> Markdown version of [/jobs/ext/1418410-senior-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/1418410-senior-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Application Security Engineer - **Company:** Prolific - **Location:** UK (Remote available) - **Experience:** Expert - **Salary:** £87,959.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Application Layers, Business Logic, Architectural Patterns, Burp Suite, Continuous Integration, Data Infrastructure, Django Web Framework, Payment Systems, Python (Programming Language), MongoDB, Open Web Application Security, Secure Coding, Software Engineering, Web Applications, Policy as Code, Google Cloud, Software Security, Vue.js, GWAPT, Terraform, Api Management, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 24, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5812142528 ## About the Role * Several years in application/product security and a background in software engineering * Strong knowledge of OWASP Top 10 (Web & API) and modern attack paths (e.g. auth flaws, SSRF, injection, business logic abuse, supply chain) * Experience working with complex, large-scale systems and modern architectures * Hands-on security testing experience (especially Burp Suite) across web apps and APIs * Python for security tooling, automation, or custom detection (Django a plus) * Experience implementing and tuning SAST, SCA, DAST, and secret scanning in CI/CD * Practical threat modelling experience, including leading lightweight sessions * Strong collaboration skills, able to clearly explain issues and drive remediation * Builder mindset, you automate wherever possible Nice to haves * Experience with Django, Vue.js, MongoDB, GCP * Security champions or bug bounty programmes * Supply chain security (SCA, SBOMs, dependency review) * IaC security (e.g. Terraform, policy-as-code) * Hands-on certifications (OSCP, GWAPT, BSCP) * Experience in scaling environments building out security practices ## Description Prolific is not just another player in the AI space - we are the architects of the human data infrastructure that's reshaping the landscape of AI development. In a world where foundational AI technologies are increasingly commoditized, it's the quality and diversity of human-generated data that truly differentiates products and models. The role Security at Prolific isn't an afterthought, it's foundational to how we build. As a company trusted by world-leading research institutions and AI labs to handle sensitive data at scale, the security of our application layer is critical. We handle participant data, researcher credentials, payment flows, and API integrations that demand rigorous protection at the code level. As a Senior Security Engineer, you'll be the technical authority on application security at Prolific. You'll work hands-on with our engineering teams to find and fix vulnerabilities in our codebase, perform security testing, build security tooling, and embed secure development practices into how we ship software. This isn't a governance or policy role, you'll be in the code, reviewing pull requests, threat modeling new features, and building the automation that keeps our platform secure as we scale. You'll report to the Head of Engineering/Platform and work cross-functionally with product engineering, platform, data, and TechOps teams. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [40 Minutes to Build a Serverless COVID-19 REST and GraphQL APIs](https://www.wearedevelopers.com/videos/208-40-minutes-to-build-a-serverless-covid-19-rest-and-graphql-apis) - [Lessons learned from building a thriving Vue.js SaaS application](https://www.wearedevelopers.com/videos/1666-lessons-learned-from-building-a-thriving-vue-js-saas-application) - [NoSQL Data Modeling for Front-end Developers](https://www.wearedevelopers.com/videos/297-nosql-data-modeling-for-front-end-developers) - [Common Mistakes in Vue.js and How to Avoid Them](https://www.wearedevelopers.com/videos/958-common-mistakes-in-vue-js-and-how-to-avoid-them) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)