Senior Application Security Engineer in London
Senior Application Security Engineer

Senior Application Security Engineer in London

London Full-Time 70000 - 90000 £ / year (est.) No home office possible
Prolific

At a Glance

  • Tasks: Secure applications by testing, reviewing code, and embedding security practices.
  • Company: Prolific, a leader in AI development and human data infrastructure.
  • Benefits: Competitive salary, remote work, and a mission-driven culture.
  • Other info: Collaborative environment with opportunities for groundbreaking research.
  • Why this job: Join us at the forefront of AI innovation and make a real impact.
  • Qualifications: Experience in application security and strong knowledge of modern attack paths.

The predicted salary is between 70000 - 90000 £ per year.

Prolific is not just another player in the AI space – we are the architects of the human data infrastructure that's reshaping the landscape of AI development. In a world where foundational AI technologies are increasingly commoditized, it's the quality and diversity of human-generated data that truly differentiates products and models. The role Security at Prolific isn't an afterthought, it's foundational to how we build. As a company trusted by world‑leading research institutions and AI labs to handle sensitive data at scale, the security of our application layer is critical. We handle participant data, researcher credentials, payment flows, and API integrations that demand rigorous protection at the code level.

As a Senior Application Security Engineer, you'll be the technical authority on application security at Prolific. You'll work hands‑on with our engineering teams to find and fix vulnerabilities in our codebase, perform security testing, build security tooling, and embed secure development practices into how we ship software. This isn't a governance or policy role, you'll be in the code, reviewing pull requests, threat modelling new features, and building the automation that keeps our platform secure as we scale. You'll report to the Head of Engineering/Platform and work cross‑functionally with product engineering, platform, data, and TechOps teams.

What you'll bring to the role:

  • Several years in application/product security or security engineering
  • Strong knowledge of OWASP Top 10 (Web & API) and modern attack paths (e.g. auth flaws, SSRF, injection, business logic abuse, supply chain)
  • Experience working with complex, large‑scale systems and modern architectures
  • Hands‑on security testing experience (especially Burp Suite) across web apps and APIs
  • Python for security tooling, automation, or custom detection (Django a plus)
  • Experience implementing and tuning SAST, SCA, DAST, and secret scanning in CI/CD
  • Practical threat modelling experience, including leading lightweight sessions
  • Strong collaboration skills, able to clearly explain issues and drive remediation
  • Builder mindset, you automate wherever possible

Nice to haves:

  • Experience with Django, Vue.js, MongoDB, GCP
  • Security champions or bug bounty programmes
  • Supply chain security (SCA, SBOMs, dependency review)
  • IaC security (e.g. Terraform, policy‑as‑code)
  • Experience in scaling environments building out security practices

What you'll be doing in the role:

You'll help secure Prolific's applications end‑to‑end, from hands‑on testing and code review to threat modelling and CI/CD security. You'll partner closely with engineers to identify and fix vulnerabilities, build and tune security tooling, and embed secure development practices across the SDLC. This includes running penetration tests, improving detection coverage, and staying ahead of emerging threats to continuously strengthen our security posture.

Why Prolific is a great place to work:

We've built a unique platform that connects researchers and companies with a global pool of participants, enabling the collection of high‑quality, ethically sourced human behavioural data and feedback. This data is the cornerstone of developing more accurate, nuanced, and aligned AI systems. We believe that the next leap in AI capabilities won't come solely from scaling existing models, but from integrating diverse human perspectives and behaviours into AI development. By providing this crucial human data infrastructure, Prolific is positioning itself at the forefront of the next wave of AI innovation – one that reflects the breadth and the best of humanity. Working for us will place you at the forefront of AI innovation, providing access to our unique human data platform and opportunities for groundbreaking research. Join us to enjoy a competitive salary, benefits, and remote working within our impactful, mission‑driven culture.

Senior Application Security Engineer in London employer: Prolific

Prolific is an exceptional employer, offering a unique opportunity to work at the forefront of AI innovation while ensuring the security of sensitive data. With a mission-driven culture that values collaboration and creativity, employees benefit from competitive salaries, remote working options, and ample opportunities for professional growth in a dynamic environment. Join us to be part of a team that is reshaping the landscape of AI development through ethically sourced human behavioural data.
Prolific

Contact Detail:

Prolific Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Senior Application Security Engineer in London

✨Tip Number 1

Network like a pro! Reach out to folks in the industry, especially those at Prolific. A friendly chat can open doors and give you insights that a job description just can't.

✨Tip Number 2

Show off your skills! If you've got a portfolio or GitHub with security projects, flaunt it. Demonstrating your hands-on experience with tools like Burp Suite can really set you apart.

✨Tip Number 3

Prepare for technical interviews by brushing up on OWASP Top 10 and modern attack paths. Be ready to discuss how you've tackled vulnerabilities in the past – real-world examples go a long way!

✨Tip Number 4

Apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you're genuinely interested in being part of the Prolific team.

We think you need these skills to ace Senior Application Security Engineer in London

Application Security
OWASP Top 10
Security Testing
Burp Suite
Python
Django
SAST
SCA
DAST
Secret Scanning
Threat Modelling
Collaboration Skills
Automation
CI/CD Security
Penetration Testing

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience in application security. We want to see how your skills align with the specific requirements mentioned in the job description, so don’t hold back!

Show Off Your Technical Skills: When detailing your experience, be sure to mention your hands-on skills with tools like Burp Suite and any programming languages you’re comfortable with, especially Python. We love seeing practical examples of how you've tackled security challenges.

Be Clear and Concise: Keep your application straightforward and to the point. Use bullet points where possible to make it easy for us to see your key achievements and relevant experience. We appreciate clarity!

Apply Through Our Website: We encourage you to submit your application directly through our website. It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it’s super easy!

How to prepare for a job interview at Prolific

✨Know Your OWASP

Make sure you brush up on the OWASP Top 10 vulnerabilities, especially those relevant to web and API security. Be ready to discuss how you've tackled these issues in past projects, as this will show your hands-on experience and understanding of application security.

✨Show Off Your Hands-On Skills

Prepare to demonstrate your practical skills with tools like Burp Suite. You might be asked to walk through a security testing scenario or even perform a live demo, so practice your approach to identifying and fixing vulnerabilities in real-time.

✨Talk About Collaboration

Since you'll be working closely with engineering teams, be ready to share examples of how you've successfully collaborated in the past. Highlight your ability to explain complex security issues in simple terms and how you've driven remediation efforts effectively.

✨Emphasise Your Builder Mindset

Prolific values a builder mindset, so come prepared to discuss how you've automated security processes in previous roles. Share specific examples of security tooling you've developed or improved, and how that has enhanced the overall security posture of your projects.

Senior Application Security Engineer in London
Prolific
Location: London

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>