Security Engineer (AppSec)
Security Engineer (AppSec)

Security Engineer (AppSec)

London Full-Time 42000 - 84000 Β£ / year (est.) Home office possible
C

At a Glance

  • Tasks: Lead and integrate security into our platform while guiding engineers in secure practices.
  • Company: Join Cloudsmith, a cutting-edge SaaS company transforming software supply chain security.
  • Benefits: Enjoy remote work, competitive pay, health insurance, and a professional development budget.
  • Why this job: Make a real impact on software security for global organisations while growing your skills.
  • Qualifications: 3+ years in security engineering with expertise in application security and cloud technologies.
  • Other info: Work in a dynamic, supportive environment with opportunities for travel and team activities.

The predicted salary is between 42000 - 84000 Β£ per year.

We are seeking a passionate and technically sophisticated security engineer to lead, architect, and integrate security into every aspect of our platform. You like making things but also breaking things and preventing others from doing the same.

About Cloudsmith: Cloudsmith is transforming how organizations handle software artifacts and secure their supply chains. As a fully managed multi-tenant Software as a Service (SaaS) built on AWS, our mission is to enable organizations to tackle scale and complexity through best-in-class artifact management and to secure software by default. Our vision is to become the software supply chain itself, powering the future of software delivery.

The Role: As a Security Engineer (AppSec) reporting to the Head of Application Security, you will be a key member of our growing security function, focusing on our product and platform security. This role combines hands-on security engineering with technical leadership, requiring someone to implement security controls and guide other engineers in secure development practices.

Key Responsibilities:

  • Technical Security Leadership: Enhance and expand security controls across our cloud-native infrastructure. Lead security architecture reviews and threat modeling sessions. Develop, evolve, and implement secure coding standards and practices. Extend our security automation tooling and strengthen CI/CD pipeline security. Build upon our existing security testing frameworks and procedures.
  • Application Security Implementation: Perform security code reviews and penetration testing of our codebases. Implement security controls for our distributed systems (AWS-based). Design and implement secure container runtime environments. Build secure API endpoints and review API security architecture. Implement supply chain security controls and verification systems.
  • Security Engineering & Architecture: Enhance our security monitoring solutions using DataDog, AWS Security Hub, etc. Strengthen our secure deployment pipelines using CircleCI and GitHub Actions. Drive implementation of our secure artifact storage and processing systems. Design and implement additional customer and environment isolation controls. Develop security automation tools and frameworks and apply them. Partner with the Head of AppSec + CTO on security architecture decisions.
  • Security Culture & Education: Provide security guidance and mentorship to engineering teams. Develop and deliver security training materials. Create security documentation and guidelines. Participate in security incident response. Contribute to security policies and standards.
  • Team Collaboration: Work closely with the Head of AppSec + CTO to implement security strategies. Collaborate with engineering teams to embed security practices. Support security audit and compliance initiatives. Participate in security incident response as a technical lead (incl. red/blue team). Help evaluate and implement new security tools and technologies. Automate everything, write code (if you want to!), and make proofs ('sploits).

Required Experience, Qualities & Skills:

  • Technical Expertise: 3+ years of security engineering experience or equivalent. Deep expertise in application security and secure software development. Experience with implementing SAST, DAST, and RASP (Runtime Security). Strong programming skills in Python, with familiarity in TypeScript/Node.js or similar. Extensive experience with cloud security (AWS-based, preferably), web application security, API security (REST or GraphQL, etc.), Infrastructure as Code security, CI/CD pipeline security, container security (Docker, OCI), and database security.
  • Security Engineering Skills: Experience building security tools and automation. Strong background in threat modeling and risk assessment. Expertise in penetration testing and vulnerability assessment. Knowledge of cryptography and secure communication protocols. Experience with security monitoring and incident response.
  • Domain Knowledge: Understanding of software supply chain security. Experience with artifact management systems. Knowledge of modern development practices and tools. Familiarity with compliance frameworks (ISO 27001, SOC2).
  • Bonus Points: Experience with data enclave implementations, secure runtime environments (Firecracker, gVisor), software composition analysis, contributions to open-source security tools, security-focused certifications (OSCP, CSSLP, etc.), and experience securing package management systems.

Cultural Values We’re Looking For:

  • Technical Mastery: Demonstrate deep security expertise and engineering craftsmanship.
  • Security Innovation: Drive automated, cloud-native security solutions to excellence.
  • Knowledge Champion: Share security expertise openly and mentor engineering teams.
  • Pragmatic Builder: Deliver practical security solutions with customer needs in mind.
  • Continuous Growth: Actively expand security knowledge and embrace sustainable practices.

Impact & Opportunity: This role offers the chance to enhance security in a platform already trusted by organizations worldwide for software supply chain security. You will join an ISO 27001-certified organization and work with cutting-edge technologies, implementing security controls that protect critical infrastructure.

Benefits, Location & Work Environment: You must be based in Ireland or the United Kingdom and have the right to work independently without requiring sponsorship. A remote-first position based in Ireland or the United Kingdom. A competitive compensation package, including equity, comprehensive health, dental, and vision insurance, generous annual leave, and flexible working policies to suit your lifestyle. Including a professional development budget for conferences and training.

