Application Security Researcher in London

Application Security Researcher in London

London Full-Time 60000 - 80000 € / year (est.) No home office possible
ActiveFence Ltd

At a Glance

  • Tasks: Lead advanced penetration tests and tackle complex security challenges for top global companies.
  • Company: Join Alice, a cutting-edge trust and safety company in the AI era.
  • Benefits: Competitive salary, flexible work environment, and opportunities for professional growth.
  • Other info: Dynamic team culture with opportunities to contribute to groundbreaking security solutions.
  • Why this job: Make a real impact in cybersecurity while working with innovative technologies.
  • Qualifications: 3+ years in application security, strong API testing skills, and a passion for problem-solving.

The predicted salary is between 60000 - 80000 € per year.

We are seeking a highly motivated and technically proficient Senior Penetration Tester to join our security research division. This role is dedicated to performing advanced offensive security assessments against the biggest companies in the world. You need to be independent, attentive to details, organized, eager to learn new things, and like to research and solve problems.

What you’ll do:

  • Lead and execute comprehensive, technically rigorous penetration tests targeting complex web applications, modern API architectures, and enterprise systems for organizations with significant global presence.
  • Engage in sophisticated Red Team projects, including the identification of undisclosed API endpoints, development of novel bypass techniques for established security controls, and lateral movement within target environments.
  • Contribute substantively to the design, development, and maintenance of proprietary internal security tools and automation frameworks to enhance the efficacy and efficiency of offensive operations.

Requirements:

  • Minimum of 3 years of proven, hands-on experience in application security analysis, with a heavy emphasis on complex API penetration testing and a mastery of the OWASP Top 10 landscape.
  • Strong experience with static and dynamic analysis of Android and iOS applications, including hands-on experience with techniques like detours, hooking, and runtime code manipulation.
  • Deep, hands-on knowledge of the latest tactics, techniques, and procedures (TTPs) used in advanced penetration testing and network analysis.
  • Ability to author comprehensive and technically rigorous reports detailing identified vulnerabilities and research outcomes.

Nice to have:

  • OSCP, OSWE, eWPTXv2, CRTP, or other high-level offensive certifications.
  • Hands-on experience with industry-standard reversing tools like JADX, Ghidra, or IDA Pro.
  • Demonstrated online achievements, write-ups, or contributions on platforms such as HackTheBox, Pwn2Own, TryHackMe, Bug Bounty programs, or published security research.

About Alice:

Alice is a trust, safety, and security company built for the AI era. We safeguard the communicative technologies people use to create, collaborate, and interact—whether with each other or with machines. In a world where AI has fundamentally changed the nature of risk, Alice provides end-to-end coverage across the entire AI lifecycle. We support frontier model labs, enterprises, and UGC platforms with a comprehensive suite of solutions: from model hardening evaluations and pre-deployment red-teaming to runtime guardrails and ongoing drift detection.

THE CHALLENGES ALONG THE WAY:

  1. Being Both Strategist and Executioner: One of the hardest parts of this role is that you’re both the visionary and the builder; the one drawing the map and paving the road. That means switching between high-level strategy and hands-on experimentation daily, and doing it while bringing others along with you. There’s no playbook for this kind of work. You’re paving an unpaved road, one small experiment at a time.
  2. Balancing Security and Innovation: ActiveFence is the leading provider of security and safety solutions for online experiences, safeguarding more than 3 billion users, top foundation models, and the world’s largest enterprises and tech platforms every day. As a trusted ally to major technology firms and Fortune 500 brands that build user-generated and GenAI products, ActiveFence empowers security, AI, and policy teams with low-latency Real-Time Guardrails and a continuous Red Teaming program that pressure-tests systems with adversarial prompts and emerging threat techniques. Powered by deep threat intelligence, unmatched harmful-content detection, and coverage of 117+ languages, ActiveFence enables organizations to deliver engaging and trustworthy experiences at global scale while operating safely and responsibly across all threat landscapes.

Application Security Researcher in London employer: ActiveFence Ltd

Alice is an exceptional employer that fosters a dynamic work culture where innovation meets security. With a strong emphasis on employee growth, team members are encouraged to engage in cutting-edge projects and develop proprietary tools, all while working alongside some of the biggest names in the industry. Located in a vibrant tech hub, Alice offers unique opportunities for collaboration and learning, making it an ideal place for those passionate about advancing their careers in application security.

ActiveFence Ltd

Contact Detail:

ActiveFence Ltd Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Application Security Researcher in London

Tip Number 1

Network like a pro! Attend industry meetups, conferences, or online webinars. Chat with fellow security enthusiasts and professionals; you never know who might have the inside scoop on job openings.

Tip Number 2

Show off your skills! Create a portfolio showcasing your penetration testing projects, write-ups, or contributions to platforms like HackTheBox. This will give potential employers a taste of what you can do.

Tip Number 3

Don’t just apply anywhere—apply through our website! Tailor your application to highlight your experience with API penetration testing and OWASP Top 10. Make it clear why you’re the perfect fit for us.

Tip Number 4

Prepare for interviews by brushing up on your technical knowledge and problem-solving skills. Be ready to discuss your past experiences in detail and demonstrate how you tackle complex security challenges.

We think you need these skills to ace Application Security Researcher in London

Penetration Testing
Application Security Analysis
API Penetration Testing
OWASP Top 10 Mastery
Static and Dynamic Analysis
Android and iOS Application Security
Detours and Hooking Techniques

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter for the role. Highlight your experience with application security and penetration testing, especially focusing on complex API architectures and the OWASP Top 10. We want to see how your skills align with what we’re looking for!

Show Off Your Projects:If you've worked on any cool projects or have contributions on platforms like HackTheBox or Bug Bounty programs, don’t hold back! Share these in your application. It gives us a glimpse into your hands-on experience and passion for security research.

Be Clear and Concise:When writing your application, keep it clear and to the point. We appreciate well-structured reports, so show us you can communicate effectively. Avoid jargon unless it’s necessary, and make sure your key achievements stand out!

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets to the right people. Plus, it shows us you’re keen on joining our team at StudySmarter!

How to prepare for a job interview at ActiveFence Ltd

Know Your Stuff

Make sure you brush up on your application security knowledge, especially the OWASP Top 10. Be ready to discuss your hands-on experience with complex API penetration testing and any relevant tools you've used. This will show that you're not just familiar with the theory but can apply it in real-world scenarios.

Show Off Your Projects

If you've contributed to platforms like HackTheBox or Bug Bounty programs, bring those achievements to the table. Prepare to talk about specific challenges you faced and how you overcame them. This demonstrates your problem-solving skills and passion for security research.

Prepare for Technical Questions

Expect in-depth technical questions related to penetration testing techniques and tools. Practice explaining your thought process when conducting assessments or developing security tools. Being articulate about your methods will impress interviewers and show your depth of knowledge.

Ask Insightful Questions

At the end of the interview, don’t shy away from asking questions about the company’s security practices or upcoming projects. This shows your genuine interest in the role and helps you gauge if the company aligns with your career goals. Plus, it gives you a chance to engage in a meaningful conversation!