I had been a security engineer at a London fintech for four years, and I had been thinking about leaving for two of them.
The role had a clear ceiling, and there was no way to move sideways into application security, where I wanted to spend more time. I was also homesick for Singapore, where I grew up, and my partner and I had been talking about whether moving back made sense. A close friend from university had joined a Singapore fintech as the platform lead the year before. He had told me more than once that I should apply if a role opened. I did not, mostly because I was waiting for the moment when the move felt right. That moment came in spring. Two friends in London moved away in the same month, and I ran out of reasons to stay. I told my friend. He passed my CV directly to the hiring manager of the security team. The recruiter call happened the same week. The process was five rounds across three weeks. Round one was about application security. Two engineers gave me a real piece of their codebase, a payment authorisation flow, and asked me to find three security problems and three operational risks. I had ninety minutes. I found two security problems quickly, missed the third, and found four operational risks. Afterwards ↓