> Markdown version of [/jobs/ext/1342147-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/1342147-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Prima - **Location:** UK (Remote available) - **Contract:** Permanent contract - **Skills:** Agile Methodology, Amazon Web Services, Software System Penetration Testing, Code Review, Computer Programming, Continuous Integration, Python (Programming Language), Open Web Application Security, Security Information and Event Management, Mobile Security, Software Engineering, Pulumi, Software Security, Kubernetes, Cloudflare, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 19, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=ea841e05ae620540 ## About the Role * Strong knowledge of web/mobile security vulnerabilities, AI security risks, and industry standards (e.g., OWASP Top 10, CWE). * Hands-on experience with threat modeling frameworks (e.g., STRIDE), code reviews, penetration testing, and SAST/DAST/SCA tools. * Proficiency in scripting/programming (e.g., Python, Rust) and experience with CI/CD systems and Infrastructure as Code (e.g., Pulumi). * Availability for on-call shifts to guarantee 24x7 security monitoring and support. * Self-motivated and proactive problem-solvers with strong English communication skills and experience in Agile environments., * Practical experience with secure AWS design/implementation and Kubernetes (EKS) security. * Hands-on experience with WAF configurations (e.g., Cloudflare) and EDR, SIEM, or SOAR platforms. * Relevant industry certifications (e.g., OSCP, OSWA/E, BSCP, PWPA/E, eWPT, or similar). * Active involvement in security research, bug bounty programs, or CTF competitions. Why you'll love it here Work Your Way: Enjoy full flexibility - work from home, the office or a mix of both. Plus, work from anywhere for up to 30 days a year. This is a full remote position and we're considering candidates located in Italy, Spain or UK. ## Description Since 2015, we've been using our love of data and tech to rethink motor insurance and bring drivers a great experience at a great price. Our story began in Italy, where we've quickly become the number one online motor insurance provider. In fact, we're trusted by over 5 million drivers. And now we're expanding to help millions more drivers in the UK and Spain. To help fuel that growth, we need a Application Security Engineer to join our Security Engineering Team. The Engineering Department is the beating heart of Prima. You'll be joining over 350 engineers across software development, infrastructure, operations and security: fueled by curiosity, experimentation and collaboration, you'll help deliver scalable, impactful solutions that shape the future of insurance. Excited to make an impact? Here are the details, * Define security requirements and design application architectures following a secure-by-default approach. * Conduct threat modeling, code reviews, and penetration testing on cloud-based web and mobile apps to proactively identify vulnerabilities. * Implement, manage, and automate SAST/DAST/SCA security controls and WAF rules to enforce protection at scale. * Partner with Product teams to ensure robust protection and foster a security-first development culture. * Participate in the investigation, management, and resolution of security alerts. * Collaborate on all core activities and initiatives of the Security Engineering team. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Fireside Chat with Cloudflare's Chief Strategy Officer, Stephanie Cohen (with Mike Butcher MBE)](https://www.wearedevelopers.com/videos/1366-fireside-chat-with-cloudflare-s-chief-strategy-officer-stephanie-cohen-with-mike-butcher-mbe) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Why segmenting your infrastructure into tiers makes your infrastructure design better](https://www.wearedevelopers.com/videos/1960-why-segmenting-your-infrastructure-into-tiers-makes-your-infrastructure-design-better) - [WebAssembly: The Next Frontier of Cloud Computing](https://www.wearedevelopers.com/videos/886-webassembly-the-next-frontier-of-cloud-computing) - [Instant KAI Sandboxes with vCluster: Multi-Tenant, Multi-Scheduler GPU Sharing](https://www.wearedevelopers.com/videos/100333-instant-kai-sandboxes-with-vcluster-multi-tenant-multi-scheduler-gpu-sharing) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Find a Developer Job: 12 Best Job Sites For Developers](https://www.wearedevelopers.com/magazine/165-find-a-developer-job-12-best-job-sites-for-developers) - [Best Job Boards for Remote Work for Developers](https://www.wearedevelopers.com/magazine/290-best-job-boards-for-remote-work-for-developers) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)