> Markdown version of [/jobs/ext/1245092-applications-security-engineer](https://www.wearedevelopers.com/jobs/ext/1245092-applications-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Applications Security Engineer - **Company:** RealVNC - **Location:** Cambridge, UK (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Microsoft Windows, Application Programming Interfaces (APIs), Artificial Intelligence, Android Software Development, Apple IOS, Apple Mac Systems, Software System Penetration Testing, Burp Suite, C++ (Programming Language), Code Review, Cyber Security, Linux, DevOps, Mobile Application Software, Python (Programming Language), Systems Development Life Cycle, Secure Coding, Software Engineering, SQL Injection, Software Security, Cyber Threat Analysis, Cross-Site Scripting (XSS), Deployment Automation, Synopsys Black Duck, Devsecops, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** July 12, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=6fe042eeb4b2ee5f ## About the Role You; * Have hands-on experience with DAST, IAST and penetration testing tools (e.g., Burp Suite, OWASP ZAP, Frida), and can manually identify and exploit vulnerabilities beyond what these tools surface automatically. * Can demonstrate independent, hands-on technical ability, for example through CTF experience, bug bounty history, HackTheBox/TryHackMe rankings, or a technical portfolio, rather than relying on AI-assisted tooling to do the analysis for you. * Have 3-5 years' experience in an application security, penetration testing, or software engineering role with a strong security focus. * Have a strong understanding of secure SDLC and DevSecOps principles. * Strong understanding of application security principles and common vulnerabilities (e.g., XSS, SQL Injection, Broken Access Control). * Have experience with Static Application Security Testing (SAST). * Have practical experience using software composition analysis (SCA) tools such as Blackduck, Mend/Whitesource, Snyk or similar. * Can easily explain complex security concepts to non-technical stakeholders and write clear security reports. * Work well with a wide range of stakeholders as part of a cross-functional team, including system administrators, developers, network engineers and information security compliance. * Have proficiency in secure coding practices (Java, Python, C++ or similar). * Are familiar with common Operating Systems - Windows, Linux, macOS, Android and iOS. ## Description We are seeking a highly skilled Applications Security Engineer to join our Cyber Security team, helping to ensure security is embedded throughout the Software Development Lifecycle (SDLC). This is a hands-on technical role: we need someone who can identify, analyse, and help mitigate vulnerabilities in our applications throughout the development lifecycle. This role exists to protect our customers and reputation by making sure security is tested into our products before they ship. You will work closely with Security, Development and QA teams to embed robust, evidence-based security practices throughout our software delivery process., * Conduct manual penetration testing and vulnerability assessments across various environments including web, API, desktop and mobile applications. * Execute Dynamic Application Security Testing (DAST) on running applications, focusing on XSS, SQL Injection, Broken Access Control etc., manually confirming exploitability beyond what scanners or AI analysis reports. * Use Interactive Application Security Testing (IAST) tools for runtime analysis, such as Burp Suite, OWASP ZAP, Frida, applying hands-on technique to validate and extend automated results. * Conduct Static Application Security Testing (SAST) and Software Composition Analysis (SCA) on source code and binaries, manually triaging findings to separate real risk from noise, using AI tools to accelerate initial triage where helpful. Secure Design & Threat Modelling * Ensure the foundation is secure from the start by conducting threat modelling and risk assessments during design phases. * Provide security requirements for new features and architecture reviews. Development & Code Assurance * Perform secure code reviews and advise developers on ensuring security best practises are followed. * Make use of AI-assisted code review tools to speed up initial passes, while personally validating any flagged issue against actual code behaviour. * Collaborate with engineering teams to integrate security into development workflows. Deployment & Monitoring * Partner with DevOps to advise on secure configurations and hardening in production environments. * Support incident response and remediation of application-level vulnerabilities. Threat Intelligence, Governance & Training * Keep up to date with industry news, vulnerability announcements and guidelines. * Deliver secure coding training and promote a positive security posture., * Leveraging AI to help drive efficiency in day-to-day workflows. * Exploit development activities, such as exploiting buffer overflows, crafting shellcode or analysing patches. * Knowledge and understanding of Cyber Security frameworks such as NIST Cybersecurity Framework. * Regulatory compliance - knowledge of GDPR, ISO-27001 and SOC2. * Details of any security-based qualifications., We work in a hybrid environment where employees combine working remotely and working from the office to facilitate a high-performance working environment - with the ability to collaborate effectively and build a cohesive team bond whilst being able to focus and deliver quality results. With this in mind, you will need to easily be able to commute to Cambridge and / or London. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)