We are looking for an experienced application security engineer who will champion a shift-left security philosophy by integrating automated security analysis into CI/CD pipelines, SAST scanning, GitHub Actions, and SCA. To ensure we embed security into the software development lifecycle (SDLC) across the organisation’s .NET, Java, and Node.js technology stacks.This role is also needed to run web application security assessments or penetration tests.
What You Will Do
• Threat Modelling
• Code reviews
• Supporting engineering teams with security related design and build issues
• Reviewing the results from various security code scanning tools
• Reviewing CI/CD pipeline configurations
• Create or amend code and generate pull requests for code fixes
• Reviewing and testing AI integrations and relevant guard rails etc
• Assisting other members of the team with application security related issues
• Completing web and desktop security assessments
• Carrying out risk assessments using the IRAM2 methodology
• Attending architecture board technical reviews
Success Measures:
• Number of threat models completed
• Number of penetration tests completed
• Number of engagements on AI and Software Engineering Projects
• Number of risk assessments completed
What You Will Have
• 5+ years of experience in application security, software engineering, or DevSecOps.
• Proven hands-on experience securing applications built with .NET, Java, and Node.js.