Application Security Manager

Application Security Manager

Full-Time 36000 - 60000 £ / year (est.) No working from home possible
Unily

At a Glance

  • Tasks: Lead application security initiatives and ensure secure software development practices.
  • Company: Join Unily, a leader in Employee Experience platforms with a vibrant team culture.
  • Benefits: Enjoy a competitive salary, flexible working, and a suite of fantastic benefits.
  • Other info: Be part of a diverse team committed to sustainability and community engagement.
  • Why this job: Make a real impact on security in a fast-paced tech environment.
  • Qualifications: Experience in application security and knowledge of secure development practices required.

The predicted salary is between 36000 - 60000 £ per year.

Unily partners with the world’s largest and most complex enterprises to power Organizational Velocity through digital Employee Experience transformation. Iconic brands, including Estée Lauder Companies, CVS Health, and British Airways, use Unily’s market-leading Employee Experience platform to improve productivity, streamline communication, and foster a highly connected workplace.

As we continue to expand our market share in the rapidly emerging Employee Experience platform category, we are looking for an Application Security Manager. This role is responsible for building and executing a comprehensive application security programme that combines strategic oversight with hands-on technical execution. The Application Security Manager ensures that security is embedded throughout the software development lifecycle (SDLC), enabling Unily to deliver secure products at speed.

Main Responsibilities:

  • Define and maintain secure development policies and privacy by design requirements
  • Own the risk acceptance and escalation process, maintaining the risk register
  • Develop and measure the application security strategy leveraging frameworks such as OWASP SAMM
  • Support RFPs and sales responses on application security matters
  • Lead and coordinate external penetration testing engagements and remediation follow up
  • Drive risk-based prioritisation, assigning and validating CVSS scores
  • Deliver and manage secure development training programs
  • Conduct and facilitate threat modelling and architecture and design security reviews
  • Perform or coordinate application security testing
  • Generate and manage software bills of materials (SBOMs) to manage supply chain risks
  • Ensure build verification and oversee IaC and container/Kubernetes scanning within pipelines
  • Provide guidance on secure cloud-native architectures
  • Evaluate and apply security testing tools and techniques (e.g. Burpsuite, fuzzing, IaC scanners, Static Analysers)
  • Contribute to security metrics, reports and dashboards
  • Collaborate with engineering, operations and product teams to embed security best practices throughout the whole SDLC

Requirements:

  • Proven experience in application security
  • Strong knowledge of secure software development practices, DevSecOps and CI/CD security integration
  • Hands-on experience with application security testing tools and techniques (e.g. SAST, DAST, Dependency checkers, IaC scanners, secret detection, container security tools)
  • Understanding of threat modelling, architecture and design reviews and offensive security principles
  • Familiarity with compliance and regulatory frameworks
  • Experience with risk acceptance processes, CVSS scoring and vulnerability management
  • Experience managing external penetration testing vendors
  • Familiarity with SBOMs and software supply chain security
  • Strong background in cloud and container security
  • Ability to communicate with technical and non-technical stakeholders
  • Knowledge of data privacy regulations and GDPR, and how they intersect with application security
  • Certifications such as CISSP, CSSLP, OSWE, OSCP or equivalents
  • Degree in computer science, cyber security, related fields or equivalent experience

We are united by a shared purpose and are committed to truly understanding each other. We know that everyone is unique and has their own story. We strive to have a diverse workforce that embraces and celebrates one another. We are united in building connections and curious to learn from each other so that we continue to grow together to build the workplace of tomorrow.

Why Work For Unily?

  • Our awesome team culture. We are focused on achieving results as a team and having fun while we do it.
  • Our industry leading product. We are very proud of our ever-evolving product, naturally we use (and love) it internally and provide the tools and resources for you (and our clients) to become a Unily expert.
  • The flexibility that we offer. We operate on a hybrid basis, and also recognize that life happens during the 9-5.30 and encourage a sustainable work/life balance.
  • Our bright and modern office spaces. When you need to be in the office we want it to be like being at home.
  • We offer a fantastic suite of benefits. Including 25 days holiday plus an extra paid day off to enjoy your birthday, Vitality life cover, Aviva pension, life assurance, income protection and more.
  • Our commitment to sustainability and giving back to the community.

Application Security Manager employer: Unily

Unily is an exceptional employer that fosters a vibrant team culture, prioritising collaboration and enjoyment in achieving results. With a commitment to employee well-being, we offer flexible working arrangements, modern office spaces, and a comprehensive benefits package, including generous holiday allowances and health coverage. Our focus on personal growth and sustainability makes Unily a rewarding place to build a meaningful career in the rapidly evolving Employee Experience sector.

Unily

Contact Details:

Unily Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Application Security Manager

Tip Number 1

Network like a pro! Reach out to people in your industry on LinkedIn or at events. A friendly chat can lead to opportunities that aren’t even advertised yet.

Tip Number 2

Prepare for interviews by researching the company and its culture. Show them you’re not just another candidate; you’re genuinely excited about what they do!

Tip Number 3

Practice your responses to common interview questions, but keep it natural. We want you to sound confident, not rehearsed. Be yourself and let your passion shine through!

Tip Number 4

Don’t forget to follow up after your interview! A quick thank-you email can leave a lasting impression and show that you’re really interested in the role.

We think you need these skills to ace Application Security Manager

Application Security
Secure Software Development Practices
DevSecOps
CI/CD Security Integration
Application Security Testing Tools
Threat Modelling
Architecture and Design Security Reviews

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter for the Application Security Manager role. Highlight your experience with secure software development practices and any relevant certifications. We want to see how your skills align with what we're looking for!

Showcase Your Technical Skills:Don’t hold back on detailing your hands-on experience with application security testing tools and techniques. Mention specific tools you've used, like SAST or DAST, and how you've applied them in real-world scenarios. This will help us understand your technical prowess.

Communicate Clearly:When writing your application, keep it clear and concise. Use straightforward language to explain your experience and achievements. Remember, we value communication skills just as much as technical expertise, so make sure your passion for security shines through!

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, it shows us that you're genuinely interested in joining our team at Unily!

How to prepare for a job interview at Unily

Know Your Stuff

Make sure you brush up on your application security knowledge, especially around secure software development practices and tools like SAST and DAST. Be ready to discuss how you've applied these in past roles, as this will show you're not just familiar with the theory but have hands-on experience.

Showcase Your Strategic Mindset

Unily is looking for someone who can blend technical skills with strategic oversight. Prepare examples of how you've defined and enforced secure development policies or managed risk acceptance processes. This will demonstrate your ability to think both tactically and strategically.

Engage with Real Scenarios

Be prepared to discuss real-world scenarios where you've conducted threat modelling or application security testing. Use specific examples to illustrate your problem-solving skills and how you’ve collaborated with engineering teams to embed security best practices throughout the SDLC.

Communicate Clearly

You’ll need to communicate with both technical and non-technical stakeholders, so practice explaining complex concepts in simple terms. Think about how you would explain a security issue to someone without a tech background, as this will be crucial in your role at Unily.