At a Glance
- Tasks: Lead the engineering build of a cutting-edge application security platform.
- Company: Major financial services organisation focused on innovative security solutions.
- Benefits: Competitive daily rate, flexible work environment, and opportunities for professional growth.
- Other info: Join a dynamic team tackling one of the biggest challenges in security today.
- Why this job: Make a real impact in securing software with AI-driven technology.
- Qualifications: Strong background in software engineering and deep application security expertise required.
Our Client is a major Financial Services Organisation undertaking a major Security Architecture Programme. They are now entering the Production Build Phase of an Agentic Application Security Agent that will fundamentally change how their Application Security is Delivered within the SDLC.
Early Phases of the Programme have already defined the Target Architecture, Threat Model & Prompt Engineering Strategy. The Next Stage is to Transform this Foundation into a Production-Grade Capability Used Daily by Engineering Teams, enabling Developers to:
- Triage Application Security Findings in Real Time
- Receive AI-Assisted Remediation Guidance & Fix Suggestions
- Reduce Cost, Time & Friction Associated with Securing Code at Scale
This is a Hands-On Engineering Leadership role. You will own the End-to-End Technical Implementation & Evolution of the Platform, working closely with Application Security, Platform Engineering, Risk & Compliance Stakeholders.
Responsibilities of Application Security Engineer role will include:
- Agent Engineering & Platform Ownership: Lead the End-to-End Engineering Build of an Agentic Application Security Capability. Own the Codebase, Orchestration Layer & Evaluation Harness. Design & Implement Agent Workflows that Triage Findings, Propose Fixes & Assist Developers within CI/CD Pipelines. Ensure Agent Operates Reliably Across Production Engineering Environments.
- Tooling & Security Integration: Integrate with Enterprise Security Tooling, including: SAST / SCA / DAST, Secret Scanning, Infrastructure-as-Code Security Tools. Embed into Developer Workflows (GitLab / GitHub, CI/CD Pipelines, Ticketing Systems, Identity Platforms). Define Robust Tool Contracts, Retry Logic, Rate Limiting & Failure Handling Mechanisms.
- Prompt, Policy & Guardrail Engineering: Design, Develop, Version & Continuously Improve: System Prompts & Agent Behaviours, Policy Frameworks & Guardrails, Tool Schemas & Execution Constraints. Implement Protections Against: Prompt Injection, Jailbreak Attempts, Unsafe Tool Execution. Ensure Alignment with Defined AASA Threat Model & Governance Standards.
- Evaluation, Metrics & Assurance: Build & Maintain a Full Evaluation Framework, including: Golden Datasets & Regression Test Suites, Precision / Recall Measurement for Vulnerability Detection, Mean-Time-To-Fix Improvements, False Positive Reduction Tracking, Human Override & Intervention Telemetry. Publish Metrics into a Central Security Assurance Scorecard.
- Secure-By-Design Engineering: Embed Secure-By-Design Principles across the Agent Architecture: Least Privilege Execution Model, Scoped Tool Access Controls, Audit Logging & Traceability, Output Validation & Sanitisation, Human-in-the-Loop Control Points. Ensure Compliance with Internal Governance Frameworks (including Agent Safety & AI Security Standards).
- Release Management & Operations: Take the Platform from Prototype to Controlled Pilot & into General Availability. Define & Manage: Service-Level Objectives (SLOs), Observability & Monitoring Model & Behaviour Drift Detection, On-Call & Operational Runbooks, Safe Rollback & Recovery Mechanisms.
- Stakeholder & Cross-Functional Collaboration: Partner closely with: Application Security Teams, Developer Experience / Platform Engineering, CISO / Security Assurance, Legal, Risk & Compliance Functions. Translate Complex Technical Design Decisions into Clear, Actionable Insights for Non-Technical Stakeholders. Balance Security, Usability & Engineering Velocity Trade-Offs.
- Thought Leadership & Architecture Contribution: Contribute to Internal Architecture Artefacts (Blueprints, Reference Architectures, Design Diagrams). Support Development of Enterprise-Wide Agentic AI Security Standards. Where appropriate, contribute to External Thought Leadership.
Essential Skills & Experience for Application Security Engineer role:
- Strong Software Engineering Background (Production-Grade Python and / or TypeScript).
