Senior Application Security Engineer (United Kingdom)
Senior Application Security Engineer (United Kingdom)

Senior Application Security Engineer (United Kingdom)

Guernsey Full-Time 43200 - 72000 £ / year (est.) Home office (partial)
C

At a Glance

  • Tasks: Secure software delivery by embedding security across platforms and leading threat modelling.
  • Company: Join a cutting-edge software supply chain company focused on security and innovation.
  • Benefits: Enjoy remote work options, flexible hours, and opportunities for professional growth.
  • Why this job: Be part of a dynamic team that values creativity and collaboration in securing software.
  • Qualifications: Experience in software development, application security, and cloud security is essential.
  • Other info: This role is remote within the UK or Ireland; no sponsorship available.

The predicted salary is between 43200 - 72000 £ per year.

Some people like building things. Others like breaking them. You? You love both and more importantly, you love stopping bad actors from breaking the things you helped build. If that sounds like your vibe, we’ve got a job you’ll want to see. This job is with the software supply chain company - securing and powering how software gets delivered everywhere.

What you'll do:

  • Embed security across the platform, from source to prod.
  • Architect security controls across distributed, cloud-native systems.
  • Lead threat modeling and security reviews (and get people to enjoy them).
  • Pen-test services and infra (ethically, please).
  • Extend security automation and monitoring with tools like CircleCI, GitHub Actions, DataDog, AWS Security Hub, etc.
  • Harden everything from container runtimes to APIs to artifact pipelines.
  • Write secure code, review other people’s code, and help everyone level up their secure coding game.
  • Build tools, automate boring stuff, and occasionally drop a ‘sploity’ proof of concept for fun.

You need:

  • A background in software development. At your core, you’re a software engineer. Python for sure and a bit of TypeScript never hurt anyone.
  • Deep application security knowledge.
  • Hands-on experience with SAST, DAST, RASP, and securing cloud (preferably AWS).
  • Strong grasp of container security, API security, IaC, and CI/CD.
  • You’ve done pen testing, threat modeling, and maybe even built some of your own security tools.
  • Big bonus if you’ve secured artifact systems or supply chains before.
  • Bigger bonus if you’ve worked with Firecracker, gVisor, or fancy things like SCA and data enclaves.
  • You believe security should enable, not block, engineering.
  • You’re a diplomat - you gotta work with engineering to secure the SDLC, not spook them.

If interested, get in touch on rose@ninedots.io. This job is remote on the Island of Ireland or in the UK. You need to be physically located here - you cannot work remotely from another country. Work permit sponsorship is not available.

Senior Application Security Engineer (United Kingdom) employer: Cloudsmith

As a Senior Application Security Engineer at our innovative software supply chain company, you'll thrive in a dynamic work culture that values both creativity and security. We offer competitive benefits, opportunities for professional growth, and a collaborative environment where your expertise will directly impact the safety of software delivery. Join us in the UK or on the Island of Ireland, where you can enjoy a flexible remote work setup while being part of a team that believes in empowering engineers through security.
C

Contact Detail:

Cloudsmith Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Senior Application Security Engineer (United Kingdom)

✨Tip Number 1

Network with professionals in the application security field. Attend meetups, webinars, or conferences where you can connect with others who share your passion for security. This can lead to valuable insights and potential referrals.

✨Tip Number 2

Showcase your hands-on experience by contributing to open-source security projects or creating your own tools. This not only demonstrates your skills but also highlights your commitment to the security community.

✨Tip Number 3

Prepare to discuss specific examples of your work in application security during interviews. Be ready to explain how you've implemented security controls, conducted threat modelling, or performed pen tests in previous roles.

✨Tip Number 4

Familiarise yourself with the latest trends and technologies in application security, especially those mentioned in the job description like SAST, DAST, and CI/CD. Being knowledgeable about these tools will help you stand out as a candidate.

We think you need these skills to ace Senior Application Security Engineer (United Kingdom)

Application Security Knowledge
Software Development Background
Proficiency in Python
Familiarity with TypeScript
Experience with SAST and DAST
Knowledge of RASP
Cloud Security Expertise (preferably AWS)
Container Security Skills
API Security Understanding
Infrastructure as Code (IaC) Proficiency
Continuous Integration/Continuous Deployment (CI/CD) Experience
Penetration Testing Skills
Threat Modelling Experience
Security Tool Development
Ability to Collaborate with Engineering Teams
Strong Communication Skills
Automation Skills
Experience with Security Automation Tools (e.g., CircleCI, GitHub Actions, DataDog, AWS Security Hub)
Knowledge of Artifact Systems and Supply Chain Security
Familiarity with Firecracker and gVisor
Understanding of Software Composition Analysis (SCA) and Data Enclaves

Some tips for your application 🫡

Tailor Your CV: Make sure your CV highlights your software development background, particularly in Python and TypeScript. Emphasise your experience with application security, including SAST, DAST, and cloud security, to align with the job requirements.

Craft a Compelling Cover Letter: In your cover letter, express your passion for both building and securing software. Mention specific experiences where you've successfully implemented security measures or led threat modelling sessions, showcasing your ability to work collaboratively with engineering teams.

Showcase Relevant Projects: If you have worked on projects involving container security, API security, or CI/CD, be sure to include these in your application. Highlight any tools you've built or automated processes that demonstrate your hands-on experience in application security.

Highlight Soft Skills: Since the role requires working closely with engineering teams, emphasise your diplomatic skills and ability to communicate effectively. Provide examples of how you've successfully collaborated with others to enhance security without hindering development.

How to prepare for a job interview at Cloudsmith

✨Showcase Your Technical Skills

Be prepared to discuss your experience with Python, TypeScript, and the various security tools mentioned in the job description. Highlight specific projects where you've implemented security measures or developed security tools.

✨Demonstrate Your Problem-Solving Ability

Expect to face scenario-based questions that assess your ability to identify vulnerabilities and propose solutions. Use examples from your past experiences to illustrate how you approached similar challenges.

✨Emphasise Collaboration

Since the role requires working closely with engineering teams, be ready to discuss how you've successfully collaborated with others in the past. Share instances where you’ve helped teams understand security without causing friction.

✨Prepare for Threat Modelling Discussions

As leading threat modelling is part of the job, brush up on your knowledge of the process. Be ready to explain how you would approach threat modelling for a given application and engage the interviewers in a discussion about it.

Senior Application Security Engineer (United Kingdom)
Cloudsmith
C
  • Senior Application Security Engineer (United Kingdom)

    Guernsey
    Full-Time
    43200 - 72000 £ / year (est.)

    Application deadline: 2027-06-19

  • C

    Cloudsmith

Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>