About the Role
As an Application Security Engineer, you will act as a core technical guide across the software development lifecycle, embedding security into code and architecture while exploring next-generation defensive strategies like AI/LLM threat modeling. You will partner closely with engineering teams to demystify complex threats, modernize DevSecOps practices, and mentor developers to build resilient systems.
Responsibilities
- Provide expert guidance on secure coding, threat modelling, and OWASP Top 10 mitigation.
- Promote a security-first mindset across development teams, acting as a supportive technical mentor.
- Integrate security assessments, code reviews, and penetration testing seamlessly into the SDLC.
- Evaluate, implement, and run modern security tooling (SAST, DAST, IAST) to streamline vulnerability checks.
- Research emerging AI and LLM threat classes to design proactive, cutting-edge defensive architectures.
- Participate in incident response investigations and help deliver engaging security training.
Requirements
- Experienced in application security (5+ years) with strong hands-on penetration testing and security tooling skills.
- Deeply knowledgeable about web vulnerabilities, secure coding practices, and cloud environments (AWS, Azure, or GCP).
- Familiar with DevSecOps methodologies and automated security integration.
- An open, clear communicator who can explain complex security concepts in plain English to both technical and non-technical teammates.
- Highly collaborative, empathetic, and passionate about mentoring engineers rather than just checking compliance boxes.
- Curious, proactive, and keen to stay ahead of modern threat landscapes like AI security.
Skills
- Penetration testing
- Security tooling
- Web vulnerabilities
- Secure coding practices
- Cloud environments (AWS, Azure, or GCP)
- DevSecOps methodologies
- Automated security integration
- AI/LLM threat modeling
- SAST
- DAST
- IAST
Location
- Hybrid
Work Type
- Permanent
- Full-time
Experience Level
- 5+ years
Salary/Compensations
- Competitive salary based on experience and market
- Potential to earn an annual bonus based on performance
Benefits
- Great work-life balance
- Flexible hybrid work
- 25 days annual leave plus bank holidays
- Option to buy five additional days of holiday
- Flexible parental leave (six months full pay for primary caregiver, four weeks full pay for secondary caregiver)
- Life event leave (an extra day off every two years for significant life events)
- Paid sabbatical (two weeks after five years, four weeks after ten years)
- Private medical insurance through BUPA (covers pre-existing conditions)
- Health cash plan for everyday medical expenses
- Access to tools for personal development on a dedicated learning platform
- Support for mental health with access to counselling
- Pension matching up to five percent
- Life assurance policy (four times basic salary, option to increase to ten times)
- Salary sacrifice car scheme
- Flexible benefits scheme (allocated amount for critical illness cover, dental insurance, travel insurance, gym membership, etc.)
About the Company
- Insures small businesses and enables big dreams.
- Protects over 1,000,000 active insurance policies for various trades.
- A technology company that builds, fails, learns, and improves.
- Global social impact strategy, 'The Big Dreams Project', aims to help 10,000 small businesses start or grow by 2030.
Equal Opportunity
- Committed to providing equality and opportunities for all employees and candidates.
- Offers a workplace where colleagues are treated with respect and dignity.
- Does not discriminate directly or indirectly on the grounds of race, colour, religion, belief, political opinion, disability, nationality, ethnic origin, sex, sexual orientation or relationship status.
