Revolut
Graduate Programme 2027: Information Security Engineer (Appsec)
At a Glance
About This Role
Responsibilities
- Running SAST and DAST security scans to identify vulnerabilities and common OWASP issues
- Reviewing system configurations and security controls to identify potential risks and areas for improvement
- Documenting findings from security assessments and collaborating with engineers to support remediation efforts
- Researching emerging security threats and contributing to security knowledge sharing across the team
- Participating in security reviews, training sessions, and team discussions
- Supporting developers by identifying security issues and recommending improvements throughout the development lifecycle
- Working closely with senior engineers to deepen your technical expertise and expand your security knowledge
Requirements
- A predicted or achieved 2:1 degree, or equivalent grade
- A bachelor's or master's degree in a relevant field, such as computer science, maths, physics, or another STEM subject
- To have graduated in 2025, 2026, or 2027
- A portfolio of coding projects or open-source contributions
- Solid problem-solving skills
- A proactive, ambitious, and results-driven mindset
- Fluency in English
- Great communication and organisational skills
- Confidence working in a fast-paced, team-driven environment
- Full-time availability from early or late 2027
- The ability to travel to a Revolut office in your country of employment
- A willingness to attend the office at least 3 days per week (this is a hybrid role)
Benefits & Perks
About Revolut
Revolut is a London-based neobank and financial superapp founded in 2015 by Nikolay Storonsky and Vlad Yatsenko. The company aims to simplify money management by providing faster and more affordable alternatives to traditional banking services, including foreign exchange and transfers. With a mission to eliminate middlemen and empower users globally, Revolut offers a seamless mobile app that supports multi-currency transactions and innovative financial tools. Since its launch, Revolut has rapidly expanded its user base, reaching over 50 million customers by 2024, including more than 30 million personal users and over 500,000 business users. The app features a comprehensive suite of financial products, such as multi-currency accounts, international money transfers, spending analytics, and investment options. Revolut Business provides corporate banking solutions, expense management, and payroll tools, catering to the needs of businesses worldwide. The company operates in over 35 countries and processes more than $1 trillion in transactions annually, positioning itself as a leader in the digital finance space.
Security at Revolut
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
- Revolut's AppSec philosophy is "developer-first" and explicitly "shift-left," prioritizing low-noise automation and auto-remediation over manual vulnerability management.
- Risk is addressed through "risk-based change review processes" embedded in product releases, with AppSec engaged "within the Software Development Life Cycle.".
Security Team
**Org Structure & Reporting Line:** AppSec sits within the **Information Security** function. Reporting chain above Information Security: Information not publicly available. **Key Public-Facing Leaders:** 1. **Arsalan Ghazi** – Head of AppSec, Revolut (named in Aikido Blog, Revolut Tech Medium) 2. **Pedro Moura** – AppSec Engineer (co-author of Security Drone and DARC) 3. **Krzysztof Pranczk** – Engineer (author on CI/CD security assurance) 4. **Victoria Fox** – Global Head of Security, Safety, Facilities and Real Estate (broader remit) **Team Size Estimate:** Information not publicly available. Named individuals suggest a small-to-mid team, but no headcount figure is published. **Active AppSec Job Postings (as_of:):** - **Count:** 4 postings (Lead AppSec Engineer – London; AppSec Engineer – multi-location; AppSec Intern; Info Sec Grad Ops) - **Common Skill/Tool Patterns:** Java, Swift, Python, Scala; Python/bash automation; SAST/DAST skills; "An understanding of DevSecOps"; source code reviews; web/mobile app security testing; managing external testing/bug bounty
Key Initiatives
**Documented Initiatives:** - SCA rollout (Aikido Security, Nov 2025) – vendor-confirmed - Shift-left CI/CD security tooling (Security Drone, DARC) – - Bug bounty / VDP via Intigriti - Responsible disclosure program (revolut.com/responsible-disclosure-program/) - Active hiring: Lead AppSec Engineer, AppSec Engineer, AppSec Intern, Info Sec Grad Ops **Security Champions Program:** No Evidence Found in public sources. **Not Publicly Documented:** Security Champions program, formal SLAs/MTTR, named SDLC ceremonies, threat-modeling cadence, SAST/DAST/Secrets/CSPM/GenAI tool selections.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.
Interested in this role?
Apply on LinkedIn