Senior Application Security Engineer – DevSecOps & Cloud Security

Company: Additional Resources
Apply for the Senior Application Security Engineer – DevSecOps & Cloud Security
Location: London
Job Description:

Overview

As a Senior Application Security Engineer, you help embed security across the software delivery lifecycle for a health research charity. You will partner with engineering and cloud teams to design, deploy, and maintain secure applications, platforms, and deployment processes. The role focuses on secure design, CI/CD security, cloud-native tech, and security automation, with hands-on responsibilities. You’ll contribute to threat modelling and compliance while enabling developers to build safer software at scale.

Pay / Benefits

  • hybrid work arrangement
  • excellent benefits package
  • central London office location
  • salary 70,000 – 80,000 per annum

Responsibilities

  • Collaborate with engineering and architecture teams to promote secure development from the outset
  • Implement and maintain application security testing capabilities to help developers identify and fix risks
  • Integrate security controls into CI/CD pipelines
  • Strengthen security of GitHub Actions and similar CI/CD platforms
  • Advise on secure API design and protection of externally facing systems
  • Support Azure cloud infrastructure security, including AKS
  • Safeguard cloud-hosted data platforms and related tech
  • Develop and maintain security-as-code and policy-as-code tooling
  • Automate security processes via infrastructure-as-code and scripting
  • Produce and maintain technical and service documentation
  • Assist development teams with adopting security tooling and best practices
  • Contribute to cyber security initiatives, including threat modelling and compliance

Key requirements

  • Hands-on experience embedding application security into the SDLC
  • Experience securing APIs, internet-facing services, Kubernetes/AKS, and containerised environments
  • Familiar with security testing tools (SAST, DAST, IAST, SCA)
  • Knowledge of security automation, security-/policy-as-code, and secure engineering practices
  • Proficiency with GitHub and GitHub Actions
  • Strong Terraform and Python skills
  • Understanding of Azure security controls and cloud governance
  • Experience with threat modelling in software contexts
  • Knowledge of ISO 27001 and its relevance to secure engineering
  • Familiar with Agile and DevSecOps methodologies
  • Eligible to work in the UK
  • collaboration with cross-functional teams
  • ability to communicate security concepts to developers
  • proactive problem-solving
  • SAST
  • DAST
  • IAST

…

Posted: September 14th, 2026