At a Glance
- Tasks: Embed security expertise in software development, shaping security practices across product teams.
- Company: Redgate, a collaborative tech company focused on AI and cloud-native solutions.
- Benefits: Competitive salary, hybrid working, wellbeing allowance, and generous paid time off.
- Other info: Join a diverse team that values trust, fairness, and continuous learning.
- Why this job: Make a real impact on security in innovative projects and work with cutting-edge technologies.
- Qualifications: Hands-on experience in application security and strong coding communication skills.
The predicted salary is between 60000 - 75000 £ per year.
Location: Cambridge
In-office expectation: Flexible hybrid, once in the office every two weeks
Employment type: Permanent
Salary: £60,000 to £75,000, subject to experience
Why This Role Exists
Redgate's product teams move fast, across a growing set of AI and cloud-native technologies, and security can't just be a gate at the end of that process. This role exists to embed security expertise directly into how our engineering teams build and ship software: setting the standards, running the threat modelling, and making the judgement calls that keep pace with delivery instead of slowing it down.
About Redgate
Redgate brings together people who want to do their best work in an environment built on trust, accountability, and collaboration. We build solutions that help data professionals securely manage the data and databases their organisations depend on, a space that's only becoming more critical as systems scale, data regulations increase, and AI adoption accelerates.
AI at Redgate
By 2028, Redgate will operate as an expert-plus-agent company: domain experts amplified by AI, delivering customer value at a pace our peers can't match. AI handles the heavy lifting, our people control the judgement. Everyone at Redgate works with Claude, giving you access to the best AI tools from day one.
Why Join Our Product Security Team
You’ll shape how security works across multiple product teams, rather than enforcing policy from the sidelines. There's real scope to specialise in emerging areas like AI security, work most security roles don't get exposure to yet. We value pragmatic, real risk reduction over checkbox compliance, so the judgement you bring carries genuine weight.
About the Role
This role sits within our Product Security function, embedded across multiple product and engineering teams rather than a single one. You'll define and operationalise security requirements throughout the SDLC, from initial design through to release, with real authority to make independent security calls rather than deferring to what a scanner tells you. It's a role built on trust: teams will come to you for guidance, and the judgement you bring to triage, threat modelling, and governance decisions will shape how security actually gets done here.
- Partner directly with engineering and product teams to define and operationalise security requirements across the full SDLC
- Own or co-own application security governance: secure-by-default standards, patterns, guardrails, and risk exceptions
- Lead threat modelling for new features and architectural changes, turning findings into practical engineering work
- Drive SAST/DAST adoption and quality, from tool tuning to severity calibration and developer-facing triage guidance
- Support product teams adopting AI, including LLMs, SLMs, and MCP, giving you visibility into work most security roles wouldn't touch
What Makes You a Great Fit
- Hands-on product or application security experience, embedding security practices across a modern software development lifecycle
- Ability to review code and communicate security issues clearly to developers, primarily within a C# ecosystem, with exposure to Java or Python
- Strong knowledge of the OWASP Top 10 and practical mitigation patterns
- Experience implementing or improving SAST/DAST processes: tool tuning, triage workflows, and reducing signal to noise
- Working understanding of cloud and container security fundamentals, ideally with AWS and Docker
What We Offer
- Salary range: £60,000 to £75,000, subject to experience
- Hybrid working: home and Cambridge office
- Monthly wellbeing allowance and generous paid time off
- Genuine investment in learning, development, and career progression
- Private health insurance
Belonging at Redgate
We believe that people do their best work in an environment built on respect, fairness, and trust, and that diverse perspectives lead to better outcomes. Redgate is an equal opportunity employer, and we make hiring decisions based on skill, potential, and alignment with our values.
Senior Application Security Engineer in Cambridge employer: red-gate
Redgate is an exceptional employer located in the vibrant city of Cambridge, offering a dynamic work culture that prioritises innovation and collaboration. Employees benefit from a strong focus on professional growth, with opportunities to lead impactful security initiatives in AI and cloud technologies, all while enjoying a supportive environment that values work-life balance and employee well-being.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Application Security Engineer in Cambridge
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including red-gate, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through red-gate
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at red-gate. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Senior Application Security Engineer in Cambridge
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at red-gate insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to red-gate that you’re committed to staying ahead in the game.
How to prepare for a job interview at red-gate
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at red-gate to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at red-gate.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.