> Markdown version of [/jobs/ext/2667825-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2667825-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Lorien - **Location:** London, UK - **Salary:** £130,000.0 - £156,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Burp Suite, Cloud Computing Security, Cyber Security, Multi-Factor Authentication, Github, Identity and Access Management, OpenID, Open Web Application Security, Security Assertion Markup Language (SAML), Web Application Security, Scripting, Okta, Software Security, Build Management, Kubernetes, Tenable Nessus, Terraform, Devsecops, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 2, 2026 - **Apply:** https://www.reed.co.uk/jobs/application-security-engineer/57301335 ## About the Role * Hands-on experience with HackerOne or similar bug bounty platforms. * Strong web application security knowledge (OWASP Top 10, ASVS, threat modelling). * Experience building security tooling and automation. * Familiarity with security testing tools such as Burp Suite. * Exposure to incident response and application security. * Strong communication and stakeholder engagement skills. Desirable Skills * Python scripting. * SAST, DAST, SCA, and secrets-scanning tools. * GitHub Actions, Terraform, Kubernetes, and IAM security. * Okta (OIDC, SAML, MFA) and Doppler experience. * AWS Cloud Security expertise., * Vulnerability * AppSec * Bug Bounty * pen-testing ## Description * Manage the end-to-end HackerOne lifecycle, from triage to remediation and closure. * Support security incident investigations and implement effective fixes. * Provide guidance on Okta and Doppler integrations and best practices. * Design and build security automation to improve scale and efficiency. * Partner with the Director of Cybersecurity on AppSec, DevSecOps, and cloud security initiatives. ## Related Videos - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [CI/CD with Github Actions](https://www.wearedevelopers.com/videos/856-ci-cd-with-github-actions) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)