Application Security Lead
Core
Own Prolific's application security strategy and serve as the senior security engineering voice, embedding security into the engineering lifecycle for a platform handling sensitive human data at scale.
Role type
Senior Application Security Lead (Player-coach)
Builds
Secure software development lifecycle (SSDLC), secure code, and compliance programs for AI data infrastructure
Domain
AI data infrastructure, application security, secure software development
Deliverable
production ML models | product features | infrastructure
Required skills
Application security strategy, Secure Software Development Lifecycle (SSDLC) design, code review, threat modelling, security testing, OWASP Top 10 expertise, modern architecture understanding (microservices, APIs), Python for security automation, CI/CD tooling (SAST, SCA, DAST, secrets), ISO 27001/SOC 2 compliance translation
Preferred skills
Engineering management/mentoring, Django, Vue.js, MongoDB, GCP Security
Technologies
Python, Django, Burp Suite, SAST, SCA, DAST, CI/CD tools
Responsibilities
Define and drive the Secure Software Development Lifecycle (SSDLC), perform hands-on code review and threat modelling, manage Senior Application Security Engineers, own the compliance programme, build security culture, partner with product engineering and platform teams
Seniority
Senior, hands-on IC with management responsibilities