At a Glance
- Tasks: Lead application security practices and champion secure software development.
- Company: Join IAG Loyalty, a dynamic team driving digital transformation.
- Benefits: Flexible hybrid working, competitive salary, and a focus on professional growth.
- Why this job: Make a real impact on security for millions of loyalty members.
- Qualifications: Experience in software engineering with a strong security mindset.
- Other info: Embrace diversity and inclusion in a collaborative environment.
The predicted salary is between 36000 - 60000 £ per year.
As IAG Loyalty evolves into a Platform as a Service business, we are looking for a talented and passionate Senior Application Security Engineer to join our security engineering team. You will have a background in software engineering and a deep interest in application and API security. You thrive on collaboration, enjoy helping others grow, and see security as an enabler - not a blocker. You will be an AppSec advocate who supports our engineers in identifying and addressing security issues across the software development lifecycle. You will be part of a small, dynamic team within the Product department that drives IAG Loyalty's digital transformation, technology strategy, and product direction. Our cloud-native platform powers the Avios currency and the digital experiences used by millions of loyalty members. This is a great opportunity to work with cutting edge technology in a fast paced, agile environment. This role is based out of our London office. We call our approach to hybrid working The Blend - it is about giving you the flexibility to choose where you do your best work, while staying connected with your team and the wider business. This means you will be required to spend at least two days per week in the office, with the rest of the time working from home. You may also be required to work from one of our other office or partner locations, based on your role and 'to do' list.
What you will be doing:
- As a Senior Application Security Engineer, you will lead the application security practice within the IAG Loyalty security team, taking responsibility for key security KPIs in this area.
- You will champion secure software development by working closely with engineers and product teams, embedding security practices into our engineering culture.
- You will provide training, offer expert advice, and drive awareness of security from the earliest stages of design through to deployment.
- You will help integrate automated security tooling and checks into our CI/CD pipelines, facilitate threat modelling sessions, and review security sensitive design decisions around authentication, cryptography, and logging.
- You will also ensure that tools such as SAST, DAST, and SCA are effective and efficient, and that testing programmes — including pen testing, vulnerability scanning, and bug bounty — are delivering value.
- You will triage vulnerabilities, support engineering teams with practical mitigations, and contribute to documentation that strengthens our internal standards and processes.
- Maintaining a strong security culture will be a key focus, and you will also support internal and external audits where needed.
Experience required:
- Experience in software engineering, with a strong security mindset.
- Deep understanding of web and API vulnerabilities, including the OWASP Top 10.
- Proficient in coding, scripting (e.g. Python, Bash), and automating security in CI/CD.
- Hands on experience with security tools like SAST, DAST, and SCA.
- Familiar with cloud environments (especially AWS), containers, and microservices.
- Comfortable reviewing technical designs, performing threat modelling, and advising on secure architecture.
- Strong communicator who collaborates well with engineers and promotes secure by default practices.
We might not be right for you if:
- You only want to focus on your to-do list; we are a small, high performing team, we help each other to succeed.
- You value perfection over fast iteration and progress; IAG Loyalty moves fast, we learn and iterate as we go; our environment isn’t right for everyone.
- You are looking to create but not build; this is an end to end role, you need to be comfortable owning your space, from ideation through to delivery and review.
If you think you have what it takes but don’t meet every single point above, please do still apply. We would love to chat and see if you could be a great fit.
Equity, Diversity and Inclusion at IAG Loyalty:
Our vision, 'to create the world’s most rewarding experiences,' applies not only to our customers but for our colleagues too. It is about taking belonging seriously, actively fostering a culture where everyone feels welcomed and valued by embracing diverse identities, personal histories, and perspectives. This commitment makes IAG Loyalty a rewarding place to work and enhances our ability to solve complex problems, drive innovation, and better serve our customers and communities. Please let us know if we can make any reasonable adjustments to support your interview process with us.
Senior Application Security Engineer in City of Westminster employer: IAG Loyalty
Contact Detail:
IAG Loyalty Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Application Security Engineer in City of Westminster
✨Tip Number 1
Network like a pro! Reach out to current employees at IAG Loyalty on LinkedIn or other platforms. Ask them about their experiences and any tips they might have for the application process. This can give you insider knowledge and make your application stand out.
✨Tip Number 2
Prepare for the interview by brushing up on your technical skills. Since this role focuses on application security, be ready to discuss the OWASP Top 10 and demonstrate your understanding of secure coding practices. We want to see your passion for security!
✨Tip Number 3
Showcase your collaborative spirit! During interviews, highlight examples of how you've worked with teams to improve security practices. Remember, IAG Loyalty values teamwork, so let us know how you can contribute to a strong security culture.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our team and being part of IAG Loyalty's exciting journey.
We think you need these skills to ace Senior Application Security Engineer in City of Westminster
Some tips for your application 🫡
Show Your Passion for Security: When writing your application, let your enthusiasm for application and API security shine through. We want to see how you view security as an enabler, not a blocker, so share examples of how you've championed secure practices in your previous roles.
Tailor Your Experience: Make sure to highlight your software engineering background and any hands-on experience with security tools like SAST, DAST, and SCA. We love seeing how your skills align with our needs, so don’t hold back on the details!
Emphasise Collaboration: Since we thrive on teamwork, mention instances where you've worked closely with engineers or product teams. Show us how you’ve helped others grow and fostered a strong security culture in your past experiences.
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for this exciting opportunity. Plus, it shows you’re keen to join our team!
How to prepare for a job interview at IAG Loyalty
✨Know Your Stuff
Make sure you brush up on your knowledge of web and API vulnerabilities, especially the OWASP Top 10. Be ready to discuss how you've tackled these issues in past projects, as this will show your deep understanding of application security.
✨Show Your Coding Skills
Since coding is a big part of this role, be prepared to demonstrate your proficiency in languages like Python or Bash. You might even be asked to solve a coding challenge during the interview, so practice some scripting and automation tasks beforehand.
✨Emphasise Collaboration
This position requires a strong communicator who can work well with engineers. Share examples of how you've successfully collaborated with teams in the past, particularly in embedding security practices into the development lifecycle.
✨Be Ready for Real-World Scenarios
Expect to discuss practical scenarios related to threat modelling and secure architecture. Prepare to explain how you would approach specific security challenges, and don’t hesitate to share your thought process on integrating security tools into CI/CD pipelines.