Application Security Engineer - Enterprise in London

Application Security Engineer - Enterprise in London

London Full-Time 63000 - 77000 £ / year (est.) Home office (partial)
CloudBees

At a Glance

  • Tasks: Secure AI initiatives and develop standards for internal apps and workflows.
  • Company: Join CloudBees, a leader in enterprise security and software delivery.
  • Benefits: Enjoy a hybrid work environment with competitive salary and growth opportunities.
  • Other info: Collaborate with top professionals and tackle unique security challenges.
  • Why this job: Make a real impact on enterprise security in the AI era.
  • Qualifications: Experience in software security and secure SDLC practices required.

The predicted salary is between 63000 - 77000 £ per year.

Working Time: Full time

Location: UK, London - Hybrid

About CloudBees

CloudBees enables enterprises to deliver scalable, compliant, and secure software, empowering developers to do their best work. Seamlessly integrating into any hybrid and heterogeneous environment, CloudBees is more than a tool—it's a strategic partner in your cloud transformation journey, ensuring security, compliance, and operational efficiency while enhancing the developer experience across your entire software development lifecycle.

About the Role

We're looking for a motivated engineer to help secure the most critical AI initiatives across the business. Most application security engineers spend their careers on the product side. This role puts you on the other side: AI-era security for the business itself, not the product customers use. You'll work alongside the CISO on problems most companies don't have a playbook for yet.

The work is product security with an enterprise scope. Internal apps, AI tools, and agents are products that need the same threat modeling, secure design, and engineering rigour as anything customer-facing. Alongside enterprise security work, you'll build tooling, automation, and agents that help the broader security team scale with AI.

This is a hands-on role. Bring initiative. We'll give you the problems worth solving.

What You'll Do

  • Secure Development Standards
    • Develop secure SDLC standards for internal apps and AI workflows
    • Build patterns, reference architectures, and the documentation teams need to self-serve
    • Work with business teams to raise the profile of security and adopt secure practices, especially for AI and low-code
  • Threat modeling and risk assessment
    • Conduct threat modeling, risk assessments, and technical security reviews for enterprise systems, internal apps, and AI and agentic deployments
    • Identify and prioritize security risks; advise risk, compliance, audit, and business teams on mitigations
    • Translate findings into actionable enterprise controls and detection requirements
  • AI and agentic security
    • Design safeguards for enterprise AI tooling, including agents and non-human identities
    • Evaluate and integrate emerging AI/ML security tools
    • Stay current with the AI security landscape
  • Building and automation
    • Engineer and automate AI-first security workflows that scale the wider Security team
    • Build for the enterprise domain in a way that benefits Product Security, SOC, and GRC

What You Bring

  • Security expertise
    • Hands-on experience in software and enterprise security
    • Desirable: working knowledge in any of SaaS, cloud, IAM, or endpoint security
  • Secure SDLC
    • Proficiency in secure SDLC fundamentals, including threat modelling, secure design, vulnerability management, and CI/CD security
  • Engineering and tooling
    • Comfortable writing and reviewing code (Python, Go, TypeScript, or similar)
    • Experience building integrations and automating security workflows
    • Experience with security tools at scale — SAST, DAST, SIEM, endpoint, cloud, identity, AI/ML, vulnerability management platforms
  • AI and agentic security knowledge
    • Understanding of AI/ML security risks, attack vectors, and vulnerabilities
    • Familiarity with agentic AI frameworks and generative AI tools
  • Communication and interpersonal skills
    • Exceptional written and verbal communication; able to translate complex security concepts for any audience
    • Strong interpersonal skills; build trust and credibility quickly across technical and non-technical teams
    • Drive outcomes through collaboration
  • Mindset
    • Self-starter with initiative and ownership
    • Hacker mindset — figures out the problem, then solves it
    • Thrives in ambiguity

Working Conditions

Hybrid - Full time Travel required. Adjustments will be considered to accommodate individual needs in line with applicable equality and disability legislation.

Equal Opportunity Statement

CloudBees is committed to providing equal opportunities in employment. We value diversity and inclusion and make decisions based on skills, qualifications, and experience. We do not discriminate on the basis of age, disability, gender identity, marital or civil status, pregnancy, maternity, race, religion or belief, sex, or sexual orientation, in accordance with applicable laws.

Data Protection Statement

All personal data collected during the recruitment process will be processed in line with CloudBees’s Privacy Policy and applicable data protection legislation, including the EU General Data Protection Regulation (GDPR).

Disclaimer

This job description provides an overview of the role and key responsibilities. It is not an exhaustive list, and responsibilities may evolve in line with business needs.

Application Security Engineer - Enterprise in London employer: CloudBees

CloudBees is an exceptional employer that fosters a dynamic and inclusive work culture, empowering employees to thrive in their roles while driving innovation in the DevSecOps space. With a strong emphasis on professional development, employees have access to extensive training programs and opportunities for growth, all while enjoying the flexibility of remote work across the UK and Ireland. Join us to be part of a collaborative team that values your contributions and supports your career journey.

CloudBees

Contact Details:

CloudBees Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Application Security Engineer - Enterprise in London

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including CloudBees, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through CloudBees

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at CloudBees. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Application Security Engineer - Enterprise in London

Secure SDLC
Threat Modeling
Risk Assessment
Technical Security Reviews
Vulnerability Management
CI/CD Security
Python

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at CloudBees insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to CloudBees that you’re committed to staying ahead in the game.

How to prepare for a job interview at CloudBees

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at CloudBees to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at CloudBees.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.