> Markdown version of [/jobs/ext/1444912-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/1444912-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Virgin Media - **Location:** London, UK (Remote available) - **Salary:** £52,857.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Encodings, Python (Programming Language), Open Source Technology, Open Web Application Security, Secure Coding, TypeScript, Large Language Models, Software Security, GWAPT, Codebase, Terraform, Devsecops - **Published:** July 26, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5815621994 ## About the Role In order to be considered, the candidate must have the following experience; * Experience assessing security impacts across codebases and APIs using languages such as Java, TypeScript and Python. * Strong knowledge of the OWASP Top 10, secure coding practices, and common web and API vulnerabilities. * Hands-on experience triaging, validating and remediating vulnerabilities with both technical and non-technical stakeholders. * Experience integrating security tooling into CI/CD pipelines and embedding DevSecOps practices. We'd also love you to bring; * Security certifications such as OSCP, GWAPT, CSSLP, CEH or Security+. * Experience securing AWS environments and infrastructure-as-code solutions such as Terraform. * Knowledge of AI-enabled security workflows and securing AI or LLM-powered features. * Experience contributing to or maintaining open-source security tooling. * Proven expertise in threat modelling, secure code review, architecture review, and container/Kubernetes security. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Getting to Know Your Legacy (System) with AI-Driven Software Archeology](https://www.wearedevelopers.com/videos/1437-getting-to-know-your-legacy-system-with-ai-driven-software-archeology) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)