Application Security Engineer

The Pokémon Company
London, UK
10 days ago
Apply on www.adzuna.co.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
£64,000.0 - £104,000.0
Working hours
Regular working hours

Tech stack

Amazon Web Services Software System Penetration Testing Cloud Computing Cyber Security Network Layer Software Engineering Software Security Cyber Threat Analysis Vulnerability Analysis

Job description

  • We administer and enforce security policies governing system and application access.
  • We perform application security testing and reviews to ensure secure configurations and compliance with standards.
  • We conduct penetration tests and vulnerability assessments across applications, operating systems, and network layers.
  • We lead threat modeling and security design reviews for new technologies and system changes.
  • We respond to security incidents, isolating threats and removing unauthorized access.
  • We research emerging cybersecurity threats and conduct root cause analysis on issues.
  • We implement technical controls to reduce cloud-based risks, including drift, private-cloud gaps, and web-facing vulnerabilities.
  • We collaborate with Information Security partners to advance roadmaps and shared initiatives.
  • We integrate security testing and controls into development lifecycle phases.
  • We provide management with insights on business impact related to data compromise or system unavailability.
  • We work within an agile framework to deliver iterative improvements toward team and organizational goals.
  • We respond to and investigate cybersecurity incidents, which may be off-hours and on a scheduled rotation.

Technologies:

  • AWS
  • Cloud
  • Incident Management
  • Marketing
  • Network
  • Security
  • Web

Requirements

  • 5-7 years of relevant experience securing cloud environments, primarily AWS, or equivalent expertise.
  • Bachelors degree in a related field or equivalent practical experience.
  • Strong time management, organizational skills, and attention to detail.
  • Solid background in application security engineering and architecture, including MWAF and software development.
  • Demonstrated ability to build partnerships and collaborate with cross-functional teams.
  • Strong communication skills, with the ability to clearly present security risks to senior leadership.
  • Experience managing security vendors and managed service providers.
  • Proven background in incident management and response.
  • Security certifications such as CISSP, GIAC, or CISA are a plus.

About the company

We are The Pokémon Company International, managing the Pokémon property outside of Asia across brand management, licensing and marketing, the Pokémon Trading Card Game, the animated TV series, home entertainment, and the official Pokémon website. Pokémon launched in Japan in 1996 and has become one of the worlds most popular childrens entertainment properties. This role is hybrid and offers an innovative, impact-driven culture, company events, competitive cash-based compensation, 100% employer-paid healthcare premiums for you, generous paid family leave, employer-paid life insurance, employer-paid long and short-term income protection insurance, 401(k) employer matching for US employees, pension employer contributions for UK/IRE/MX employees, fitness reimbursement, commuter benefit, LinkedIn Learning, and a comprehensive relocation package for certain roles.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.co.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

3:17 min

Applying authorization at the network versus application layers

Alex Olivier Alex Olivier · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · World Congress 2024

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:50 min

Configuring gRPC bindings in the OpenSearch YAML

Sakshi Nasha Sakshi Nasha · Europe 2026 Virtual

Videos

See all

Related articles

See all