Overview
As a Senior Application Security Engineer, you embed within an engineering tribe to lift security from inside the core team. You’ll influence design, review code and architecture, and drive pragmatic, secure fixes while building tooling and processes that scale security across the platform. You work with security, platform, and engineering guilds to route work to the right teams and impact multiple domains from APIs to data stores. This role blends hands-on engineering with security leadership to strengthen Cloudsmith’s secure-by-design culture and product. You will shape the application security roadmap and mentor others, contributing to a trusted, enterprise-grade software supply chain.
Pay / Benefits
- health, dental, and vision insurance
- equity
- generous annual leave
- flexible working policies
- professional development budget for conferences and training
- Belfast HQ and remote-friendly environment
Responsibilities
- Embed inside an engineering tribe and participate in planning, design review, code review, incident learning, and delivery conversations
- Collaborate across security, platform, and engineering guilds to route security work effectively
- Threat-model product and platform changes across APIs, workers, data stores, queues, object storage, CDNs, identity, policy, and tenant boundaries
- Review production code and architecture for authentication, authorization, data access, secrets handling, artifact integrity, signing, auditability, and abuse cases
- Build and improve security tooling, paved roads, checks, libraries, and automation for engineers
- Tune and operate security controls across SAST, DAST, SCA, secrets scanning, container scanning, IaC scanning, dependency analysis, and runtime signals
- Investigate, triage, and remediate vulnerabilities from various sources
- Support security incidents, red/blue exercises, detection work, and post-incident follow-ups
- Support technical control work for SOC 2, ISO 27001, EU CRA, and related frameworks with GRC input
- Raise the tribe’s security capability by helping engineers understand risks and threat-model their work
Key requirements
- Around 5+ years of hands-on application security experience, or equivalent across software engineering and security
- Deep software engineering craft with focus on Python; familiarity with TypeScript, Go, or Rust is a plus
- Deep web and API security knowledge: OWASP Top 10, authn/authz design, token handling, REST, GraphQL, multi-tenant access control
- Practical threat modeling and vulnerability research against real applications and cloud-native systems
- Strong cloud-native security experience across AWS, IAM, KMS, S3, containers, Terraform, CI/CD, secrets handling, logging, multi-tenant isolation
- Sound judgment on vulnerability priority (CVSS awareness, but focus on exploitability and production impact)
- Ability to reason through production systems (APIs, queues, caches, databases, edge delivery, telemetry, failure modes)
- Clear communication in a remote-first environment; threat models, incident notes, and feedback are engineer- and leadership-ready
- Understanding of Software Supply Chain concepts and related threats (Ecosystems, SBOMs, signing, attestations, zero-trust delivery)
- Willingness to embed within tribes and influence secure design patterns
- Engineering mindset with security focus
- Ownership and accountability
- Clear, credible communication across remote teams
- Python
- TypeScript / Go / Rust (advantage)
- OWASP Top 10 and API security
…
