Senior Application Security Engineer in London

Senior Application Security Engineer in London

London Full-Time 80000 - 100000 € / year (est.) Home office (partial)
Amach

At a Glance

  • Tasks: Lead application security practices and enhance software security across engineering processes.
  • Company: Join Amach, a tech leader modernising aviation with cloud, data, and AI.
  • Benefits: Flexible work, competitive salary, and great career advancement opportunities.
  • Other info: Work in a dynamic environment with a focus on collaboration and innovation.
  • Why this job: Make a real impact in a fast-growing company while shaping security practices.
  • Qualifications: 8+ years in application security and strong coding skills required.

The predicted salary is between 80000 - 100000 € per year.

Amach is an industry‑leading technology driven company founded in 2013, headquartered in Dublin with remote teams in the UK and Europe. We help airlines modernise their operating model using cloud, data and AI, delivering solutions with deep aviation domain expertise.

Senior Application Security Engineer is responsible for leading the application security practice, taking ownership of key security KPIs, and strengthening the security of software, systems and engineering processes. Candidates must be willing to work from the Central London office two days per week.

Responsibilities

  • Lead the application security practice and drive measurable improvements in application security maturity.
  • Embed secure development practices across the engineering lifecycle, from design to deployment.
  • Provide expert guidance on secure architecture and design decisions.
  • Facilitate threat‑modelling sessions and review security‑sensitive decisions on authentication, cryptography and logging.
  • Integrate and configure automated security tooling (SAST, DAST, SCA) and oversee testing programs including penetration testing, vulnerability scanning and bug bounty initiatives.
  • Triage vulnerabilities and support engineering teams with practical remediation and mitigation plans.
  • Deliver training, raise awareness and champion secure‑by‑default practices across the organisation.
  • Contribute to documentation, internal security standards and engineering processes.
  • Support internal and external audits and promote a strong security culture across the organisation.

Required Skills

  • 8+ years of experience in application security, software engineering and/or product security.
  • Strong hands‑on experience in secure software development environments.
  • Proficiency in coding and scripting (Python, Bash); working knowledge of GitHub‑based delivery pipelines.
  • Experience leading or shaping application security practices across engineering teams.
  • Deep understanding of web and API vulnerabilities, including OWASP Top 10 and modern attack patterns.
  • Familiarity with modern cloud‑native environments (especially AWS), containers and microservices architectures.
  • Experience working closely with software engineers to embed security into day‑to‑day development.
  • Proven ability to review security‑sensitive technical designs (auth, crypto, logging).
  • Hands‑on experience integrating and tuning SAST, DAST and SCA within CI/CD workflows.
  • Experience supporting or evaluating security testing programmes such as penetration testing, vulnerability scanning and bug bounty.
  • Practical experience triaging vulnerabilities and collaborating with engineering teams on realistic remediation plans.
  • Comfortable acting as a go‑to person for technical security discussions and presenting to senior technical and non‑technical stakeholders.
  • Strong communication skills and ability to provide guidance, training and practical advice that promotes secure‑by‑default engineering behaviours.
  • Experience automating security controls and checks in modern software delivery pipelines.
  • Ability to review application and platform designs from a security perspective.
  • Strong collaboration skills and a practical, engineering‑focused approach to improving security outcomes.

Benefits

  • Opportunity to join a fast‑growing company.
  • Options for career advancement.
  • Learning and development opportunities.
  • Flexible working environment.
  • Competitive salary based on experience.

Equal Opportunity Employer

Amach is an equal opportunity employer and makes employment decisions on the basis of merit. We celebrate diversity and are committed to creating an inclusive environment for all employees.

Senior Application Security Engineer in London employer: Amach

Amach is an exceptional employer, offering a dynamic and inclusive work culture that prioritises employee growth and development. With a focus on innovation in the aviation sector, employees benefit from flexible working arrangements, competitive salaries, and ample opportunities for career advancement, all while contributing to meaningful projects that leverage cutting-edge technology. Located in Central London, the company fosters a collaborative environment where security practices are embedded into the engineering lifecycle, ensuring that team members can thrive both personally and professionally.

Amach

Contact Detail:

Amach Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior Application Security Engineer in London

Network Like a Pro

Get out there and connect with folks in the industry! Attend meetups, webinars, or even just grab a coffee with someone who works at Amach. Building relationships can open doors that a CV just can't.

Show Off Your Skills

When you get the chance to chat with potential employers, don’t hold back! Share your hands-on experience with secure software development and any cool projects you've worked on. Let them see the real you!

Prepare for Technical Chats

Brush up on your knowledge of web and API vulnerabilities, especially the OWASP Top 10. Be ready to discuss how you've tackled security challenges in the past. Confidence is key!

Apply Through Our Website

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you're genuinely interested in joining our team at Amach.

We think you need these skills to ace Senior Application Security Engineer in London

Application Security
Secure Software Development
Threat Modelling
Vulnerability Management
Penetration Testing
SAST
DAST

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Senior Application Security Engineer role. Highlight your experience in application security, secure software development, and any relevant projects that showcase your skills. We want to see how you fit into our world!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about application security and how your background aligns with our mission at Amach. Let us know what excites you about the role and our company.

Showcase Your Technical Skills:Don’t forget to highlight your technical skills, especially in coding and scripting languages like Python and Bash. Mention your hands-on experience with security tools and practices, as we’re keen on seeing your practical knowledge in action.

Apply Through Our Website:We encourage you to apply through our website for a smoother process. It helps us keep track of your application and ensures you don’t miss out on any important updates. Plus, it’s super easy!

How to prepare for a job interview at Amach

Know Your Stuff

Make sure you brush up on your application security knowledge, especially the OWASP Top 10 and modern attack patterns. Be ready to discuss how you've applied this knowledge in previous roles, as well as any specific tools you've used like SAST, DAST, or SCA.

Showcase Your Leadership Skills

Since this role involves leading the application security practice, be prepared to share examples of how you've successfully led teams or initiatives in the past. Highlight your experience in embedding secure development practices and how you've driven measurable improvements in security maturity.

Prepare for Technical Discussions

Expect to dive deep into technical discussions about secure architecture and design decisions. Brush up on your coding and scripting skills, particularly in Python and Bash, and be ready to explain how you've integrated security into CI/CD workflows.

Communicate Clearly

Strong communication skills are key for this role. Practice explaining complex security concepts in a way that non-technical stakeholders can understand. Think about how you can convey your passion for security and your ability to train others in secure-by-default practices.