Senior Application Security Engineer
Core
Building automated security guardrails, tools, and AI/LLM models to enable secure development and shift security left within multi-cloud environments.
Role type
Senior Application Security Engineer (IC)
Builds
Automated security tooling, secure frameworks, and AI-driven security review systems for product teams.
Domain
Cloud Security (AWS, GCP, Azure) and Application Security
Deliverable
production ML models | product features
Required skills
Application security architecture, CI/CD pipeline hardening, SAST/SCA/Secret Detection integration, threat modelling, compliance translation (ISO 27001, SOC 2), secure Java application development, Python/Bash/Go scripting, Security Champions programme management.
Preferred skills
OWASP Top 10, dependency management, OAuth2/OIDC, SonarQube, CrowdStrike.
Technologies
AWS, Terraform, CloudFormation, Java, Python, Bash, Go, SonarQube, CrowdStrike, SAST, SCA, LLMs.
Responsibilities
Define security standards for product deployments; integrate and optimize security tools into developer workflows; architect secure frameworks and patterns; automate remediation for common security issues; design and deploy AI/LLM models for security change reviews; drive developer engagement via Security Champions programmes and workshops; collaborate on threat modelling and compliance specs; harden CI/CD pipelines; automate security incident triage.
Seniority
Senior, hands-on IC
