> Markdown version of [/jobs/ext/3100841-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/3100841-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** DGH Recruitment - **Location:** London, UK - **Salary:** £75,000.0 - **Contract:** Permanent contract - **Skills:** ASP.NET, Java (Programming Language), JavaScript (Programming Language), .NET Framework, Application Programming Interfaces (APIs), Amazon Web Services, Software Applications, Software System Penetration Testing, JIRA, Authentication Protocols, Burp Suite, Cloud Computing, Programming Tools, Github, Python (Programming Language), OAuth, Open Source Technology, OpenID, Open Web Application Security, Openid Connect, Cloud Services, Red Team (Cyber Security), Web Application Security, Software Engineering, Datadog, Sonatype, Software Security, Veracode, Gitlab, Kubernetes, Checkmarx, Purple Team (Cyber Security), Blue Team (Cyber Security), Docker, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 27, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5899590012 ## About the Role * We are looking for someone experienced in application security, with a focus on red team, blue team, or purple team activities. * We are looking for someone with software development experience or experience contributing to open-source projects. * We are looking for experience with DAST tools such as Burp Suite, OWASP ZAP, or similar. * We are looking for experience with SAST/SCA tools such as Snyk, Veracode, Checkmarx, or similar. * We are looking for proficiency in one or more of the following languages: Python, JavaScript, .NET, or Java. * We are looking for demonstrated experience with development tools including GitLab/GitHub, Datadog, Jira, Docker, and various IDEs. * Desirable: experience with cloud services, particularly AWS services like WAF and Cognito. * Desirable: experience working with Infrastructure as Code, Kubernetes, and containers. * Desirable: experience with authentication mechanisms such as OpenID Connect, OAuth, and identity providers. ## Description * Act as a security champion to foster a secure-by-design approach. * Support the identification and analysis of web application security vulnerabilities. * Oversee the daily management of application security platforms to maintain coverage, compliance, and remediation of findings. * Conduct threat modelling and review application architectures. * Implement application security controls and proactive measures to prevent security incidents. * Implement and manage SAST/SCA tooling across application repositories to identify source code risks. * Scale automated DAST solutions across applications to maximise testing coverage. * Carry out penetration testing on internally developed applications. Technologies: * AWS * Cloud * Datadog * Docker * GitHub * GitLab * Support * JIRA * Java * JavaScript * Kubernetes * OWASP * OAuth * OpenID * Python * Security * WAF * Web * ASP.NET * API, We are recruiting an Application Security Engineer for a permanent role in London, fully onsite, on behalf of a leading global client in the financial services industry. You will work alongside engineering and IT teams to enhance application security, APIs, and infrastructure by implementing preventative controls and identifying risks through testing. We are looking for someone who speaks the language of developers, thrives in a purple team environment, and has a passion for automation. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) ## Related Articles - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)