Senior Application Security Engineer in London

Senior Application Security Engineer in London

London Full-Time 63000 - 77000 £ / year (est.) No working from home possible
TripleLift

At a Glance

  • Tasks: Drive secure software development and enhance application security across our innovative ad-tech platform.
  • Company: Join TripleLift, a leading advertising platform committed to innovation and economic inclusion.
  • Benefits: Enjoy competitive salary, flexible PTO, 401k match, and comprehensive health plans.
  • Other info: Be part of a supportive team that values collaboration and continuous learning.
  • Why this job: Make a real impact in the fast-paced ad-tech landscape while building a robust security program.
  • Qualifications: 5+ years in application security with strong coding and security tool experience.

The predicted salary is between 63000 - 77000 £ per year.

About Triple Lift

We're Triple Lift, an advertising platform on a mission to elevate digital advertising through beautiful creative, quality publishers, actionable data and smart targeting.

Through over 1 trillion monthly ad transactions, we help publishers and platforms monetize their businesses.

Our technology is where the world's leading brands find audiences across online video, connected television, display and native ads.

Brand and enterprise customers choose us because of our innovative solutions, premium formats, and supportive experts dedicated to maximizing their performance.

As part of the Vista Equity Partners portfolio, we are NMSDC certified, qualify for diverse spending goals and are committed to economic inclusion.

Find out how Triple Lift raises up the programmatic ecosystem at triplelift. com .

Overview

The Senior Application Security Engineer plays a critical role in driving secure software development and application security maturity within Triple Lift's Engineering and Security organization, directly influencing how we protect our advertising platforms and the trust our publishers and advertisers place in us.

In this position, you will partner closely with Engineering, Platform, Cloud Infrastructure, and Security teams to shape secure coding practices, application security tooling, vulnerability remediation, and CI/CD security, ensuring security is embedded into how we design, build, deploy, and operate our products.

This is an exciting opportunity for someone who wants to build and scale an application security program at a company operating at the center of a rapidly evolving, high-stakes ad-tech landscape, while contributing meaningfully to the long-term security posture and resilience of the organization.

Responsibilities

  • Play a critical role in building and maintaining a global security compliance program based on NIST CSF.
  • Scale application security by developing automated security testing utilizing enterprise SAST, DAST, and code-review tools.
  • Champion SDLC to promote secure application development and infrastructure deployment and facilitate secure coding remediation activities.
  • Automate security testing in CI/CD pipelines to detect vulnerabilities early, including building and maintaining the pipeline integrations themselves.
  • Administer and drive adoption of Git Hub Advanced Security (GHAS) : code scanning, secret scanning, and dependency review across engineering repositories.
  • Participate in threat modeling and design/architecture spec reviews to identify and mitigate security risks early in the SDLC.
  • Coordinate with stakeholders to develop and implement a vulnerability management program and to perform threat-hunting activities.
  • Own and conduct internal penetration testing and vulnerability assessments of applications and infrastructure, and validate findings from third-party pentest engagements.
  • Monitor and respond to application-layer security threats like API abuses, business logic flaws, and common web vulnerabilities.
  • Collaborate with product and engineering teams to ensure security is a key consideration in software design and architecture.
  • Enhance application security posture by working with cross-functional teams to implement proper authentication, authorization, and data protection mechanisms.
  • Enhance and facilitate security incident handling activities.
  • Evangelize security best practices and provide education and awareness to company employees.

Develop and implement secure coding guidelines and conduct secure development training for engineers.

  • Evaluate and continuously improve the maturity of the security program through the deployment and management of various security tools and processes.

