CareerPlanSign in

Application Security Engineer

London, UK💼 Full-time🗓 2026-05-12 → 2026-08-07

Core

Embed security into the Secure SDLC, automate controls in CI/CD, and drive measurable risk reduction for products.

Role type

Senior IC application security engineer

Builds

Secure SDLC processes, automated CI/CD pipelines, secure APIs, and supply chain security practices

Domain

Financial services / Application Security

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

Secure SDLC design, CI/CD security automation, security code review, API security, threat modeling, supply chain security (SCA/SBOM), vulnerability lifecycle management, risk-based testing

Technologies

SAST, DAST, SCA, IaC, container security, OAuth, OIDC

Responsibilities

Define lightweight SSDLC requirements and release criteria; own AppSec toolchain/pipelines and tune security rules; perform security code reviews for critical areas; lead API security and drive API testing; run pragmatic threat modeling and design reviews; manage dependency risk and SBOM generation; run vulnerability intake/triage and define remediation SLAs; execute targeted risk-based testing on high-risk areas

Seniority

Senior, hands-on IC

Sourced via adzuna · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.