Application Security Engineer

Lorien
London, UK
2 days ago
Apply on www.reed.co.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Part-time / full-time
Compensation
£130,000.0 - £156,000.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Burp Suite Cloud Computing Security Cyber Security Multi-Factor Authentication Github Identity and Access Management OpenID Open Web Application Security Security Assertion Markup Language (SAML) Web Application Security Scripting
+9 more
Okta Software Security Build Management Kubernetes Tenable Nessus Terraform Devsecops Static Application Security Testing Dynamic Application Security Testing

Job description

  • Manage the end-to-end HackerOne lifecycle, from triage to remediation and closure.
  • Support security incident investigations and implement effective fixes.
  • Provide guidance on Okta and Doppler integrations and best practices.
  • Design and build security automation to improve scale and efficiency.
  • Partner with the Director of Cybersecurity on AppSec, DevSecOps, and cloud security initiatives.

Requirements

  • Hands-on experience with HackerOne or similar bug bounty platforms.
  • Strong web application security knowledge (OWASP Top 10, ASVS, threat modelling).
  • Experience building security tooling and automation.
  • Familiarity with security testing tools such as Burp Suite.
  • Exposure to incident response and application security.
  • Strong communication and stakeholder engagement skills.

Desirable Skills

  • Python scripting.
  • SAST, DAST, SCA, and secrets-scanning tools.
  • GitHub Actions, Terraform, Kubernetes, and IAM security.
  • Okta (OIDC, SAML, MFA) and Doppler experience.
  • AWS Cloud Security expertise., * Vulnerability
  • AppSec
  • Bug Bounty
  • pen-testing

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.reed.co.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

5:01 min

Bridging the gap between software development and security

Vandana Verma · LIVE

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas Südbröcker · LIVE

Videos

See all

Related articles

See all