Senior Application Security Engineer - DevSecOps & Cloud Security

Senior Application Security Engineer - DevSecOps & Cloud Security

Full-Time 70000 - 80000 Β£ / year (est.) Home office (partial)
A

At a Glance

  • Tasks: Integrate security into software development and enhance secure processes in a collaborative environment.
  • Company: Join a leading health research charity making a real difference in medical advancements.
  • Benefits: Competitive salary, hybrid work model, and excellent benefits package.
  • Other info: Opportunity for career growth in a dynamic and supportive team.
  • Why this job: Make a meaningful impact on the safe adoption of emerging technologies in healthcare.
  • Qualifications: Experience in application security, cloud technologies, and CI/CD practices required.

The predicted salary is between 70000 - 80000 Β£ per year.

An opportunity has arisen for a Senior Application Security Engineer to join a well-established health research organisation and charity that supports large-scale medical research to improve disease prevention, diagnosis and treatment.

As a Senior Application Security Engineer, you will play a key part in integrating security throughout the software development lifecycle, working alongside engineering and cloud teams to build, improve and maintain secure applications, platforms and deployment processes. This is not a traditional vulnerability management role; it is a hands-on Application Security role centred on secure design, CI/CD security, cloud-native technologies, Kubernetes, API security, code analysis, security-as-code and supporting development teams to build secure applications.

This is a full-time permanent role, working on a hybrid basis with a Central London office location, offering a salary from 70,000 per annum and an excellent benefits package. Visa sponsorship is not available.

You will be responsible for:

  • Working closely with engineering and architecture teams to promote secure development from the earliest stages of delivery.
  • Implementing and maintaining application security testing solutions, enabling developers to identify and remediate security risks.
  • Enhancing secure development processes by integrating security controls throughout CI/CD pipelines.
  • Strengthening the security of GitHub Actions and comparable continuous integration and deployment platforms.
  • Providing technical guidance on secure API design and protecting externally accessible systems.
  • Supporting the security of Azure cloud infrastructure, including Azure Kubernetes Service (AKS).
  • Assisting with the protection of cloud-hosted data platforms and associated technologies.
  • Developing and maintaining security-as-code and policy-as-code using appropriate tooling.
  • Automating security processes through infrastructure-as-code and scripting technologies.
  • Producing and maintaining technical documentation, security procedures and service documentation.
  • Supporting development teams with the adoption and integration of security tooling and best practices.
  • Contributing to wider cyber security initiatives, including threat modelling and compliance activities.

What we are looking for:

  • Previously worked as a Senior Application Security Engineer, Lead Application Security Engineer, Principal Application Security Engineer, Application Security Engineer, Senior Product Security Engineer, Product Security Engineer, Senior DevSecOps Engineer, DevSecOps Engineer, Application Security Consultant or in a similar role.
  • Hands-on experience embedding application security into the SDLC.
  • Experience securing APIs, internet-facing services, and Kubernetes (preferably AKS) and containerised environments.
  • Experience working with engineering teams and implementing security testing tools (SAST, DAST, IAST, SCA).
  • Knowledge of security automation, security-/policy-as-code, and secure engineering practices (code review, testing, source control, documentation).
  • Familiar with CI/CD tools such as GitHub and GitHub Actions.
  • Highly skilled in Terraform and Python.
  • Strong understanding of Azure security controls and cloud security governance.
  • Experience with threat modelling in software engineering contexts.
  • Knowledge of ISO 27001 and its relevance to secure engineering.
  • Familiar with Agile and DevSecOps methodologies.
  • Eligible to work in the UK.

This is an excellent opportunity for a Senior Application Security Engineer where you can make a meaningful impact on the safe and effective adoption of emerging technologies.

Senior Application Security Engineer - DevSecOps & Cloud Security employer: Additional Resources

At Additional Resources, we pride ourselves on fostering a collaborative and innovative work culture that empowers our employees to thrive. As a Senior App Security Engineer, you will benefit from flexible hybrid remote work arrangements in London, competitive salary packages, and ample opportunities for professional growth in the rapidly evolving field of application security. Join us to make a meaningful impact while enjoying a supportive environment that values your contributions and encourages continuous learning.

A

Contact Details:

Additional Resources Recruitment Team

We think you need these skills to ace Senior Application Security Engineer - DevSecOps & Cloud Security

SQL
Python
Problem-Solving Skills
Communication Skills
Automation
Data Engineering
Data Pipeline Development