> Markdown version of [/jobs/ext/2143170-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2143170-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Simply Business - **Location:** London, UK - **Experience:** Expert - **Salary:** £45,713.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Code Review, Open Web Application Security, Systems Development Life Cycle, Secure Coding, Security Software, Software Engineering, Cloud Platform System, Large Language Models, Software Security, Devsecops, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 20, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5849690864 ## About the Role * Experienced in application security (5+ years) with strong hands-on penetration testing and security tooling skills. * Deeply knowledgeable about web vulnerabilities, secure coding practices, and cloud environments (AWS, Azure, or GCP). * Familiar with DevSecOps methodologies and automated security integration. * An open, clear communicator who can explain complex security concepts in plain English to both technical and non-technical teammates. * Highly collaborative, empathetic, and passionate about mentoring engineers rather than just checking compliance boxes. * Curious, proactive, and keen to stay ahead of modern threat landscapes like AI security. ## Description We're on a mission to build a tech-forward, secure environment that empowers developers rather than putting roadblocks in their way. As an Application Security Engineer, you'll act as a core technical guide across our software development lifecycle-helping us embed security directly into our code and architecture while exploring next-generation defensive strategies like AI/LLM threat modeling. Unlike security roles where you're isolated or acting as a gatekeeper, here you'll be a genuine security champion. You'll partner closely with engineering teams to demystify complex threats, modernise our DevSecOps practices, and mentor developers to build naturally resilient systems. As one of our Application Security Engineers, you'll: * Provide expert guidance on secure coding, threat modelling, and OWASP Top 10 mitigation. * Promote a security-first mindset across development teams, acting as a supportive technical mentor. * Integrate security assessments, code reviews, and penetration testing seamlessly into the SDLC. * Evaluate, implement, and run modern security tooling (SAST, DAST, IAST) to streamline vulnerability checks. * Research emerging AI and LLM threat classes to design proactive, cutting-edge defensive architectures. * Participate in incident response investigations and help deliver engaging security training. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)