- Experience with Modern Engineering Practices: CI/CD, Testing Frameworks, Code Review Standards.
- Hands-On Experience Building LLM-Powered or Agentic Applications.
- Prior Use of Claude Code or similar Tools to Accelerate Engineering Workflows.
- Deep Application Security Expertise: SAST / SCA / DAST / Secret Scanning, Secure Code Review, Threat Modelling (OWASP Top 10, API Top 10, LLM Security Risks).
- Experience Integrating Security Tooling into Developer Pipelines (GitLab / GitHub, CI/CD).
- Understanding of Prompt Injection, Jailbreak Risks, Sandboxing & Least-Privilege Design.
- Ability to operate effectively in Regulated Environments & Translate Controls into Engineering Solutions.
Ideally Experience would include:
- Delivered AI / Agent Platforms or AppSec Automation Solutions at Scale.
- Familiarity with: Anthropic Claude / Claude Code, MCP or similar Agent / Tool Orchestration Frameworks.
- Experience with AI Security Tooling or AISPM Platforms.
- Exposure to Financial Services Regulatory Environments (eg DORA, FCA/PRA, MAS, JFSA, EU AI Act).
- Knowledge of Secure Development Frameworks (e.g. NIST SSDF, SABSA).
- Experience with AI Red-Teaming & Adversarial Testing.
- Evidence of External Thought Leadership in AppSec or AI Security.
Why This Role is Exciting!!
- Build a Real Production System used at Scale by Engineers - not a Prototype or Slideware.
- Work on one of the Most Important Emerging Challenges in Security: How Agents Safely Build & Secure Software.
- Join a Team that values strong Engineering Discipline, Architecture Clarity & High-Quality Execution.
- Opportunity to Shape How a Major Organisation Approaches AI-Driven Application Security.
SENIOR APPLICATION SECURITY ENGINEER (OUTSIDE IR35) employer: Secure Recruitment LTD
Contact Detail:
Secure Recruitment LTD Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land SENIOR APPLICATION SECURITY ENGINEER (OUTSIDE IR35)
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the industry. Attend meetups, webinars, or even just grab a coffee with someone who’s already in the field. You never know when a casual chat could lead to your next big opportunity.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those related to application security. This gives potential employers a taste of what you can do and sets you apart from the crowd.
✨Tip Number 3
Prepare for interviews like it’s game day! Research the company and its security practices, and be ready to discuss how your experience aligns with their needs. Practise common interview questions and have your own questions ready to show your interest.
✨Tip Number 4
Don’t forget to apply through our website! We’ve got loads of opportunities that might be perfect for you. Plus, applying directly can sometimes give you an edge over other candidates. So, get clicking!
We think you need these skills to ace SENIOR APPLICATION SECURITY ENGINEER (OUTSIDE IR35)
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the role of Senior Application Security Engineer. Highlight your experience with Python, CI/CD, and any hands-on work with AI or agentic applications. We want to see how your skills align with our needs!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about application security and how your background makes you a perfect fit for this role. Let us know what excites you about working with us at StudySmarter.
Showcase Relevant Projects: If you've worked on projects that involve SAST, DAST, or integrating security tooling into developer pipelines, make sure to showcase them. We love seeing real-world examples of your work and how you've tackled challenges in application security.
Apply Through Our Website: We encourage you to apply through our website for a smoother process. It helps us keep track of your application and ensures you don’t miss out on any important updates. Plus, it’s super easy!
How to prepare for a job interview at Secure Recruitment LTD
✨Know Your Stuff
Make sure you brush up on your knowledge of application security, especially around SAST, DAST, and secure coding practices. Be ready to discuss how you've integrated security tooling into CI/CD pipelines in the past.
✨Showcase Your Leadership Skills
Since this is a hands-on engineering leadership role, be prepared to share examples of how you've led projects or teams. Highlight your experience in building production-grade systems and how you’ve managed cross-functional collaboration.
✨Understand the Threat Landscape
Familiarise yourself with the latest threats in application security, including prompt injection and jailbreaking risks. Be ready to discuss how you would implement protections against these threats in a real-world scenario.
✨Ask Insightful Questions
Prepare thoughtful questions about the company's security architecture programme and their approach to AI-driven application security. This shows your genuine interest and helps you gauge if the role aligns with your career goals.