> Markdown version of [/jobs/ext/3280166-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/3280166-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Tripadvisor - **Location:** Oxford, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Microsoft Azure, Cloud Computing Security, Code Review, Cyber Security, Identity and Access Management, PCI Data Security Standards, Secure Coding, Software Engineering, Delivery Pipeline, Software Security, Technical Debt, Static Application Security Testing, Vulnerability Analysis, Microservices, Dynamic Application Security Testing - **Published:** September 10, 2026 - **Apply:** https://startup.jobs/senior-application-security-engineer-tripadvisor-9978746 ## About the Role * Extensive experience in application security, including expertise in secure coding practices, threat modelling, vulnerability assessments, and incident response. * Hands-on experience with security testing tools (SAST, DAST) and their integration into development pipelines. * Strong understanding of advanced security concepts such as encryption, secure software design, identity management, and API security. * Experience with cloud security (AWS, Azure, etc.) and securing microservices architectures. * Proven leadership skills, with the ability to guide and mentor other engineers and influence security practices across teams. * Excellent communication and collaboration skills, with a track record of working closely with cross-functional teams to improve security posture. * 4+ years experience working as a Security Engineer / Application Security Analyst, * Experience with regulatory frameworks (e.g., GDPR, PCI-DSS, SOC 2) and their integration into security processes. * Industry-recognised security certifications (e.g., OSCP, OSCE, or similar). * Familiarity with the latest security tools and frameworks to proactively identify vulnerabilities and mitigate threats. * A passion for mentoring and developing others, with a commitment to continuous learning and improvement. ## Description * Lead the design and implementation of advanced application security measures, including encryption, secure APIs, and identity management. * Conduct in-depth threat modelling and risk assessments to identify and mitigate potential security risks. * Performing manual security assessments including code reviews. * Act as a Subject Matter Expert (SME) for security breaches, including performing root cause analysis and creating corrective actions related to security vulnerabilities. * Develop and enforce application security policies across multiple engineering teams, ensuring consistency and scalability. * Mentor and train junior engineers, helping them improve their security knowledge and practices. * Provide expert advice on security architecture and design for new features and systems. * Collaborate with engineering and product teams to integrate security requirements into software development lifecycles. * Champion security initiatives by advocating for prioritisation of security issues and resolution of technical debt. * Stay up to date with the latest security threats and industry best practices, ensuring that the team remains proactive in its approach to security. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Microservices: how to get started with Spring Boot and Kubernetes](https://www.wearedevelopers.com/videos/242-microservices-how-to-get-started-with-spring-boot-and-kubernetes) - [What The Hack is Web App Sec?](https://www.wearedevelopers.com/videos/1343-what-the-hack-is-web-app-sec) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london)