Overview
As a Senior Application Security Engineer, you help embed security across the software delivery lifecycle for a health research charity. You will partner with engineering and cloud teams to design, deploy, and maintain secure applications, platforms, and deployment processes. The role focuses on secure design, CI/CD security, cloud-native tech, and security automation, with hands-on responsibilities. You’ll contribute to threat modelling and compliance while enabling developers to build safer software at scale.
Pay / Benefits
- hybrid work arrangement
- excellent benefits package
- central London office location
- salary 70,000 – 80,000 per annum
Responsibilities
- Collaborate with engineering and architecture teams to promote secure development from the outset
- Implement and maintain application security testing capabilities to help developers identify and fix risks
- Integrate security controls into CI/CD pipelines
- Strengthen security of GitHub Actions and similar CI/CD platforms
- Advise on secure API design and protection of externally facing systems
- Support Azure cloud infrastructure security, including AKS
- Safeguard cloud-hosted data platforms and related tech
- Develop and maintain security-as-code and policy-as-code tooling
- Automate security processes via infrastructure-as-code and scripting
- Produce and maintain technical and service documentation
- Assist development teams with adopting security tooling and best practices
- Contribute to cyber security initiatives, including threat modelling and compliance
Key requirements
- Hands-on experience embedding application security into the SDLC
- Experience securing APIs, internet-facing services, Kubernetes/AKS, and containerised environments
- Familiar with security testing tools (SAST, DAST, IAST, SCA)
- Knowledge of security automation, security-/policy-as-code, and secure engineering practices
- Proficiency with GitHub and GitHub Actions
- Strong Terraform and Python skills
- Understanding of Azure security controls and cloud governance
- Experience with threat modelling in software contexts
- Knowledge of ISO 27001 and its relevance to secure engineering
- Familiar with Agile and DevSecOps methodologies
- Eligible to work in the UK
- collaboration with cross-functional teams
- ability to communicate security concepts to developers
- proactive problem-solving
- SAST
- DAST
- IAST
…
