Application Security Engineer
Core
Embed security best practices into the software development lifecycle, conduct manual security assessments, and drive vulnerability remediation for cloud-native applications.
Role type
Senior IC application security engineer
Builds
Secure software development lifecycle, secure cloud-native applications, and API/microservices security
Domain
Cybersecurity, Cloud Security, Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
secure software development, OWASP Top 10, secure SDLC, Python, JavaScript, AWS, Azure, SAP, container security, API security, OAuth 2.0, OIDC, SAML, CI/CD security integration, SAST, DAST, SCA, vulnerability management, SBOM, infrastructure-as-code security, threat modelling
Preferred skills
GWAPT, GWEB, OSCP, AWS Security Specialty certifications, Security Champions programme experience, developer training, SOC, incident response
Technologies
CycloneDX, Terraform, Bicep, Ansible, Trivy, Policy as Code, Azure DevOps, GitHub Actions
Responsibilities
Embed security best practices into the software development lifecycle, conduct manual security assessments, review SAST/DAST/SCA findings, lead Security Champions programme, support third-party supply chain security
Seniority
Senior, hands-on IC