> Markdown version of [/jobs/ext/2190628-senior-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2190628-senior-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Application Security Engineer - **Company:** Redgate Software - **Location:** Cambridge, UK - **Experience:** Expert - **Salary:** £89,496.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Artificial Intelligence, Amazon Web Services, C Sharp (Programming Language), Code Review, Encodings, Corona (Software Development Kit), Python (Programming Language), Open Web Application Security, Systems Development Life Cycle, Large Language Models, Software Security, Docker, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 23, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5853010750 ## About the Role * Hands-on product or application security experience, embedding security practices across a modern software development lifecycle * Ability to review code and communicate security issues clearly to developers, primarily within a C# ecosystem, with exposure to Java or Python * Strong knowledge of the OWASP Top 10 and practical mitigation patterns * Experience implementing or improving SAST/DAST processes: tool tuning, triage workflows, and reducing signal to noise * Working understanding of cloud and container security fundamentals, ideally with AWS and Docker ## Description This role sits within our Product Security function, embedded across multiple product and engineering teams rather than a single one. You'll define and operationalise security requirements throughout the SDLC, from initial design through to release, with real authority to make independent security calls rather than deferring to what a scanner tells you. It's a role built on trust: teams will come to you for guidance, and the judgement you bring to triage, threat modelling, and governance decisions will shape how security actually gets done here. * Partner directly with engineering and product teams to define and operationalise security requirements across the full SDLC * Own or co-own application security governance: secure-by-default standards, patterns, guardrails, and risk exceptions * Lead threat modelling for new features and architectural changes, turning findings into practical engineering work * Drive SAST/DAST adoption and quality, from tool tuning to severity calibration and developer-facing triage guidance * Support product teams adopting AI, including LLMs, SLMs, and MCP, giving you visibility into work most security roles wouldn't touch ## Related Videos - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [A Brief History of Data Storage](https://www.wearedevelopers.com/videos/974-a-brief-history-of-data-storage) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)