Senior Security Engineer (Application) in London

Senior Security Engineer (Application) in London

London Full-Time 70000 - 90000 € / year (est.) No home office possible
Eeze

At a Glance

  • Tasks: Strengthen application security practices and embed security into engineering workflows.
  • Company: Dynamic engineering organisation focused on modern security practices.
  • Benefits: 26 days holiday, competitive salary, hybrid working, and personal growth opportunities.
  • Other info: Inclusive team culture with flexible hours and continuous support for your development.
  • Why this job: Make a real impact on security while collaborating with innovative engineering teams.
  • Qualifications: 3+ years in security-focused engineering, strong understanding of DevSecOps and secure coding.

The predicted salary is between 70000 - 90000 € per year.

We are seeking a Senior Security Engineer (Application) to help strengthen and mature application security practices across a fast‑moving engineering organisation. This is a hands‑on technical role focused on embedding security into engineering workflows, improving secure development practices and ensuring security is integrated throughout the software delivery lifecycle. The successful candidate will work closely with platform engineering, software engineering and architecture teams to identify security risks early, implement scalable controls and tooling and help drive modern DevSecOps and security‑by‑design practices across the organisation. The role requires a strong technical security engineer who remains close to engineering, understands modern application attack vectors and can balance security, scalability and developer experience. Operating within the wider Security Engineering function, the role will contribute towards improving organisational security maturity, strengthening application security capabilities and ensuring security standards evolve alongside modern engineering and platform practices.

Main Responsibilities

  • Partner with all engineering teams to embed security‑by‑design principles into applications, platforms and engineering workflows.
  • Perform threat modelling exercises across new applications, services, APIs and platform changes.
  • Review application architectures and engineering designs to identify security risks and recommend mitigations.
  • Drive secure‑by‑design and DevSecOps practices across engineering workflows and CI/CD pipelines.
  • Implement and manage secure code scanning, software supply chain security and application security tooling across modern delivery platforms.
  • Support implementation, tuning and operational maturity of application security tooling including SAST, DAST, SCA, secrets detection and cloud security platforms.
  • Identify, prioritise and support remediation of application, API and software supply chain vulnerabilities.
  • Define and maintain secure development standards, reusable security patterns and application security guardrails.
  • Work closely with developers to improve secure coding practices, vulnerability remediation and security awareness.
  • Support API security, authentication, authorisation and secrets management best practices across distributed systems.
  • Work closely with platform teams to improve security across containerised applications, Kubernetes environments and cloud‑native platforms.
  • Develop security automation and self‑service capabilities that improve developer experience whilst reducing risk.
  • Strong understanding of Layer 7 security concepts including API security, web application security, authentication, session management and protection against common web‑based attack vectors such as OWASP Top 10 threats.
  • Contribute towards incident response, vulnerability management and security investigations where required.
  • Continuously evaluate emerging application security threats, tooling and industry best practices to improve the organisation's security posture.

Main Requirements

  • 3+ years experience in a dedicated or heavily security‑focused engineering role.
  • Strong background in application or product security engineering within modern software environments.
  • Experience embedding security into CI/CD pipelines and software engineering workflows.
  • Strong understanding of DevSecOps principles and secure software development lifecycle practices.
  • Hands‑on experience with secure code scanning and application security tooling including SAST, DAST, SCA, dependency scanning and secrets detection platforms.
  • Experience with modern cloud and security platforms such as Wiz, Prisma Cloud or similar tooling.
  • Strong understanding of modern application attack vectors, API security and software supply chain security risks.
  • Experience working with containerised applications, Kubernetes and cloud‑native environments.
  • Ability to help design and implement scalable security controls within modern engineering and platform environments.
  • Strong troubleshooting, communication and stakeholder management capabilities.
  • Experience operating within regulated or high‑availability environments is advantageous.

What's in it for you?

  • Experience a dynamic and team‑orientated work environment.
  • Opportunities for personal growth and learning.
  • An open, inclusive and supportive team where you will be valued, and your suggestions will be welcome.
  • 26 days paid holiday per year. This is in addition to local public holidays.
  • Competitive salary.
  • Hybrid Working.
  • Risk Benefits such as pension, Life Assurance (4x annual salary), Private Medical Insurance.
  • Team Building Opportunities.
  • Flexible core hours between 10am - 4pm.
  • Receive support whenever you need it with our Employee Assistance Program, available 24/7.
  • Local discounts and more...

Our team is committed to keeping remuneration and benefits under constant review to make sure what we offer stays relevant.

Senior Security Engineer (Application) in London employer: Eeze

Join a dynamic and inclusive team as a Senior Security Engineer (Application) in Hammersmith, where your expertise will be valued and your contributions will directly impact our engineering workflows. Enjoy a supportive work culture that prioritises personal growth, offers flexible working hours, and provides comprehensive benefits including 26 days of paid holiday, competitive salary, and robust risk benefits. With opportunities for continuous learning and development, this role is perfect for those looking to make a meaningful impact in application security within a fast-paced environment.

Eeze

Contact Detail:

Eeze Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior Security Engineer (Application) in London

Tip Number 1

Network like a pro! Reach out to folks in the industry, attend meetups or webinars, and connect with potential colleagues on LinkedIn. The more people you know, the better your chances of landing that Senior Security Engineer role.

Tip Number 2

Show off your skills! Create a portfolio showcasing your past projects, especially those related to application security and DevSecOps. This will give hiring managers a taste of what you can bring to the table.

Tip Number 3

Prepare for interviews by brushing up on common security scenarios and challenges. Be ready to discuss how you've tackled security risks in previous roles and how you can embed security-by-design principles in engineering workflows.

Tip Number 4

Don't forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, we love seeing candidates who are genuinely interested in joining our team.

We think you need these skills to ace Senior Security Engineer (Application) in London

Application Security
DevSecOps
Secure Software Development Lifecycle
Threat Modelling
CI/CD Pipelines
SAST
DAST

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter for the Senior Security Engineer role. Highlight your experience with application security, DevSecOps, and any relevant tools you've used. We want to see how your skills align with our needs!

Showcase Your Technical Skills:Don’t hold back on detailing your technical expertise! Mention specific tools like SAST, DAST, and any cloud platforms you’ve worked with. We’re looking for someone who knows their stuff, so let us know what you bring to the table.

Be Clear and Concise:When writing your application, keep it clear and to the point. Use bullet points where possible to make it easy for us to read through your qualifications and experiences. We appreciate a well-structured application!

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it’s super easy – just follow the prompts!

How to prepare for a job interview at Eeze

Know Your Security Fundamentals

Make sure you brush up on your understanding of Layer 7 security concepts, especially around API security and web application vulnerabilities. Be ready to discuss the OWASP Top 10 threats and how they relate to modern application development.

Showcase Your Hands-On Experience

Prepare to share specific examples from your past roles where you've embedded security into CI/CD pipelines or improved secure coding practices. Highlight any tools you've used like SAST, DAST, or cloud security platforms, as this will demonstrate your practical knowledge.

Understand the DevSecOps Culture

Familiarise yourself with DevSecOps principles and be prepared to discuss how you can drive these practices within an engineering team. Think about how you can balance security with developer experience and scalability in your answers.

Engage with the Team Dynamics

Since this role involves collaboration with various teams, be ready to talk about your communication and stakeholder management skills. Share examples of how you've worked closely with developers or platform teams to enhance security measures in a project.