> Markdown version of [/jobs/ext/1372015-lead-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/1372015-lead-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Application Security Engineer - **Company:** CAIS - **Location:** London, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Cloud Engineering, Cyber Security, Continuous Integration, Systems Development Life Cycle, Secure Coding, Software Engineering, TypeScript, Software Vulnerability Management, ReactJS, Software Security, Kotlin, Containerization, Production Code, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** July 22, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=6fd29f3c2110c688 ## About the Role We are looking for a hands-on technical leader who is as comfortable reading production code as setting strategy. You are someone who enjoys partnering with engineers and product owners; you are eager to experiment with new technologies to raise our security bar across the stack, and you are easy to do business with. You see a growing security practice not as a constraint to enforce but as a capability to build, one that helps us ship reliable products, grow as engineers, and have some fun along the way., * Experience in application or product security teams. A software engineering background is * Ability to read and reason about production code and hold your own with senior engineers, with working knowledge of Java/Kotlin and JavaScript/TypeScript (React). * Solid AWS security experience, including securing cloud-native, containerized environments (e.g. EKS). * Hands-on experience with security tooling across the SDLC, such as SAST, DAST, and dependency or container scanning (specific products are not important). * Demonstrated experience driving threat modeling and leading security architecture and design reviews. * Proven ability to lead engineering and security teams in adopting AI tools and automated workflows when it comes to security as part of the SDLC . * A confident, collaborative communicator who partners effectively with engineers and product owners and explains risk clearly to both technical and non-technical audiences. * A builder's mindset, you are energized by growing an application security practice from an early stage, eager to experiment and collaborative along the way. ## Description Secure Software Development & Architecture * Own security elements of the software development lifecycle, designing and implementing automated controls within CI/CD, including SAST, DAST, dependency and container security scanning. * Conduct security architecture and design reviews across product and platform areas, surfacing risk early and providing clear, actionable remediation paths. * Drive CAIS's threat modeling strategy, establishing it as a repeatable practice across teams rather than a one-off exercise. Vulnerability Management & Engineering Partnership * Triage, validate, and prioritize findings, coordinating remediation through to resolution with clear ownership and follow-through. * Liaise with key vendors on penetration testing, vulnerability scanning, and threat modeling, translating external findings into prioritized action. * Partner with engineers and product owners to embed security pragmatically into design, development, and release, supporting teams without becoming a blocker. * Provide secure coding guidance and clear documentation that helps teams understand risk and apply secure development practices independently. * Level up CAIS's security capability across the tech stack, experimenting with new tooling, automation, and AI-assisted workflows as the practice grows. ## Related Videos - [Do TypeScript without TypeScript](https://www.wearedevelopers.com/videos/327-do-typescript-without-typescript) - [Watch Tests Go Brrrr! : Getting Started with Cypress in ReactJS](https://www.wearedevelopers.com/videos/282-watch-tests-go-brrrr-getting-started-with-cypress-in-reactjs) - [Kotlin Multiplatform - True power of native code reuse](https://www.wearedevelopers.com/videos/4-kotlin-multiplatform-true-power-of-native-code-reuse) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [Vuejs and TypeScript- Working Together like Peanut Butter and Jelly](https://www.wearedevelopers.com/videos/127-vuejs-and-typescript-working-together-like-peanut-butter-and-jelly) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [What is Software Engineering in the Age of AI?](https://www.wearedevelopers.com/magazine/640-what-is-software-engineering-in-the-age-of-ai) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)