Application Security Engineer

Company: The Pokémon Company
Apply for the Application Security Engineer
Location: London
Job Description:

Overview

As an Application Security Engineer, you design, implement, and operate controls to prevent and detect attacks on company systems, apps, and data. You perform penetration testing and vulnerability assessments across software, OS, and networks, and respond to incidents by isolating threats. You research emerging threats and support security solutions, communicating business impact of data loss or outages. You collaborate across teams to embed security throughout development and build scalable protections for cloud and on-prem workloads. This role combines hands-on security work with shaping risk-aware engineering practices to protect Pokémon’s digital ecosystem.

Pay / Benefits

  • 100% employer-paid healthcare premiums for you
  • Generous paid family leave
  • Employer-paid life insurance
  • Employer-paid long and short-term disability
  • 401k employer matching (US)
  • Hybrid work environment

Responsibilities

  • Enforce security policies for system and application access
  • Perform application security testing and secure configuration reviews
  • Conduct penetration tests and vulnerability assessments across layers
  • Lead threat modeling and security design reviews for new tech and changes
  • Respond to security incidents by isolating threats and removing unauthorized access
  • Research emerging threats and perform root cause analysis
  • Implement controls to reduce cloud-based risks, including drift and web-facing vulnerabilities
  • Collaborate with Information Security to advance roadmaps
  • Integrate security testing and controls into development lifecycle
  • Provide management with insights on business impact of data compromise or outages
  • Work in an agile framework to deliver iterative security improvements
  • Respond to incidents, including off-hours on rotation

Key requirements

  • 5–7 years of experience securing cloud environments, especially AWS
  • Bachelor’s degree in a related field or equivalent experience
  • Strong time management, organizational skills, and attention to detail
  • Solid background in application security engineering and architecture (MWAF and development)
  • Ability to build partnerships and collaborate with cross-functional teams
  • Strong communication skills for presenting risks to senior leadership
  • Experience managing security vendors and managed service providers
  • Proven incident management and response experience
  • Security certifications (CISSP, GIAC, CISA, etc.) are a plus
  • Cross-functional collaboration
  • Effective communication with senior leadership
  • Attention to detail
  • Cloud security (AWS)
  • MWAF (mod_security web application firewall)
  • Penetration testing

…

Posted: September 14th, 2026