Application Security Engineer in London

Application Security Engineer in London

London Full-Time 48000 - 72000 £ / year (est.) No working from home possible
Millennium Management, LLC

At a Glance

  • Tasks: Lead the charge in securing AI technologies and applications while collaborating with diverse teams.
  • Company: Join a top-tier firm dedicated to protecting information and systems in a dynamic tech environment.
  • Benefits: Enjoy competitive pay, flexible work options, and opportunities for professional growth.
  • Other info: Be part of a collaborative team focused on innovation and excellence in security.
  • Why this job: Make a real impact by shaping security practices in cutting-edge AI and application development.
  • Qualifications: 5+ years in application security with a strong grasp of AI risks and secure coding.

The predicted salary is between 48000 - 72000 £ per year.

The successful candidate will be a subject matter expert with direct experience in a wide range of security technologies, tools, and methodologies. The role is suited for an experienced Application Security engineer with proven understanding in enterprise security and AI security and will focus on building toolsets and processes to drive adoption of secure practices across the enterprise. The team fosters a collaborative environment and is building a best-in-class program to partner with the business to protect the Firm's information and computer systems. Millennium is a complex and robust technical environment and securing the Firm from external and internal threats is a top priority.

Principal Responsibilities

  • AI Security Strategy: Define and implement security guardrails for Generative AI, LLMs, and Agentic frameworks, ensuring safe enterprise adoption.
  • AI Risk Management: Conduct specialized threat modeling, red teaming, and risk assessments for AI/ML models (e.g., testing for prompt injection, model theft, and data poisoning).
  • Security Consulting: Lead risk management activities, including application risk assessments, design reviews, and mitigation strategies for IT projects.
  • Lifecycle Engagement: Engage throughout the SDLC to identify vulnerabilities, conduct code reviews/penetration testing, and enforce secure coding standards.
  • Program Development: Evangelize AppSec and AI security best practices through developer education, training materials, and outreach.
  • Tooling & Architecture: Design robust security architectures and integrate automated security testing (SAST/DAST/SCA) into CI/CD pipelines.
  • Stakeholder Liaison: Partner with Technology, Trading, Legal, and Compliance to create policies and communicate technical risks to non-technical stakeholders.

Qualifications/Skills Required

  • Bachelor's degree or higher in Computer Science, Computer Engineering, IT Security or related field.
  • 5+ years' experience working as an Application Security Engineer, Software Engineer, or similar role.
  • Deep understanding of AI-specific risks (OWASP Top 10 for LLMs) and experience securing applications utilizing LLMs.
  • Experience working with AI models, Agentic frameworks and security risks associated with AI.
  • Experience in working with global teams, collaborating on code and presentations.
  • Demonstrated work experience in hybrid on-premise and Public Cloud environments (AWS/GCP/Azure).
  • Strong understanding of security architectures, secure configuration principles/coding practices, cryptography fundamentals and encryption protocols.
  • Experience with common SCM & CI/CD technologies like GitHub, Jenkins, Artifactory, etc. and integrating Security Scanning and Vulnerability Management into the CI/CD Pipelines.
  • Familiarity with static and dynamic security analysis tools, and SCA/SBOM solutions.
  • Hands on experience with Secrets Management & Password Vault technologies such as Delinea Secret Server and/or Hashicorp Vault, etc.
  • Strong experience in secure programming in languages such as Python, Java, C++, C#, or similar.
  • Familiarity with Infrastructure as Code tools (CloudFormation, Terraform, Ansible, etc.).
  • Familiarity with web application security testing tools and methodologies.
  • Knowledge of various security frameworks and standards such as ISO 27001, NIST, OWASP, etc.
  • Knowledge of Linux, OS internals and containers is a plus.
  • Certifications like CISSP, CISM, CompTIA Security+, or CEH are advantageous.

Application Security Engineer in London employer: Millennium Management, LLC

Millennium is an exceptional employer for Application Security Engineers, offering a dynamic and collaborative work culture that prioritises security in a complex technical environment. Employees benefit from extensive professional growth opportunities, including hands-on experience with cutting-edge AI security technologies and the chance to shape best practices across the enterprise. With a commitment to fostering innovation and protecting vital information systems, Millennium stands out as a rewarding place to advance your career in application security.

Millennium Management, LLC

Contact Details:

Millennium Management, LLC Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Application Security Engineer in London

Tip Number 1

Network like a pro! Attend industry meetups, webinars, or conferences related to application security. It's a great way to connect with potential employers and show off your passion for the field.

Tip Number 2

Showcase your skills! Create a portfolio that highlights your projects, especially those involving AI security and secure coding practices. This will give you an edge and demonstrate your hands-on experience.

Tip Number 3

Prepare for interviews by brushing up on common application security scenarios and challenges. Be ready to discuss how you've tackled vulnerabilities in past roles, especially in hybrid environments.

Tip Number 4

Don't forget to apply through our website! We love seeing candidates who are genuinely interested in joining our team. Plus, it makes the process smoother for everyone involved.

We think you need these skills to ace Application Security Engineer in London

Application Security
AI Security Strategy
Threat Modeling
Red Teaming
Risk Assessments
Secure Coding Standards
Security Architecture Design

Some tips for your application 🫡

Show Off Your Skills:Make sure to highlight your experience with security technologies and methodologies in your application. We want to see how your background aligns with the role of Application Security Engineer, so don’t hold back on showcasing your expertise!

Tailor Your Application:Take a moment to customise your CV and cover letter for this specific role. We love seeing candidates who understand our needs and can articulate how they can contribute to our AI security strategy and overall mission.

Be Clear and Concise:When writing your application, keep it straightforward and to the point. We appreciate clarity, so make sure your key achievements and experiences are easy to spot. This helps us quickly see why you’d be a great fit!

Apply Through Our Website:We encourage you to submit your application through our website. It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it’s super easy to do!

How to prepare for a job interview at Millennium Management, LLC

Know Your Stuff

Make sure you brush up on your knowledge of AI-specific risks and security methodologies. Be prepared to discuss the OWASP Top 10 for LLMs and how they apply to real-world scenarios. This will show that you’re not just familiar with the theory but can also apply it practically.

Showcase Your Experience

Prepare to share specific examples from your past roles where you’ve successfully implemented security measures or conducted risk assessments. Highlight your experience with CI/CD pipelines and how you've integrated security testing into them. Real-life examples will make your skills more tangible.

Collaborative Spirit

Since the role involves working with various teams, be ready to discuss how you’ve collaborated with non-technical stakeholders in the past. Share instances where you’ve communicated complex security concepts in a way that was easily understood by others. This will demonstrate your ability to bridge the gap between tech and business.

Ask Smart Questions

Prepare insightful questions about the company’s current security practices and future goals, especially regarding AI security strategy. This shows your genuine interest in the role and helps you gauge if the company’s values align with yours. Plus, it gives you a chance to engage in a meaningful conversation.