Application Security Engineer

Company: Rightmove
Apply for the Application Security Engineer
Location: London
Job Description:

Overview

As the first AppSec engineer in Rightmove’s growing security function, you will implement and operate security tooling, vulnerability management, and secure design practices across engineering teams. You help shape the AppSec program as it matures, collaborating with developers to reduce risk and improve security posture. You’ll drive threat modelling, security reviews, and risk-based triage, delivering tangible improvements in secure software delivery. This is a hands-on, impact-first role at a scale‑up within a market‑leading property platform.

Pay / Benefits

  • Cash plan for dental, optical and physio treatments
  • Private Medical Insurance, Pension and Life Insurance
  • 27 days holiday plus volunteering days
  • Life assurance 4x basic salary
  • Travel Loans, Bike to Work scheme, Rental Deposit Loan
  • Hybrid working with minimum 2 days in office

Responsibilities

  • Roll out and operate application security tooling (SAST, SCA, secrets detection) across repositories
  • Triage, classify and drive remediation of security findings and secrets backlog
  • Manage day-to-day vulnerability management including triage, monitoring and engineering engagement
  • Maintain engineer-facing guidance for vulnerability resolution and exceptions
  • Support cloud security posture management with Prisma Cloud, including findings triage and engagement
  • Run risk-tiered engagement with engineeringTeams based on SLA compliance
  • Triage inbound security requests and conduct secure design and API security reviews for new services and RFCs
  • Review and respond to penetration test requests and third-party integration reviews
  • Facilitate threat modelling sessions and improve practices across squads
  • Maintain runbooks and process documentation; support recurring review cadences (access reviews, vulnerability audits)

Key requirements

  • Practical experience in application security or security engineering
  • Ability to assess findings in context and make pragmatic engineering recommendations
  • Working proficiency in Python (read/modify/write internal tooling scripts)
  • Experience with DAST/SAST/SCA/secrets scanning tools (Aikido, Snyk, Semgrep, Checkmarx or similar)
  • Experience with Prisma Cloud or similar cloud-native security platform
  • Comfort reading code and understanding CI/CD pipelines (GitLab CI or equivalent)
  • Experience running or contributing to threat modelling exercises
  • Comfortable coordinating recurring stakeholder syncs with engineering teams
  • Strong written communication
  • Ability to triage and prioritise high volume inbound requests independently
  • clear written communication
  • stakeholder management
  • proactive problem solving
  • Python scripting for internal tooling
  • DAST/SAST/SCA/secrets tooling
  • Cloud security posture management (Prisma Cloud)

…

Posted: October 5th, 2026