We are seeking an experienced Senior Application Security Engineer to join a high-performing security team supporting a large-scale technology environment.
This role is focused on Product Security and Application Security, working closely with engineering and product teams to embed security throughout the software development lifecycle. You will play a key role in identifying security risks early, leading threat modelling activities, conducting security design reviews, and helping teams implement secure-by-design solutions across modern cloud-native platforms.
Key responsibilities include:
- Leading threat modelling workshops for new and existing applications, platforms and services
- Conducting security architecture and application security reviews
- Partnering with engineering teams to identify risks and recommend security controls
- Driving secure development practices across the SDLC
- Providing guidance on secure coding, application security and cloud security
- Supporting DevSecOps initiatives and security automation
- Collaborating with product, engineering and security stakeholders to prioritise and remediate security findings
- Developing reusable security patterns, standards and guidance for development teams
Essential experience:
- Strong Application Security or Product Security experience
- Proven experience leading threat modelling exercises (STRIDE or similar)
- Security architecture and secure design review experience
- Secure SDLC and DevSecOps practices
- AWS cloud security experience
- Web application security and vulnerability management
- Modern architectures including APIs, microservices and cloud-native platforms
- Security frameworks such as OWASP, MITRE ATT&CK;, NIST and/or ISO 27001
- Strong stakeholder engagement and the ability to influence engineering and product teams
Highly regarded:
- Experience within SaaS, product-led or technology-focused organisations
- Container and Kubernetes security
- Security Champion programs
- Secure coding and developer training initiatives
- AI security exposure
Please note:This prospect is best suited to candidates with a strong Application Security, Product Security or AppSec background. Candidates whose experience is primarily within SOC Operations, GRC, IAM or compliance-focused environments may not be closely aligned to the requirements of this role.
Additional information
- Initial 12-month contract with potential extension
- Lead threat modelling workshops and application security reviews
- AWS, DevSecOps, Secure SDLC, APIs and microservices