Skip to content
← Back to job listings

Senior Application Security Engineer

Our Future Health · London, United Kingdom

External listingfull-timeabout 2 months ago

About The Role

Join our expanding Information Security team as a Senior Application Security Engineer. In this role, you will work in a modern, cloud-native environment and have the autonomy, tooling, and influence to shape secure design and embed controls into CI/CD. You will partner with development teams to embed security into code, applications, and containerized workloads, and help define how we secure applications across various platforms. This is a hands-on engineering role focused on true AppSec, not vulnerability management.

  • Collaborate with development teams to embed security into code, applications, Kubernetes, and containerized workloads.
  • Implement and operate code scanning to help developers identify and remediate vulnerabilities, and mature the Secure Development Lifecycle.
  • Define how to secure applications across various platforms, influencing processes, tooling, and engineering culture.
  • If you are a hands‑on AppSec expert who enjoys working deep in the SDLC, partnering with talented engineers and building security into fast‑moving delivery pipelines, this role gives you the space to make a real impact
  • If you come from a startup or scale‑up background, thrive in cloud‑native environments and enjoy being the trusted expert for squads who want to do the right thing, you will feel at home here
  • Experience of securing APIs and other exposed components
  • Exposure to Agile working and DevSecOps
  • Experience of securing GitHub and GitHub Actions, or similar CI/CD platforms
  • Knowledge of ISO 27001 and its relevance to secure engineering
  • Desire to be part of a small fast‑paced team with a collaborative mindset
  • Relevant certifications such as Microsoft MS‑500, AZ‑500, AZ‑700, SC‑200, CompTIA Security+ or Cloud+, CSA CCSK, ISC2 CSSLP, GIAC GWAPT or EC‑Council CASE
  • Experience of automating security capabilities and delivering security or policy as code using tools such as OPA or Azure Policy
  • Significant hands‑on experience with implementing and operating code scanners including SAST, DAST, IAST and SCA
  • Ideally experience in securing data platforms such as Databricks, Dagster or Snowflake
  • Proficient in writing Terraform, Python and ideally KQL
  • Experience working directly with software engineering best practices including source control, unit testing, code reviews, design documentation and strong debugging and troubleshooting
  • Experience in threat modelling within engineering teams
  • Experience of securing Kubernetes ideally AKS, along with broader container security

This is an external listing. JobSpring does not represent or verify the employer. Report this listing