Offensive Application Security Engineer

Cytix
Manchester, UK
3 months ago
Apply on indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
£40,000.0 - £50,000.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Software System Penetration Testing Mobile Application Software Web Applications Software Security

Job description

This is a full-time hybrid role for a Security Consultant specializing in Application Security (AppSec) Testing, located in Manchester with flexibility for remote work. Responsibilities include:

  • Penetration Testing web applications, APIs, mobile applications, etc for our clients across a range of industries.
  • Working with stakeholders of both a technical and non-technical nature to assist in vulnerability identification and remediations.
  • Performing risk reviews of application changes as part of our continuous security testing process.

You will collaborate closely with developers and other teams to strengthen application security, drive continuous improvement, and enhance organizational resilience to cybersecurity threats.

  • Up to £50k (reviewed regularly)
  • EMI share options
  • Pension: 8% (3% employer, 5% employee)

Requirements

Do you have experience in Penetration testing?, * 2+ years in Penetration Testing, Application Security Engineering, or a similar offensive security role.

Benefits & conditions

Pulled from the full job description

  • Annual leave
  • Unlimited paid holidays
  • Employee stock ownership plan
  • Company pension
  • Discounted or free food
  • Private medical insurance

About the company

We have an exciting opportunity to join our Manchester-based application security business as a member of the Application Security Engineering team. Cytix is a platform that threat models development tickets and creates security testing plans that include both manual and automated testing.

In this role, you won’t be confined to traditional 4+1 web applications. We’re breaking away from the constraints of CHECK or CE+ standards, and we’re not interested in producing lengthy PDF reports. Instead, our focus is on seamlessly integrating continuous penetration testing into our customers’ Software Development Life Cycle (SDLC).

Collaborating closely with both our in-house development team and clients, you’ll play a pivotal role in shaping the evolution of our products and services, helping to deliver the next generation of continuous penetration testing.

As a well-funded cybersecurity start-up doing something innovative, this opportunity is genuinely one-of-a-kind for the right individual.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:13 min

Analyzing test coverage gaps in standard web applications

Jorge Gonzalez Pliego Jorge Gonzalez Pliego · Europe 2026 Virtual

1:30 min

The universal and shared team responsibility of software security

Julia Wilson Julia Wilson +1 · World Congress 2025

3:06 min

Exposing location tracking vulnerabilities in mobile application software kits

Dan Cranney +2 · LIVE

2:39 min

Shifting security testing focus toward critical application logic problems

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

2:32 min

Transitioning across tech stacks into mobile application development

Sylvia Dieckmann · LIVE

3:55 min

Establishing blameless dialogue surrounding critical software security vulnerabilities

Chris Heilmann +2 · LIVE

Videos

See all

Related articles

See all