Application Security Engineer
Core
Strengthen secure development practices across a multi-cloud environment by embedding security into the software delivery lifecycle and reducing risk.
Role type
Senior Application Security Engineer (DevSecOps)
Builds
Secure, automated, and scalable software delivery pipelines for energy infrastructure and services.
Domain
Energy sector, Cloud Security, DevSecOps
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure
Required skills
Application security, Secure SDLC, OWASP Top 10, Cloud security (AWS/Azure), API security, Container security, CI/CD security integration, SAST/DAST/SCA, Vulnerability management, Policy as Code, Threat modelling
Preferred skills
Python or JavaScript, Code security automation, OAuth 2.0/OIDC/SAML, IaC security (Terraform/Bicep/Ansible), SBOM tooling (CycloneDX), Trivy, Security Champions program leadership
Technologies
AWS, Azure, Azure DevOps, GitHub Actions, Terraform, Bicep, Ansible, Trivy, CycloneDX, SAST, DAST, SCA
Responsibilities
Collaborate with DevOps and engineering teams to integrate security best practices into the SDLC; Provide guidance on secure design, implementation, and architecture for microservices and cloud-native apps; Conduct manual security assessments and coordinate third-party engagements; Review SAST, DAST, and SCA outputs to drive remediation; Provide on-demand application security support and drive process/tooling improvements; Lead or contribute to the Security Champions programme and work with GSOC/CSIRT on application-layer incidents.
Seniority
Senior, hands-on IC