Senior Application Security Engineer - 12 Month Fixed Term Contract in Uxbridge

Senior Application Security Engineer - 12 Month Fixed Term Contract in Uxbridge

Uxbridge Full-Time 65000 - 78000 £ / year (est.) No working from home possible
giffgaff | Certified B Corp

At a Glance

  • Tasks: Embed security in product design and development, ensuring safe software delivery.
  • Company: Join giffgaff, a certified B Corp focused on positive impact and collaboration.
  • Benefits: Competitive salary, hybrid working, and a supportive culture with great perks.
  • Other info: Dynamic environment with opportunities for personal and professional growth.
  • Why this job: Make a real difference in security while working with cutting-edge technology.
  • Qualifications: Experience in security assessments, coding languages, and DevSecOps practices.

The predicted salary is between 65000 - 78000 £ per year.

As a Senior Application Security Engineer at giffgaff on a 12-month fixed-term contract, you'll be responsible for embedding security into the way we design, build and operate our products. Working across a modern technology estate, you'll help ensure security is considered from the earliest stages of development through to production, enabling engineers to deliver secure software with confidence. This role combines technical depth with collaboration and influence.

You'll work alongside engineers, architects and platform teams to identify risks, improve security controls, drive vulnerability remediation and strengthen our DevSecOps capabilities. You'll also help foster a strong security culture by coaching teams and championing security best practice throughout the business.

Location: Uxbridge

Job Type: Full Time

The must haves:

  • Experience assessing security impacts across codebases and APIs using languages such as Java, TypeScript and Python.
  • Strong knowledge of the OWASP Top 10, secure coding practices, and common web and API vulnerabilities.
  • Hands-on experience triaging, validating and remediating vulnerabilities with both technical and non-technical stakeholders.
  • Experience integrating security tooling into CI/CD pipelines and embedding DevSecOps practices.
  • Proven expertise in threat modelling, secure code review, architecture review, and container/Kubernetes security.

The other stuff we are looking for:

  • Security certifications such as OSCP, GWAPT, CSSLP, CEH or Security+.
  • Experience securing AWS environments and infrastructure-as-code solutions such as Terraform.
  • Knowledge of AI-enabled security workflows and securing AI or LLM-powered features.
  • Experience contributing to or maintaining open-source security tooling.

Our goal is to celebrate our people and their lives. We aim to create a culture that empowers everyone to bring the best versions of themselves to work each and every day. We believe the most inclusive and diverse culture makes for a better business and a brighter world. Working at giffgaff means you get a bumper reward package bursting with benefits, and loads of extras you can add if you’d like to.

We’re all about hybrid working here, so expect to have a base location where you’ll have the right facilities to enable amazing collaboration and quality time with your team, alongside all the right kit to work from home too.

Senior Application Security Engineer - 12 Month Fixed Term Contract in Uxbridge employer: giffgaff | Certified B Corp

Join a forward-thinking company in Uxbridge, West London, where your role as a Senior Mobile Engineer will not only allow you to innovate but also contribute to a culture that values diversity and inclusion. With hybrid or remote working options, competitive salaries, and a strong emphasis on work-life balance and professional development, this is an excellent opportunity for those seeking meaningful and rewarding employment in a collaborative environment.

giffgaff | Certified B Corp

Contact Details:

giffgaff | Certified B Corp Recruitment Team

We think you need these skills to ace Senior Application Security Engineer - 12 Month Fixed Term Contract in Uxbridge

Application Security
Java
TypeScript
Python
OWASP Top 10
Secure Coding Practices
Web and API Vulnerabilities