Education & Requirements

  • 5+ years of experience in application security, secure software development, security engineering, or a similar role.
  • Strong understanding of secure coding practices and ability to guide developers on remediation strategies.
  • Experience with Git Hub Advanced Security (GHAS), including Code Scanning (SAST), Secret Scanning, and Dependency Review.
  • Proficiency in SAST, DAST, and SCA tools (e. g., Code QL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode).
  • Hands-on experience integrating security testing tools into CI/CD pipelines for automated security scanning, including designing and building pipeline workflows.
  • Hands-on penetration testing / offensive security experience across web applications, APIs, or cloud infrastructure.
  • Knowledge of common application security vulnerabilities and mitigations (OWASP Top 10, CWE, business logic flaws, API security).
  • Ability to perform threat modeling and participate in design/architecture spec reviews to assess security risks in applications and services.
  • Experience conducting security code reviews across various programming languages (e. g., Python, Java, Type Script, Go).
  • Understanding of security fundamentals with relation to various cybersecurity and compliance frameworks, particularly NIST CSF, but any of PCI, SOC2, HITRUST, ISO 27001/2, or similar.
  • Strong understanding of AWS security services and controls (IAM, VPC, KMS, Guard Duty, Cloud Trail) and experience securing cloud-native environments and workloads, with the ability to deploy security tools within them.
  • Takes ownership of projects, works independently with minimal oversight, and delivers results in a fast-paced environment while balancing multiple priorities.
  • Continuously learns, adapts, and values correctness, efficiency, and constructive feedback.

Preferred

  • Experience in the ad-tech / programmatic advertising industry, or another high-scale, real-time environment.
  • Preferred: Familiarity with using AI/LLM-based tools (e. g., Claude or similar) for threat intelligence, alert triage, or security automation.
  • Holds a cybersecurity certification, e. g., OSCP, GWAPT, CISSP, CISA, etc.

US Jobs

The base salary range represents the low and high end of the Triple Lift US salary range for this position.

Actual salaries will vary depending on factors including but not limited to experience and performance.

The range listed is just one component of Triple Lift’s total compensation package for employees.

Other rewards may include bonuses, an open Paid Time Off policy, and many region-specific benefits.

Pay is based on various non-discriminatory factors including but not limited to experience, education, and skills.

Benefits Available to Eligible Employees Include the following*

  • Medical, Dental & Vision Plans
  • Flexible PTO
  • 401k w/ employer match

*Full-time employees are eligible for comprehensive benefits (subject to the terms of applicable plans/policies/agreements, which will be made available to you after commencing employment).

  • Salary range transparency
  • $125,000
  • $165,000
  • USD
  • Life at Triple Lift

At Triple Lift, we’re a team of great people who like who they work with and want to make everyone around them better.

This means being positive, collaborative, and compassionate.

We hustle harder than the competition and are continuously innovating.

Learn more about Triple Lift and our culture by visiting our

Linked In Life page.

Establishing People, Culture and Community Initiatives

At Triple Lift, we are committed to building a culture where people feel connected, supported, and empowered to do their best work.

We invest in our people and foster a workplace that encourages curiosity, celebrates shared values, and promotes meaningful connections across teams and communities.

We want to ensure the best talent of every background, viewpoint, and experience has an opportunity to be hired, belong, and develop at Triple Lift.

Through our People, Culture, and Community initiatives, we aim to create an environment where everyone can thrive and feel a true sense of belonging.

  • Privacy Policy
  • Please see our Privacy Policies on our
  • Triple Lift and

1plus X websites.

Triple Lift does not accept unsolicited resumes from any type of recruitment search firm.

Any resume submitted in the absence of a signed agreement will become the property of Triple Lift and no fee shall be due.

Senior Application Security Engineer in London employer: TripleLift

TripleLift is an exceptional employer that prioritises a positive and collaborative work culture, where employees are empowered to innovate and grow. With comprehensive benefits including flexible PTO and a 401k plan with employer match, we invest in our team's well-being and professional development. Located at the heart of the ad-tech landscape, this role offers the unique opportunity to shape application security practices while contributing to a mission-driven company committed to economic inclusion and diversity.

TripleLift

Contact Details:

TripleLift Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior Application Security Engineer in London

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including TripleLift, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through TripleLift

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at TripleLift. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Senior Application Security Engineer in London

Application Security
Secure Software Development
Security Engineering
GitHub Advanced Security (GHAS)
SAST Tools
DAST Tools
CI/CD Pipeline Integration

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at TripleLift insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to TripleLift that you’re committed to staying ahead in the game.

How to prepare for a job interview at TripleLift

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at TripleLift to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at TripleLift.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.