzo, we’re embracing diversity by fostering an inclusive environment for all people to do the best work of their lives with us. This is integral to our mission of making money work for everyone. You can read more in our blog, 2023 Diversity and Inclusion Report and 2023 Gender Pay Gap Report.
We’re an equal opportunity employer. All applicants will be considered for employment without attention to age, ethnicity, religion, sex, sexual orientation, gender identity, family or parental status, national origin, or veteran, neurodiversity or disability status.
If you have a preferred name, please use it to apply. We don't need full or birth names at application stage 😊