Senior Application Security Engineer

Company: Elsevier
Apply for the Senior Application Security Engineer
Location:
Job Description:

Overview

In this role you bolster secure software delivery across engineering teams by embedding security practices, tooling, and automation into development workflows. You’ll enable teams to build secure applications and CI/CD pipelines through practical guidance and reusable solutions, reducing risk at scale. You will collaborate with platform, architecture, and security groups to improve processes and delivery capabilities, delivering secure-by-default patterns. This position offers an opportunity to impact how security is integrated throughout the development lifecycle at Elsevier, a global leader in information and analytics.

Pay / Benefits

  • wellbeing initiatives
  • shared parental leave
  • study assistance and sabbaticals
  • flexible working hours
  • disability accommodation support
  • location-based benefits

Responsibilities

  • Partner with development teams to improve secure software delivery practices across applications and CI/CD pipelines
  • Support triage and remediation of application security findings through practical guidance and secure refactoring recommendations
  • Facilitate threat modelling activities and translate outcomes into actionable improvements and risk reduction measures
  • Design and maintain secure-by-default delivery patterns, reusable templates, and reference implementations
  • Support adoption of centrally managed tooling and automated security controls
  • Develop integrations and automation to enable security validation, audit evidence generation, and operational metrics
  • Collaborate with platform, architecture, and security teams to improve processes, tooling, and delivery capabilities
  • Communicate security guidance, standards, and best practices to stakeholders

Key requirements

  • Experience in application security, software engineering, or product security
  • Knowledge of application security principles, common vulnerabilities, and secure coding practices across multiple technology stacks
  • 5+ years of application security, software engineering, or product security experience
  • BS Engineering/Computer Science or equivalent experience
  • Understanding of CI/CD security, including pipeline controls, identity and access management, and secrets handling
  • Experience integrating automated security tooling into software delivery workflows
  • Experience developing reusable templates, standards, and reference implementations
  • Familiarity with security automation, compliance support, and audit evidence generation
  • Awareness of industry security standards and best practices
  • Strong collaboration, communication, analytical, troubleshooting, and problem-solving skills
  • collaboration
  • communication
  • analytical thinking
  • application security
  • CI/CD security
  • security tooling integration

…

Posted: October 1st, 2026