Building a better world with better data.
Application Security Lead
Location
United Kingdom
Posted
34 days ago
Salary
0
Seniority
Senior
Job Description
Application Security Lead
Prolific
• You'll own Prolific's application security strategy and be the most senior security engineering voice in the organisation. • Define and drive our Secure Software Development Lifecycle (SSDLC). • Set the standard for how security is embedded into engineering. • Get hands-on with code review, threat modelling, and security testing when it matters. • Manage our Senior Application Security Engineer and continue to own our compliance programme alongside these responsibilities. • Act as the go-to expert for application security, partnering with engineering leadership to balance risk and velocity. • Build the tooling, processes, and culture needed to embed security into how we ship.
Job Requirements
- Several years of experience in software engineering, you’ve built and shipped production systems at scale
- Several years in application security (testing, code review, threat modelling, vuln management)
- Expert knowledge of OWASP Top 10 (Web & API) and modern attack paths (e.g. auth flaws, SSRF, injection, business logic, supply chain)
- Strong understanding of modern architectures (microservices, APIs, event-driven systems)
- Python for security tooling and automation (Django a strong plus)
- Hands-on testing experience (e.g. Burp Suite) and manual assessment of apps/APIs
- Experience building and scaling SSDLCs, including CI/CD tooling (SAST, SCA, DAST, secrets)
- Experience leading threat modelling and security design reviews
- Strong engineering partnership skills, you influence through trust
- Experience with ISO 27001 / SOC 2 and translating controls into real engineering practices
- Clear communicator across technical and non-technical audiences.
Benefits
- Competitive salary
- Remote working within our impactful, mission-driven culture
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Role Description - Innovate with the Customer in Mind: Partner with product owners, stakeholders, and engineers to understand customer needs, translating complex technical risks into actionable, scalable solutions that solidify Prowler's position at the forefront of the industry and drive our mission to become the standard for cloud protection. - Team Leadership & Execution: Lead, mentor, and grow a team of cloud security engineers and researchers, owning the end-to-end planning, execution, and delivery of cutting-edge research and team projects. - Pioneer Cloud Threat Research: Conduct comprehensive architectural reviews of major cloud ecosystems (AWS, GCP, Azure, OCI), their telemetry data, and Kubernetes to uncover hidden threat vectors, evasion techniques, and structural vulnerabilities. Naturally adopt an adversarial mindset, constantly evaluating new cloud deployments to identify architectural flaws, blind spots, and potential abuse vectors. - Develop Scalable Security Controls: Pioneer new methodologies for threat identification, engineering advanced security rules and automated safeguards from the ground up. Transform experimental security research into robust, enterprise-grade detection features integrated into the Prowler product. - Advanced Threat Modeling: Conduct deep-dive analysis and advanced threat modeling on complex cloud architectures and emerging AI/LLM infrastructures to preemptively identify and mitigate risks. - Drive the Security Roadmap: Contribute to strategic architecture decisions, collaborating closely with world-class engineering and research teams to define and execute the security product roadmap. - Champion Engineering Excellence: Drive high-quality code standards by leading code reviews, automated testing, and CI/CD workflows. Provide constructive feedback and mentor fellow engineers on best practices. - Elevate Industry Standards: Continuously update knowledge and push the continuous improvement of internal practices, introducing the latest industry standards and emerging trends to keep the team at the forefront of cloud security. - Community & Thought Leadership: Actively engage with and support the Prowler community, implement customer-driven requests, represent the team externally, and guide others in the open-source cloud security ecosystem. Qualifications - Cloud Security Expertise: 6+ years of extensive experience in Cybersecurity, with at least 3 years explicitly focused on Cloud Security ecosystems (CSPM, CWPP, CNAPP). - Technical Leadership: Proven experience (2-3+ years) leading engineering or research teams, driving collaborative development workflows, conducting rigorous code reviews, and managing agile security projects. - Cloud Architecture & IAM Mastery: Expert, deep-dive understanding of CSP APIs, internal services, and complex permission models (IAM) across at least one major cloud provider (AWS, GCP, Azure), alongside strong networking fundamentals (including cross-network routing, micro-segmentation, and advanced network topologies). - Attacker/Defender Mindset: A proven ability to evaluate any cloud architecture with an adversarial mindset, identifying structural flaws and potential abuse vectors before they are weaponized, backed by a solid foundation in cloud attack methodologies, vulnerability research, and penetration testing. - Coding Excellence: Advanced proficiency in Python, with a strong ability to write clean, efficient, scalable code. You are a strong advocate for maintaining high standards of detection quality and thorough documentation. - Cloud-Native & Infrastructure: Hands-on experience with containers and orchestration tools (Docker, Kubernetes), and a deep understanding of operating system architectures. - Automation & CI/CD: Practical experience with Git, collaborative workflows, Infrastructure as Code (leveraging the HashiCorp ecosystem or native cloud templates), and deployment automation