Application Security Engineer

DGH Recruitment
London, UK
2 days ago
Apply on www.adzuna.co.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
£75,000.0
Working hours
Regular working hours

Tech stack

ASP.NET Java (Programming Language) JavaScript (Programming Language) .NET Framework Application Programming Interfaces (APIs) Amazon Web Services Software Applications Software System Penetration Testing JIRA Authentication Protocols Burp Suite Cloud Computing
+24 more
Programming Tools Github Python (Programming Language) OAuth Open Source Technology OpenID Open Web Application Security Openid Connect Cloud Services Red Team (Cyber Security) Web Application Security Software Engineering Datadog Sonatype Software Security Veracode Gitlab Kubernetes Checkmarx Purple Team (Cyber Security) Blue Team (Cyber Security) Docker Static Application Security Testing Dynamic Application Security Testing

Job description

  • Act as a security champion to foster a secure-by-design approach.
  • Support the identification and analysis of web application security vulnerabilities.
  • Oversee the daily management of application security platforms to maintain coverage, compliance, and remediation of findings.
  • Conduct threat modelling and review application architectures.
  • Implement application security controls and proactive measures to prevent security incidents.
  • Implement and manage SAST/SCA tooling across application repositories to identify source code risks.
  • Scale automated DAST solutions across applications to maximise testing coverage.
  • Carry out penetration testing on internally developed applications.

Technologies:

  • AWS
  • Cloud
  • Datadog
  • Docker
  • GitHub
  • GitLab
  • Support
  • JIRA
  • Java
  • JavaScript
  • Kubernetes
  • OWASP
  • OAuth
  • OpenID
  • Python
  • Security
  • WAF
  • Web
  • ASP.NET
  • API, We are recruiting an Application Security Engineer for a permanent role in London, fully onsite, on behalf of a leading global client in the financial services industry. You will work alongside engineering and IT teams to enhance application security, APIs, and infrastructure by implementing preventative controls and identifying risks through testing. We are looking for someone who speaks the language of developers, thrives in a purple team environment, and has a passion for automation.

Requirements

  • We are looking for someone experienced in application security, with a focus on red team, blue team, or purple team activities.
  • We are looking for someone with software development experience or experience contributing to open-source projects.
  • We are looking for experience with DAST tools such as Burp Suite, OWASP ZAP, or similar.
  • We are looking for experience with SAST/SCA tools such as Snyk, Veracode, Checkmarx, or similar.
  • We are looking for proficiency in one or more of the following languages: Python, JavaScript, .NET, or Java.
  • We are looking for demonstrated experience with development tools including GitLab/GitHub, Datadog, Jira, Docker, and various IDEs.
  • Desirable: experience with cloud services, particularly AWS services like WAF and Cognito.
  • Desirable: experience working with Infrastructure as Code, Kubernetes, and containers.
  • Desirable: experience with authentication mechanisms such as OpenID Connect, OAuth, and identity providers.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.co.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

6:14 min

Structuring CI/CD pipelines with integrated security and quality checks

Christoph Ruggenthaler · LIVE

4:58 min

Scaling security teams through developer advocates

Tanya Janca · World Congress 2021

5:47 min

Integrating user stories and test automation via Jira tools

Christoph Ruggenthaler · LIVE

Videos

See all

Related articles

See all