Application Security Engineer
London, UK
We are looking for an application security engineer who is based in the UK for a majority remote role based in London.
In order to be considered, the candidate must have the following experience;
- Experience assessing security impacts across codebases and APIs using languages such as Java, TypeScript and Python.
- Strong knowledge of the OWASP Top 10, secure coding practices, and common web and API vulnerabilities.
- Hands-on experience triaging, validating and remediating vulnerabilities with both technical and non-technical stakeholders.
- Experience integrating security tooling into CI/CD pipelines and embedding DevSecOps practices.
- Security certifications such as OSCP, GWAPT, CSSLP, CEH or Security+.
- Experience securing AWS environments and infrastructure-as-code solutions such as Terraform.
- Knowledge of AI-enabled security workflows and securing AI or LLM-powered features.
- Experience contributing to or maintaining open-source security tooling.
- Proven expertise in threat modelling, secure code review, architecture review, and container/Kubernetes security.