within CI/CD pipelines. - Communication Skills: Adept at translating intricate security threats into actionable business insights for leadership, while providing deep, actionable context for our engineering squads. - Startup DNA: Driven by a strong sense of ownership, you excel in self-directed remote work while remaining deeply engaged and highly communicative within our distributed engineering culture. Working fluency in English is required. Requirements - AI & LLM Security Vanguard: Pioneering knowledge of emerging threat landscapes, attack vectors, and security best practices within Artificial Intelligence infrastructures, LLM security, and MLOps environments. - Open-Source Champion: A strong background with active, hands-on contributions to open-source security projects and a visible presence in the collaborative security ecosystem. - Industry Thought Leadership: A proven track record of sharing research and knowledge. This includes speaking engagements at top-tier conferences (e.g., DEF CON, Black Hat, fwd:cloudsec, BSides) or impactful research publications, CVE discoveries, and technical blog posts. - Advanced Certifications: Holding industry-recognized certifications that validate your deep technical expertise, such as AWS Certified Security - Specialty, GCP Professional Cloud Security Engineer, OSCP, OSWE, or equivalent. Benefits - Opportunity to work with a rapidly growing and innovative company in the cloud security industry. - Fully remote work, allowing for a flexible and collaborative environment. - Competitive compensation package. - Continuous learning and professional development opportunities. - Be part of a dynamic team that values creativity and innovation. - This is a full time, salaried position writing, testing, reviewing, and operating code at scale. - Prowler is fully remote and distributed, spanning all U.S. time zones and several in E.U. - Mandatory minimum PTO (shoot for ~5 weeks; anything less than 4 weeks/year is unacceptable). - Workstation/home office stipend per year, flexible working hours, and stock options. Hiring Process - Intro & Technical Screen (30 minutes): We want to get to know the person behind the profile. You'll jump on a quick call with one of our founders or tech leads to discuss your background, your proudest achievements, and the complex security or engineering challenges you’ve tackled so far. - Culture & Alignment Interview (1 hour): We thrive on a generative, diversity-first culture that champions context over control. This conversation is a two-way street to ensure you resonate with the high degree of autonomy, freedom, and ownership we expect, and to confirm that our environment is the right place for you to grow and succeed. - Technical Team Dynamic (1 hour 30 minutes): No take-home assignments here—we want to see how we build together. You will join a live, collaborative session with your future teammates to tackle a real-world cloud security scenario. Rather than answering trick questions in isolation, this interactive exercise focuses on your technical reasoning, solution architecture, and how effectively you communicate and problem-solve within a team setting.
Cybersecurity And IOT Research Analyst
LMILMI is a nonprofit business that was established in 1961 to address complex issues throughout the federal government of the United States. LMI is headquartered in McLean, Virginia
Title: Cybersecurity And IoT Research Analyst Location: Tysons Corner United States Job Description: LMI is a new breed of digital solutions provider dedicated to accelerating government impact with innovation and speed. Investing in technology and prototypes ahead of need, LMI brings commercial-grade platforms and mission-ready AI to federal agencies at commercial speed. Leveraging our mission-ready technology and solutions, proven expertise in federal deployment, and strategic relationships, we enhance outcomes for the government efficiently and effectively. With a focus on agility and collaboration, LMI serves the defense, space, healthcare, and energy sectors-helping agencies navigate complexity and outpace change. The Opportunity We're hiring a Cybersecurity & IoT Research Analyst to support ongoing R&D efforts while contributing directly to production-bound DoD systems. This is a hybrid R&D + implementation role. You'll take hands-on research-like IoT protocol vulnerability testing, wireless security analysis, and device-level exploitation-and translate it into actionable security improvements, RMF artifacts, and deployable solutions. You'll work across the full lifecycle: from lab-based vulnerability testing (e.g., replay attacks, packet injection, device compromise) to supporting accreditation (RMF/ATO) and hardening real-world systems. Responsibilities Cybersecurity & RMF Support - Support Risk Management Framework (RMF) activities including control implementation, documentation, POA&Ms, and ATO readiness. - Assist in system security architecture development, aligning IoT/embedded systems with DoD cybersecurity requirements. - Conduct security assessments and support vulnerability management processes across hardware and software systems. - Collaborate with ISSOs, ISSMs, and engineering teams to ensure compliance with NIST and DoD standards. Vulnerability Testing & Security Research - Design and execute vulnerability testing across IoT and RF protocols (e.g., ZigBee, LoRaWAN, NB-IoT, Mist). - Perform packet analysis, traffic inspection, and exploitation testing using tools like Wireshark, Kali Linux, and SDR frameworks. - Simulate real-world attack vectors such as replay attacks, packet injection, device cloning, and resource exhaustion. - Analyze protocol weaknesses such as centralized trust models, insecure key exchange, and lack of rate limiting. R&D and Innovation - Support ongoing R&D efforts focused on IoT protocol security, wireless communications, and system resilience. - Contribute to