> Markdown version of [/jobs/ext/2821955-senior-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2821955-senior-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Application Security Engineer - **Company:** Pennylane - **Location:** Greater London, UK (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Cloud Computing, Cloud Computing Security, Code Review, Python (Programming Language), Open Web Application Security, Ruby, Software Vulnerability Management, Scripting, Software Security, Patch Management, Programming Languages - **Published:** September 10, 2026 - **Apply:** https://www.collegerecruiter.com/job/2840611903-senior-application-security-engineer ## About the Role * Ability to perform offensive security assessments on infrastructure and applications. * Know how to exploit and fix a wide range of web vulnerabilities and be able to explain them to non-technical persons (not just the OWASP Top 10). * Experience in a programming language (Ruby, Python, JavaScript) for scripting or larger projects. * Experience in cloud infrastructure security. * Ability to popularize technical terms to facilitate the adoption of security measures within projects or to broadcast messages to peers. * Fluent in French and/or English (both oral and written)., * Humble. * Team player; able to work with remote colleagues. * Proactive and organized. * Quick learner who enjoys working on different projects (application security, cloud infrastructure, training, ISO 27001)., * Speaks English (level assessed and appreciated). * Thrives in a rapidly changing work environment. * Highly collaborative within own team or other stakeholders. * Experienced enough to prioritize business-led actions on a day-to-day basis. ## Description We aim to become the most beloved financial operating system of French SMEs and accounting firms (and soon, European ones). We help entrepreneurs rid themselves of time-consuming tasks related to accounting and finance while providing them with access to key financial information to assist in making the best decisions for their business., * Conduct and perform regular security assessments (internally or through external consulting companies) on the applications (code reviews, pentests, bug bounty in particular) and the infrastructure. * Strengthen the current means of detecting malicious attempts. * Be involved in all security incidents, investigate logs, block attacks, and propose corrective measures to prevent future threats. Compliance & Awareness * Ensure compliance with ISO 27001 controls (processes) related to development (mandatory code practices, validation, patch management, vulnerability management, etc.) by training developers, monitoring projects, conducting regular internal audits, and managing technical non-conformities. * Build or improve secure development training materials and conduct regular training sessions with developers, engaging them in the Security Champions program. * Improve the security awareness throughout the company. * Contribute to tenders to explain our security policies and provide the necessary technical details. ## Related Videos - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Coroutine explained yet again 60 years later](https://www.wearedevelopers.com/videos/690-coroutine-explained-yet-again-60-years-later) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)