Application Security Engineer
We are seeking an Application Security Engineer to strengthen the security of software applications throughout their development lifecycle. In this role, you will work closely with software engineers, architects, DevOps specialists and product teams to identify, assess and reduce application security risks. You will help embed secure development practices into design, coding, testing and deployment, while promoting a practical, risk-based approach to security across the technology environment.
Your responsibilities will include conducting threat modelling, secure code reviews, vulnerability assessments and penetration testing across web, mobile and application programming interface (API) platforms. You will support the implementation and optimisation of application security tooling, including static and dynamic application security testing, software composition analysis and secrets detection. You will analyse findings, validate vulnerabilities, prioritise remediation and provide clear, actionable guidance to technical teams. You will also contribute to security standards, policies, architecture reviews, developer training and security champions programmes, while monitoring emerging threats and industry best practice.
The successful candidate will have professional experience in application security, software engineering, penetration testing or a closely related discipline, together with a strong understanding of the secure software development lifecycle. You should be familiar with common vulnerabilities and attack techniques, including those identified by the OWASP Top 10, and be confident working with modern programming languages, APIs, cloud services, CI/CD pipelines and version control systems. Experience with security automation and tools such as SAST, DAST, SCA, container security or cloud security platforms is desirable. Strong communication, problem-solving and stakeholder management skills are essential, along with the ability to explain technical risks to both specialist and non-specialist audiences. Relevant certifications, such as OSCP, GWAPT, CSSLP or equivalent practical experience, would be advantageous.
Application Security Engineer
Other similar jobs
Popular job searches
Your next job
starts here.
JOB SPECIALISMS
LATEST JOBS
TOP SEARCHES
LOCATIONS
- Security Engineer
- Security Analyst
- Security Architect
- IT Security Manager
- Security Consultant
- SOC Analyst
- Identity Access Management IAM
- Cyber Security Consultant
- Cloud Security
- Application Security
- Incident Response
- Penetration Tester
LATEST JOBS
- Security Engineer (Contractor)
- Vice President, Field CISO Com...
- Microsoft 365 & Security Infra...
- Senior ICT Security Designer
- Data Protection Expert
- Data Protection Officer: Schoo...
- Data Protection Officer
- IT CONSULTANT (IT Management,...
- Technology and Cyber Employee...
- Cyber Security Consultant
- Cyber Security Consultant (Pen...
- Platform and Services Engineer...