Senior Application Security Engineer (SCA/SAST)
Location
UK - Remote
The Mission
At Trimble, we aren't just building software; we’re transforming the way the world works.
Why This Role? Global Influence
You won't just be "fixing bugs." You will be the architect of a global security strategy that impacts 99% of our engineering teams.
Strategic Autonomy
Lead the vision for our SCA and SAST roadmaps. You have the seat at the table to decide how we evolve.
Innovation at Scale
Work across diverse tech stacks—from .NET and Java to Go and Python—integrating security directly into the heartbeat of our CI/CD pipelines. How You’ll Make an Impact Strategic Leadership: Act as the global SME for SCA and SAST, turning complex security requirements into scalable, automated solutions. Optimize our security tooling to be "developer-first," slashing false positives and focusing engineering energy on what truly matters. Shape the organizational approach to open-source security and license compliance.
Engineering Excellence
Embed security into the DNA of the SDLC by collaborating with architects and product owners worldwide. Automate everything. You’ll build the "guardrails" that allow our developers to move fast without breaking things. Mentor the next generation of security talent and lead through influence across cross-functional teams.
Vision & Advisory
Stay ahead of the curve. You’ll evaluate emerging security tech and proactively keep Trimble at the cutting edge. Conduct threat modeling and architectural reviews to kill vulnerabilities before they are ever coded. The Profile We’re Looking For The Architect: 5+ years in AppSec with a deep, battle-tested mastery of SCA and SAST implementation at an enterprise level.
The Polyglot
You speak the language of developers. Whether it’s Java, C#, Python, or Go, you can read the code and provide real remediation paths.
The Integrator
You live in the pipeline. You have hands-on experience with GitHub Actions, Jenkins, Azure DevOps, or GitLab CI.
The Communicator
You can translate "security risk" into "business value" for stakeholders and "clear action" for engineers.
Education
Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience.