Application Security Engineer at Simply Business | GB | Rezi

Application Security Engineer at Simply Business

Application Security Engineer

Simply Business · GB

1 weeks ago

Application Security Engineer

Simply Business · GB

11 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

As an Application Security Engineer, you will act as a core technical guide across the software development lifecycle, embedding security into code and architecture while exploring next-generation defensive strategies like AI/LLM threat modeling. You will partner closely with engineering teams to demystify complex threats, modernize DevSecOps practices, and mentor developers to build resilient systems.

Responsibilities

  • Provide expert guidance on secure coding, threat modelling, and OWASP Top 10 mitigation.
  • Promote a security-first mindset across development teams, acting as a supportive technical mentor.
  • Integrate security assessments, code reviews, and penetration testing seamlessly into the SDLC.
  • Evaluate, implement, and run modern security tooling (SAST, DAST, IAST) to streamline vulnerability checks.
  • Research emerging AI and LLM threat classes to design proactive, cutting-edge defensive architectures.
  • Participate in incident response investigations and help deliver engaging security training.

Requirements

  • Experienced in application security (5+ years) with strong hands-on penetration testing and security tooling skills.
  • Deeply knowledgeable about web vulnerabilities, secure coding practices, and cloud environments (AWS, Azure, or GCP).
  • Familiar with DevSecOps methodologies and automated security integration.
  • An open, clear communicator who can explain complex security concepts in plain English to both technical and non-technical teammates.
  • Highly collaborative, empathetic, and passionate about mentoring engineers rather than just checking compliance boxes.
  • Curious, proactive, and keen to stay ahead of modern threat landscapes like AI security.

Skills

  • Penetration testing
  • Security tooling
  • Web vulnerabilities
  • Secure coding practices
  • Cloud environments (AWS, Azure, or GCP)
  • DevSecOps methodologies
  • Automated security integration
  • AI/LLM threat modeling
  • SAST
  • DAST
  • IAST

Location

  • Hybrid

Work Type

  • Permanent
  • Full-time

Experience Level

  • 5+ years

Salary/Compensations

  • Competitive salary based on experience and market
  • Potential to earn an annual bonus based on performance

Benefits

  • Great work-life balance
  • Flexible hybrid work
  • 25 days annual leave plus bank holidays
  • Option to buy five additional days of holiday
  • Flexible parental leave (six months full pay for primary caregiver, four weeks full pay for secondary caregiver)
  • Life event leave (an extra day off every two years for significant life events)
  • Paid sabbatical (two weeks after five years, four weeks after ten years)
  • Private medical insurance through BUPA (covers pre-existing conditions)
  • Health cash plan for everyday medical expenses
  • Access to tools for personal development on a dedicated learning platform
  • Support for mental health with access to counselling
  • Pension matching up to five percent
  • Life assurance policy (four times basic salary, option to increase to ten times)
  • Salary sacrifice car scheme
  • Flexible benefits scheme (allocated amount for critical illness cover, dental insurance, travel insurance, gym membership, etc.)

About the Company

  • Insures small businesses and enables big dreams.
  • Protects over 1,000,000 active insurance policies for various trades.
  • A technology company that builds, fails, learns, and improves.
  • Global social impact strategy, 'The Big Dreams Project', aims to help 10,000 small businesses start or grow by 2030.

Equal Opportunity

  • Committed to providing equality and opportunities for all employees and candidates.
  • Offers a workplace where colleagues are treated with respect and dignity.
  • Does not discriminate directly or indirectly on the grounds of race, colour, religion, belief, political opinion, disability, nationality, ethnic origin, sex, sexual orientation or relationship status.