← Back to job listings
OF
Senior Application Security Engineer
Our Future Health · London, United Kingdom
About The Role
Join our expanding Information Security team as a Senior Application Security Engineer. In this role, you will work in a modern, cloud-native environment and have the autonomy, tooling, and influence to shape secure design and embed controls into CI/CD. You will partner with development teams to embed security into code, applications, and containerized workloads, and help define how we secure applications across various platforms. This is a hands-on engineering role focused on true AppSec, not vulnerability management.
- Collaborate with development teams to embed security into code, applications, Kubernetes, and containerized workloads.
- Implement and operate code scanning to help developers identify and remediate vulnerabilities, and mature the Secure Development Lifecycle.
- Define how to secure applications across various platforms, influencing processes, tooling, and engineering culture.
- If you are a hands‑on AppSec expert who enjoys working deep in the SDLC, partnering with talented engineers and building security into fast‑moving delivery pipelines, this role gives you the space to make a real impact
- If you come from a startup or scale‑up background, thrive in cloud‑native environments and enjoy being the trusted expert for squads who want to do the right thing, you will feel at home here
- Experience of securing APIs and other exposed components
- Exposure to Agile working and DevSecOps
- Experience of securing GitHub and GitHub Actions, or similar CI/CD platforms
- Knowledge of ISO 27001 and its relevance to secure engineering
- Desire to be part of a small fast‑paced team with a collaborative mindset
- Relevant certifications such as Microsoft MS‑500, AZ‑500, AZ‑700, SC‑200, CompTIA Security+ or Cloud+, CSA CCSK, ISC2 CSSLP, GIAC GWAPT or EC‑Council CASE
- Experience of automating security capabilities and delivering security or policy as code using tools such as OPA or Azure Policy
- Significant hands‑on experience with implementing and operating code scanners including SAST, DAST, IAST and SCA
- Ideally experience in securing data platforms such as Databricks, Dagster or Snowflake
- Proficient in writing Terraform, Python and ideally KQL
- Experience working directly with software engineering best practices including source control, unit testing, code reviews, design documentation and strong debugging and troubleshooting
- Experience in threat modelling within engineering teams
- Experience of securing Kubernetes ideally AKS, along with broader container security
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring