Senior Application Security Engineer - London

Additional Resources
London, UK
2 days ago
Apply on www.adzuna.co.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
£25,000.0 - £50,000.0
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Agile Methodology Microsoft Azure Cloud Computing Cloud Computing Security Code Review Cyber Security Continuous Integration Github Python (Programming Language) Systems Development Life Cycle Secure Coding
+12 more
Software Engineering Policy as Code Software Security Kubernetes Azure AKS Data Management Terraform Software Version Control Devsecops Security Orchestration, Automation & Response Static Application Security Testing Dynamic Application Security Testing

Job description

  • We will work closely with engineering and architecture teams to promote secure development from the earliest stages of delivery.
  • We will implement and maintain application security testing solutions, enabling developers to identify and remediate security risks.
  • We will enhance secure development processes by integrating security controls throughout CI/CD pipelines.
  • We will strengthen the security of GitHub Actions and comparable continuous integration and deployment platforms.
  • We will provide technical guidance on secure API design and protecting externally accessible systems.
  • We will support the security of Azure cloud infrastructure, including Azure Kubernetes Service (AKS).
  • We will assist with the protection of cloud-hosted data platforms and associated technologies.
  • We will develop and maintain security-as-code and policy-as-code using appropriate tooling.
  • We will automate security processes through infrastructure-as-code and scripting technologies.
  • We will produce and maintain technical documentation, security procedures and service documentation.
  • We will support development teams with the adoption and integration of security tooling and best practices.
  • We will contribute to wider cyber security initiatives, including threat modelling and compliance activities.

Technologies:

  • API
  • Azure
  • CI/CD
  • Cloud
  • DevSecOps
  • GitHub
  • Support
  • Kubernetes
  • Python
  • Security
  • Terraform

Requirements

  • We are looking for someone who has previously worked as a Senior Application Security Engineer, Lead Application Security Engineer, Principal Application Security Engineer, Application Security Engineer, Senior Product Security Engineer, Product Security Engineer, Senior DevSecOps Engineer, DevSecOps Engineer, Application Security Consultant or in a similar role.
  • We need hands-on experience embedding application security into the SDLC.
  • We need experience securing APIs, internet-facing services, and Kubernetes, preferably AKS, and containerised environments.
  • We need experience working with engineering teams and implementing security testing tools such as SAST, DAST, IAST and SCA.
  • We need knowledge of security automation, security-/policy-as-code, and secure engineering practices including code review, testing, source control and documentation.
  • We need familiarity with CI/CD tools such as GitHub and GitHub Actions.
  • We need strong skills in Terraform and Python.
  • We need a strong understanding of Azure security controls and cloud security governance.
  • We need experience with threat modelling in software engineering contexts.
  • We need knowledge of ISO 27001 and its relevance to secure engineering.
  • We need familiarity with Agile and DevSecOps methodologies.
  • You must be eligible to work in the UK.

Benefits & conditions

We are a well-established health research organisation and charity that supports large-scale medical research to improve disease prevention, diagnosis and treatment. This is a full-time, permanent hybrid role based in Central London, with a salary of 70,000 to 80,000 per annum and an excellent benefits package. The role is a hands-on Application Security position focused on secure design, CI/CD security, cloud-native technologies, Kubernetes, API security, code analysis and security-as-code, working alongside engineering and cloud teams to build, improve and maintain secure applications, platforms and deployment processes. Visa sponsorship is not available.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.co.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

5:01 min

Container hosting options available on Microsoft Azure

Federico Fregosi · World Congress 2022

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

2:46 min

Evaluating managed container services and migration strategies

Adam Bien · World Congress 2021

2:32 min

Overview of Terraform and Terraform Cloud features

Devlin Duldulao · LIVE

Videos

See all

Related articles

See all