Health and Wellness: Regardless of your location, we deeply care about our staff's and their families' health and wellness; a sustainable pace is essential. In addition to generous annual leave (PTO), we offer parental leave and health benefits to cover you and your dependents up to 100%. We also offer flexible, family-friendly working policies.

Personal Growth: You will have an enormous opportunity to learn new skills alongside your colleagues, and your continued professional development is essential to us because it's important to you. We will support you with budgets for equipment, training, books, conferences, travel, and certifications.

Hybrid / Remote First: Cloudsmith is headquartered in Belfast, Northern Ireland, and we use our H.Q. regularly for activities like team planning, meets and greets, and sometimes other group activities (like games!). We also hold all-hands offsites in Belfast (or otherwise) thrice yearly, with guest speakers and team activities. Most Cloudsmithers work remotely, close and far, so we rely on our online collaboration tools; Slack is how we work.

About Equal Opportunity: Cloudsmith is an equal-opportunity employer proud to nurture a diverse workplace that welcomes applications from individuals of all races, genders, and ethnic groups. We do not discriminate on age, religion, sexual orientation, citizenship status, military service, or health conditions. We will not tolerate discrimination of any kind within our workforce.

The Final Word: We are seeking someone with deep technical security expertise and a passion for building secure systems. You will be working at the intersection of cloud infrastructure, artifact management, and supply chain security, helping to develop a platform that organizations trust with their most critical assets. If you are excited about security engineering and want to have a lasting impact on the software industry, we want to hear from you.

Security Engineer (AppSec) employer: Cloudsmith

Cloudsmith is an exceptional employer, offering a dynamic and innovative work environment that prioritises employee growth and well-being. With a remote-first approach based in Ireland or the UK, employees enjoy competitive compensation, comprehensive health benefits, and generous annual leave, alongside opportunities for professional development and collaboration with cutting-edge technologies. Join us to make a meaningful impact on software supply chain security while being part of a supportive and trust-centric culture.
C

Contact Detail:

Cloudsmith Recruiting Team

StudySmarter Expert Advice 🀫

We think this is how you could land Security Engineer (AppSec)

✨Tip Number 1

Familiarise yourself with Cloudsmith's platform and its security features. Understanding how our artifact management system works will give you an edge in interviews, as you'll be able to discuss specific security challenges and solutions relevant to our technology.

✨Tip Number 2

Engage with the security community by participating in forums or attending meetups focused on application security. This not only helps you stay updated on the latest trends but also allows you to network with professionals who might have insights into our hiring process.

✨Tip Number 3

Showcase your hands-on experience with security tools and practices that align with our requirements, such as SAST, DAST, and CI/CD pipeline security. Be prepared to discuss specific projects where you've implemented these tools effectively.

✨Tip Number 4

Prepare to demonstrate your problem-solving skills through practical scenarios during the interview. Think of examples where you've successfully identified vulnerabilities and implemented security measures, as this will highlight your technical expertise and proactive approach.

We think you need these skills to ace Security Engineer (AppSec)

Application Security Expertise
Secure Software Development
Security Architecture Reviews
Threat Modelling
Security Code Reviews
Penetration Testing
Cloud Security (AWS)
API Security (REST/GraphQL)
CI/CD Pipeline Security
Container Security (Docker, OCI)
Database Security
Security Automation Tools
Threat Modelling and Risk Assessment
Cryptography Knowledge
Incident Response Experience
Software Supply Chain Security Understanding
Artifact Management Systems Knowledge
Compliance Framework Familiarity (ISO 27001, SOC2)
Programming Skills in Python
Familiarity with TypeScript/Node.js
Security Tool Development

Some tips for your application 🫑

Tailor Your CV: Make sure your CV highlights relevant experience in security engineering, particularly in application security. Emphasise your technical skills, such as programming in Python and familiarity with AWS, as these are crucial for the role.

Craft a Compelling Cover Letter: In your cover letter, express your passion for security engineering and how your background aligns with Cloudsmith's mission. Mention specific projects or experiences that demonstrate your ability to implement security controls and lead technical initiatives.

Showcase Relevant Projects: If you have worked on any security-related projects, especially those involving secure coding practices or penetration testing, be sure to include them in your application. This will help illustrate your hands-on experience and technical expertise.

Highlight Continuous Learning: Mention any certifications or ongoing education related to security, such as OSCP or CSSLP. This shows your commitment to staying updated in the field and aligns with Cloudsmith's value of continuous growth.

How to prepare for a job interview at Cloudsmith

✨Showcase Your Technical Expertise

Be prepared to discuss your hands-on experience with application security and secure software development. Highlight specific projects where you've implemented security controls or conducted penetration testing, as this will demonstrate your capability to handle the responsibilities of the role.

✨Understand Cloudsmith's Mission

Familiarise yourself with Cloudsmith's vision and how they are transforming software supply chain security. Being able to articulate how your skills align with their mission will show your genuine interest in the company and the role.

✨Prepare for Technical Questions

Expect in-depth technical questions related to security engineering, such as SAST, DAST, and RASP. Brush up on your knowledge of cloud security, API security, and CI/CD pipeline security to confidently answer these queries.

✨Demonstrate a Collaborative Mindset

Since the role involves working closely with engineering teams, be ready to discuss your experience in mentoring others and collaborating on security initiatives. Share examples of how you've successfully embedded security practices within teams to highlight your teamwork skills.

Security Engineer (AppSec)
Cloudsmith
C
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>