About the Role
We are seeking a Senior Application Security Engineer to join our Information Security team. This hands-on role focuses on integrating security throughout the Software Development Lifecycle (SDLC) and CI/CD pipelines within a modern, cloud-native environment. You will partner with engineering teams to build secure applications and influence security processes, tooling, and culture.
Responsibilities
- Partner with development teams across architecture, engineering, and cloud to embed security into code, applications, Kubernetes, and containerized workloads.
- Promote a shift-left approach and secure engineering practices.
- Implement and operate code scanning tools (SAST, DAST, IAST, SCA) to help developers identify and remediate vulnerabilities.
- Mature the Secure Development Lifecycle by embedding security into CI/CD pipelines (GitHub Actions) and strengthening development tooling.
- Advise on securing APIs and other high-risk system components.
- Assist with securing Data Platforms including Databricks, Dagster, Snowflake, and the broader cloud environment.
- Develop security policy as code using OPA or similar and drive adoption across teams.
- Document security processes and low-level designs for security tools and services.
- Contribute to security service documentation for consistent delivery and operations.
- Assist teams integrating with security tooling and ensure smooth onboarding to security services.
- Support wider security initiatives including ISO 27001 activities and threat modeling.
Requirements
- Proficient in writing Terraform, Python, and ideally KQL.
- Significant hands-on experience implementing and operating code scanners (SAST, DAST, IAST, SCA).
- Experience automating security capabilities and delivering security or policy as code using tools like OPA or Azure Policy.
- Experience securing GitHub and GitHub Actions, or similar CI/CD platforms.
- Experience securing Kubernetes (ideally AKS) and broader container security.
- Experience securing APIs and other exposed components.
- Experience working directly with software engineering best practices including source control, unit testing, code reviews, design documentation, and strong debugging/troubleshooting.
- Experience in threat modeling within engineering teams.
- Exposure to Agile working and DevSecOps.
- Knowledge of ISO 27001 and its relevance to secure engineering.
- Desire to be part of a small, fast-paced team with a collaborative mindset.
- Relevant certifications such as Microsoft MS-500, AZ-500, AZ-700, SC-200, CompTIA Security+ or Cloud+, CSA CCSK, ISC2 CSSLP, GIAC GWAPT or EC-Council CASE.
Skills
- Terraform
- Python
- KQL
- SAST
- DAST
- IAST
- SCA
- OPA
- Azure Policy
- GitHub Actions
- Kubernetes
- AKS
- Container Security
- API Security
- Databricks
- Dagster
- Snowflake
- Source Control
- Unit Testing
- Code Reviews
- Design Documentation
- Debugging
- Troubleshooting
- Threat Modeling
- Agile
- DevSecOps
- ISO 27001
Location
- Central London (Holborn)
- Remote
Work Type
- Flexible
- Remote
Experience Level
- Senior
Education Level
- Relevant certifications
Salary/Compensations
- £70,000 per annum
Benefits
- Generous Pension Scheme (up to 12% employer contribution)
- 30 Days Holiday + Bank Holidays
- Enhanced Parental Leave
- Cycle to Work Scheme
- Home & Tech Savings
- £1,000 Employee Referral Bonus
- Wellbeing Support (Mental Health First Aiders, 24/7 online GP, Employee Assistance Programme)
About the Company
- Our Future Health's mission is to transform the prevention, detection, and treatment of conditions such as dementia, cancer, diabetes, heart disease, and stroke.
- We are building a modern, cloud-native environment where squads genuinely care about secure engineering.
- We are looking for people to join us on our journey to help future generations live in good health for longer.
Equal Opportunity
- We recognise the importance of having a diverse workforce and ensuring that all candidates, regardless of their background, have equitable access to our application process.
- We proactively encourage applicants who identify as having a disability, neurodiversity, or long-term health conditions to let us know if they require any reasonable adjustments as part of their application process.
- If you do require any reasonable adjustments, please email us at talent@ourfuturehealth.org.uk
