> Markdown version of [/jobs/ext/352611-staff-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/352611-staff-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Application Security Engineer - **Company:** Bitwise - **Location:** London, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Software System Penetration Testing, Audit Trail, Cloud Computing, Continuous Integration, Fuzz Testing, Key Management, Systems Development Life Cycle, Software Engineering, Software Security, Hashicorp, Static Application Security Testing, Dynamic Application Security Testing - **Published:** June 23, 2026 - **Apply:** https://www.apply4u.co.uk/jobs/x/39759561/ ## About the Role 7+ years of experience in application security or a closely related discipline Demonstrated experience building or significantly maturing an application security program Deep hands-on experience with SAST and DAST tooling implementation and management Strong knowledge of secure SDLC practices and CI/CD pipeline security integration Experience with dependency scanning and software supply chain security Proficiency in threat modeling methodologies (STRIDE, PASTA, or equivalent) Experience managing or coordinating third-party penetration testing engagements Solid understanding of secrets management solutions (e.g., HashiCorp Vault, AWS Secrets Manager, or equivalent) Strong written and verbal communication skills - able to document findings and present risk clearly to both technical and non-technical audiences ## Description Our engineering organization is growing, and with that growth comes an expanding application and infrastructure footprint that requires dedicated application security ownership. This role exists to build that function from the ground up. As our first dedicated Staff Application Security Engineer, you will own the design and implementation of our application security program, from SAST and DAST tooling to secure SDLC practices, threat modeling, dependency security, and penetration testing coordination. You will work directly with engineering teams across a cloud-based environment securing both customer-facing products and internal systems. You will be reporting directly to the Head of Security and will have the autonomy and organizational support to build an application security program that is practical, scalable, and aligned to the risk profile of a company operating in the digital asset space. Primary Responsibilities: Static & Dynamic Application Security Testing (SAST / DAST) Own the full implementation of SAST tooling across all codebases and CI/CD pipelines Own the full implementation of DAST tooling across all customer-facing and internal applications Establish baseline findings, prioritize remediation, and work directly with engineering to resolve issues Maintain and tune tooling over time as the codebase and attack surface evolve Secure SDLC & Code Integrity Define and enforce a secure software development lifecycle across engineering teams Establish secure release processes including code signing and build integrity verification Develop and maintain security standards, guidelines, and secure coding practices Integrate security checkpoints throughout the development pipeline without creating unnecessary friction for engineering Threat Modeling Lead threat modeling exercises for new infrastructure designs, features, and system changes Ensure all customer-facing and internal applications are fully documented and threat modeled Maintain a living inventory of the company's attack surface and ensure it reflects current architecture Dependency & Supply Chain Security Implement and manage dependency scanning across all projects Enforce version pinning policies to reduce exposure from uncontrolled dependency updates Deploy and manage supply chain security tooling (e.g., Socket.dev or equivalent) to monitor for malicious or compromised dependencies Establish a process for ongoing dependency review and remediation Penetration Testing Define and maintain a penetration testing program covering all surface areas - applications, APIs, internal tooling, and infrastructure Scope, schedule, and manage third-party penetration testing engagements Track findings through to remediation and validate fixes Secrets Management Design and implement a secrets management program across cloud infrastructure and engineering workflows Eliminate hardcoded credentials and secrets from codebases Establish policies and tooling for secrets rotation, access control, and audit logging Fuzzing & Attack Surface Coverage Implement fuzz testing across applicable components, particularly APIs and input-handling logic Ensure coverage gaps in the attack surface are identified, documented, and addressed systematically ## Related Videos - [Bridging AI and Nomad: a Go-based MCP Server for Cluster Control](https://www.wearedevelopers.com/videos/2063-bridging-ai-and-nomad-a-go-based-mcp-server-for-cluster-control) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [How will artificial intelligence change the future of software testing?](https://www.wearedevelopers.com/videos/85-how-will-artificial-intelligence-change-the-future-of-software-testing) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Securing Secrets in the GitOps era](https://www.wearedevelopers.com/videos/546-securing-secrets-in-the-gitops-era) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)