At a Glance
- Tasks: Secure software delivery by embedding security across platforms and leading threat modelling.
- Company: Join a cutting-edge software supply chain company focused on security and innovation.
- Benefits: Enjoy remote work options, flexible hours, and opportunities for professional growth.
- Why this job: Make a real impact by protecting what you build and enhancing security culture.
- Qualifications: Experience in software development, Python, application security, and cloud security is essential.
- Other info: This role is remote within the Island of Ireland or the UK only.
The predicted salary is between 48000 - 72000 £ per year.
Some people like building things. You love both and more importantly, you love stopping bad actors from breaking the things you helped build. This job is with the software supply chain company - securing and powering how software gets delivered everywhere.
Responsibilities:
- Embed security across the platform, from source to production.
- Architect security controls across distributed, cloud-native systems.
- Lead threat modeling and security reviews.
- Extend security automation and monitoring with tools like CircleCI, GitHub Actions, DataDog, AWS Security Hub, etc.
- Write secure code, review other people’s code, and help everyone level up their secure coding game.
Requirements:
- A background in software development; at your core, you’re a software engineer.
- Proficiency in Python and some experience with TypeScript.
- Deep application security knowledge.
- Hands-on experience with SAST, DAST, RASP, and securing cloud (preferably AWS).
- Strong grasp of container security, API security, IaC, and CI/CD.
- Experience with pen testing, threat modeling, and building security tools.
- Big bonus if you’ve secured artifact systems or supply chains before.
- Bigger bonus if you’ve worked with Firecracker, gVisor, or technologies like SCA and data enclaves.
You believe security should enable, not block, engineering. This job is remote on the Island of Ireland or in the UK. You need to be physically located here - you cannot work remotely from another country. Work permit sponsorship is not available.
Senior Security Applications Engineer employer: Cloudsmith
Contact Detail:
Cloudsmith Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Security Applications Engineer
✨Tip Number 1
Familiarise yourself with the latest trends in application security, especially around SAST, DAST, and RASP. Being able to discuss recent developments or tools you've used in these areas during your interview will show your passion and expertise.
✨Tip Number 2
Prepare to demonstrate your hands-on experience with cloud security, particularly AWS. Be ready to share specific examples of how you've secured cloud environments or implemented security controls in previous roles.
✨Tip Number 3
Brush up on your coding skills, especially in Python and TypeScript. You might be asked to solve a coding challenge or review code during the interview, so being sharp in these languages will give you an edge.
✨Tip Number 4
Showcase your ability to lead and engage others in security practices. Think of examples where you've successfully conducted threat modelling sessions or security reviews that were well-received by your team.
We think you need these skills to ace Senior Security Applications Engineer
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights your experience in software development, particularly with Python and TypeScript. Emphasise your hands-on experience with security tools like SAST, DAST, and cloud security, especially AWS.
Craft a Compelling Cover Letter: In your cover letter, express your passion for security and how it enables engineering. Mention specific projects where you've implemented security measures or tools, and how you’ve contributed to secure coding practices within teams.
Showcase Relevant Experience: When detailing your work history, focus on roles where you’ve led threat modelling, conducted security reviews, or developed security automation. Include any experience with container security, API security, and CI/CD processes.
Highlight Continuous Learning: Mention any relevant certifications or courses you've completed related to application security, cloud security, or secure coding. This shows your commitment to staying updated in the field and improving your skills.
How to prepare for a job interview at Cloudsmith
✨Showcase Your Technical Skills
Be prepared to discuss your experience with security tools like CircleCI, GitHub Actions, and AWS Security Hub. Highlight specific projects where you've implemented security measures and how they improved the overall system.
✨Demonstrate Your Problem-Solving Abilities
Expect to face scenario-based questions that assess your ability to handle security threats. Use examples from your past experiences to illustrate how you approached and resolved similar challenges.
✨Emphasise Collaboration and Communication
Since you'll be leading threat modelling and security reviews, it's crucial to show that you can engage and motivate others. Share instances where you've successfully collaborated with teams to enhance security practices.
✨Prepare for Coding Challenges
Brush up on your coding skills, particularly in Python and TypeScript. Be ready to write secure code during the interview and explain your thought process behind it, as this will demonstrate your technical proficiency.