At a Glance
- Tasks: Lead and enhance application security for innovative AI technology in self-driving cars.
- Company: Wayve, a pioneering company in Embodied AI technology with a focus on diversity.
- Benefits: Hybrid working policy, competitive salary, and opportunities for professional growth.
- Other info: Join a dynamic team dedicated to innovation and continuous improvement in application security.
- Why this job: Make a real impact on the future of automated driving while fostering an inclusive culture.
- Qualifications: Experience in software or security engineering, with strong application security knowledge.
The predicted salary is between 63000 - 77000 £ per year.
At Wayve we're committed to creating a diverse, fair and respectful culture that is inclusive of everyone based on their unique skills and perspectives. Founded in 2017, Wayve is the leading developer of Embodied AI technology. Our advanced AI software and foundation models enable vehicles to perceive, understand, and navigate any complex environment, enhancing the usability and safety of automated driving systems.
As Application Security Lead at Wayve, you’ll define, build, and lead our application security (AppSec) programme. You will be accountable for assessing and improving the security of our internal and external applications, partnering with engineering teams, and shaping the controls, testing processes, and guidance that protect the software used by our scientists, OEM partners, and internal developers.
This is an individual contributor role initially, with scope to build and lead a dedicated application security team as Wayve’s needs evolve. You’ll define processes, own the fitness-for-purpose and effective use of Wayve’s AppSec tooling, and be accountable for the lifecycle of application security across the company. This includes driving secure development guidance with engineering teams, managing and scoping a schedule of application security testing, and ensuring Wayve can proactively surface, prioritise, and remediate application security risks.
The role is advisory in nature, focused on enabling engineering teams to build secure software through guidance, challenge, and partnership rather than direct feature delivery.
- Application Security Assessment & Review: Define, lead, and mature application-focused security reviews, respond to security concerns raised by staff or partners, and identify risks across internal and external applications used by our scientists, developers, and customers.
- Application Security Incident Response: Lead response activities for application-centric security incidents.
- Vulnerability Oversight & Testing Management: Own the scheduling, scoping, and coordination of application security testing, ensuring tests are well designed, executed, and effectively communicated. Provide practical, actionable guidance to improve the security of new and existing applications.
- Application Security Intelligence & Proactive Analysis: Integrate threat intelligence into assessments and proactively surface patterns, misconfigurations, or weaknesses that could lead to compromise.
- Define and deliver the roadmap for scaling and continuously improving Wayve’s application security capability across people, processes, and tools, proactively identifying gaps and inefficiencies in the existing application security toolchain and driving improvement or replacement plans aligned to Wayve’s risk profile and engineering practices.
- Evaluate and select AppSec tooling, leading its adoption and partnering with DevOps and engineering teams on implementation and operation, and collaborating with vendors to ensure comprehensive visibility and coverage across our application portfolio.
In order to set you up for success as Application Security Lead at Wayve, we’re looking for the following skills and experience:
- Previous experience as a software engineer or security engineer working directly with application code, sufficient to review code, understand design trade-offs, and provide credible, practical security guidance to developers.
- Proven experience in application security, secure development practices, and vulnerability management across cloud-based and internal application environments.
- Led or played a key role in addressing a significant application security incident or critical vulnerability.
- Strong working knowledge of application security frameworks and methodologies.
- Hands-on experience with application security tooling (e.g. SAST/DAST/IAST, dependency scanning, SCA, secrets detection) as well as manual review techniques.
- Experience scoping, managing, and interpreting third-party application security testing or penetration testing engagements.
- Ability to make sound, risk-based decisions independently in time-sensitive situations.
- Bachelor’s degree (or equivalent) in a relevant discipline, demonstrating strong analytical, problem-solving, and communication skills.
- Experience building or scaling an application security programme or secure development capability.
- Familiarity with safety-critical, automotive, or operational software environments.
- Relevant application security certifications.
This is a full-time role based in our offices in London or Sunnyvale. At Wayve we want the best of all worlds so we operate a hybrid working policy that combines time together in our offices and workshops to fuel innovation, culture, relationships and learning, and time spent working from home. If you require any accommodations or adjustments to participate fully in our interview process, please let us know.
If you’re passionate about self-driving cars and think you have what it takes to make a positive impact on the world, we encourage you to apply.
Senior Data Management Team Lead in London employer: Wayve
Wayve is an exceptional employer that fosters a dynamic and innovative work culture, where software engineers can thrive while contributing to cutting-edge AI solutions. With a strong emphasis on employee growth, Wayve offers opportunities for professional development and collaboration in a hybrid work environment, allowing for flexibility and work-life balance. Located in a vibrant tech hub, employees benefit from a supportive community and access to industry-leading resources.