Application Security Engineer

Application Security Engineer

Full-Time 60000 - 80000 £ / year (est.) No working from home possible
P

At a Glance

  • Tasks: Design and implement security controls to protect applications and data from cyber threats.
  • Company: Join a dynamic team at The Pokémon Company, where innovation meets impact.
  • Benefits: Enjoy competitive pay, 100% employer-paid healthcare, and generous family leave.
  • Other info: Flexible hybrid work environment with great career growth opportunities.
  • Why this job: Make a real difference in cybersecurity while working with cutting-edge technologies.
  • Qualifications: 5-7 years in cloud security, strong communication skills, and a passion for tech.

The predicted salary is between 60000 - 80000 £ per year.

Designs, implements, and operates security controls to prevent and detect attacks against company systems, applications, and data.

Conducts penetration testing and vulnerability assessments across applications, operating systems, and networks.

Responds to cybersecurity incidents by identifying, isolating, and removing unauthorized access.

Researches emerging threats, performs root cause analysis, and supports the development of security solutions.

Communicates business impact related to data loss, system disruption, or unauthorized access.

Responsibilities

  • Administer and enforce security policies governing system and application access.
  • Perform application security testing and reviews to ensure secure configurations and compliance with standards.
  • Conduct penetration tests and vulnerability assessments across applications, OS, and network layers.
  • Lead threat modeling and security design reviews for new technologies and system changes.
  • Respond to security incidents, isolating threats and removing unauthorized access.
  • Research emerging cybersecurity threats and conduct root cause analysis on issues.
  • Implement technical controls to reduce cloud-based risks, including drift, private‑cloud gaps, and web‑facing vulnerabilities.
  • Collaborate with Information Security partners to advance roadmaps and shared initiatives.
  • Integrate security testing and controls into development lifecycle phases.
  • Provide management with insights on business impact related to data compromise or system unavailability.
  • Work within an agile framework to deliver iterative improvements toward team and organizational goals.
  • Respond and investigate cybersecurity incidents, which may be off‑hours and on a scheduled rotation.

Qualifications

  • 5–7 years of relevant experience securing cloud environments, primarily AWS, or equivalent expertise.
  • Bachelor’s degree in a related field or equivalent practical experience.
  • Strong time management, organizational skills, and attention to detail.
  • Solid background in application security engineering and architecture, including MWAF and software development.
  • Demonstrated ability to build partnerships and collaborate with cross‑functional teams.
  • Strong communication skills, with the ability to clearly present security risks to senior leadership.
  • Experience managing security vendors and managed service providers.
  • Proven background in incident management and response.
  • Security certifications (CISSP, GIAC, CISA, etc.) are a plus.
  • Salary Range

For this role, new hires generally start between £59,829.00 – £79,604.00 per year. The full range is £59,829.00 – £107,759.00 per year.

Benefits

  • An innovative culture driven by impact, delivering meaningful outcomes.
  • Company events that celebrate the spirit of Pokémon.
  • Competitive cash‑based compensation programs.
  • 100% employer‑paid healthcare premiums.
  • Generous paid family leave.
  • Employer‑paid life insurance.
  • Employer‑paid long and short‑term income protection insurance.
  • US Employees: 401k Employer Matching.
  • UK/IRE/MX Employees: Pension Employer Contributions.
  • Fitness reimbursement.
  • Commuter benefit.
  • Linked In learning.
  • Comprehensive relocation package for certain roles.
  • Hybrid work environment.

EEO Statement

The above statements are intended to describe the general nature and level of work being performed by people assigned to this role.

They are not to be construed as an exhaustive list of all responsibilities, duties, and skills required.

Employees may be required to perform duties outside of their normal responsibilities from time to time, as needed.

For roles in the United Kingdom, candidates will need the right to work.

In some cases, and for some roles, the Company may be able to arrange a visa.

For roles in Ireland, this role requires candidates to have the right to live and work in the Republic of Ireland.

However, we welcome applications from all nationalities and may consider supporting an employment permit application, in appropriate and suitable cases.

The Pokémon Company International is committed to the inclusion of all qualified applicants for consideration in our job application process.

If you require reasonable accommodation to complete a job application, pre‑employment testing, or a job interview, or to otherwise participate in the hiring process, please contact the Talent Acquisition team at accommodationrequest_ta@pokemon. com.

#J-18808-Ljbffr

Application Security Engineer employer: Pokemoncareers

The Pokémon Company International is an exceptional employer, offering a vibrant work culture that celebrates creativity and passion for the iconic Pokémon brand. Employees enjoy a collaborative environment with ample opportunities for professional growth, as well as the unique advantage of working in a globally recognised company that values innovation and quality in every product. Located in a dynamic area, this role as a Brand Services Specialist allows you to immerse yourself in the world of Pokémon while contributing to its legacy in fashion and home products.

P

Contact Details:

Pokemoncareers Recruitment Team

We think you need these skills to ace Application Security Engineer

Application Security Engineering
Penetration Testing
Vulnerability Assessments
Incident Management
Root Cause Analysis
Cloud Security (AWS)
Security Policy Administration