development of testbeds and experimental environments to simulate real-world deployments. - Evaluate emerging technologies and security approaches to improve system architecture and defense-in-depth strategies. - Document findings and translate research into engineering recommendations and product improvements. Secure System Development - Support development of secure update mechanisms, device authentication workflows, and trust validation systems. - Contribute to secure software and firmware design, including integrity validation and access control mechanisms. - Assist in implementing protections against unauthorized access, tampering, and compromised device participation. - Collaborate with DevSecOps and platform teams to integrate security into CI/CD pipelines and deployment workflows. Data Analysis & Reporting - Analyze quantitative and qualitative security data to assess system resilience and risk posture. - Develop technical reports, briefings, and executive summaries to communicate findings and recommendations. - Support customer-facing deliverables and contribute to proposal or R&D documentation efforts. Qualifications What We're Looking For - Bachelor's degree in Cybersecurity, Computer Engineering, Computer Science, or related field (or equivalent experience). - Strong foundation in cybersecurity principles, including network security, cryptography, and secure system design. - Experience or coursework in wireless communications, RF systems, or IoT protocols. - Hands-on experience with tools such as Wireshark, Kali Linux, Metasploit, or similar security testing frameworks. - Familiarity with programming/scripting (Python, C/C++, or Java). - Understanding of networking fundamentals and packet-level analysis. - U.S. Citizenship required; ability to obtain a Secret clearance. Bonus Points For - Experience with RMF, ATO processes, or NIST 800-53 controls. - Exposure to IoT security testing, embedded systems, or RF communications. - Experience building or working with testbeds (e.g., Raspberry Pi, wireless mesh networks). - Familiarity with cloud platforms (GCP, AWS) and containerization (Docker). - Participation in cybersecurity competitions, research programs, or technical R&D initiatives. - Experience analyzing attack vectors like replay attacks, packet injection, or unauthorized access in IoT systems. Why This Role Matters Modern IoT systems are expanding the attack surface across critical defense infrastructure. Research has shown that protocols can be vulnerable to attacks like replay, injection, and unauthorized access depending on implementation and architecture . In this role, you won't just study those vulnerabilities-you'll help eliminate them. Your work will directly influence how secure, resilient, and mission-ready next-generation DoD systems become. Target salary range: $69265.76 - $118424.66 Disclaimer: The salary range displayed represents the typical salary range for this position and is not a guarantee of compensation. Individual salaries are determined by various factors including, but not limited to location, internal equity, business considerations, client contract requirements, and candidate qualifications, such as education, experience, skills, and security clearances. #LI-SH1
Title: Lead Security Engineer Location: Amsterdam NL Hybrid Technology Job Description: At bunq, we're not just building a banking app; we're reshaping how people around the world experience financial freedom. As our Lead Security Engineer, you are the digital guardian of our bank. You'll lead the charge in protecting our users and our data from an ever-evolving landscape of cyber threats, ensuring our platform remains a fortress of trust. Up for this? Kick off your application by taking our assessment and find out if bunq is your perfect match! Take Ownership As our Security Engineering Lead, you will play a critical role in strengthening and defending our digital environment. You will lead a team of highly skilled security professionals, making bunq safer for users and employees globally. You'll: - Lead the SecOps team responsible for detecting, investigating, and resolving security events, owning the end-to-end security posture of bunq. - Work together with our CISO to define our security roadmap by identifying gaps and risks, then drive the implementation of new tools and measures to mitigate those threats. - Manage and harden our core corporate infrastructure, including G-suite, AWS, Okta, and our fleet of Apple endpoints. This challenge is perfect for you if - You have experience leading a small, hands-on team of Security Engineers, and you aren't afraid to get your hands dirty. - You have extensive, practical experience with SOC processes, incident response, and SIEM software. - You possess a deep knowledge of security best practices for both cloud and corporate IT environments. - You have hands-on experience managing and securing G-suite, Okta, AWS, Apple endpoints, and device management software (preferably Kandji). - You are fluent in English - able to communicate effectively in a global team, ensuring collaboration and clarity across all project stages. All new hires are subject to Pre-employment Screening (PES), which includes checks conducted by our third-party partner, DISA. This is part of our commitment to a secure and trustworthy workplace Curious to see how we make life easy? - try the bunq app, it only takes 5 minutes to sign up. Your space to perform We give you the space and the tools you need to succeed Great, international colleagues who share your mindset Hybrid setup: after 3 months in-office, work 2 days remote, 3 days in-office weekly. Digital Nomad Program: After your first year, enjoy up to 20 days per year to work while traveling, combining flexibility with strong team collaboration We reward tenure with a dedicated travel budget: €1.5k after 2 years and €3k after 4 years to visit another core office. We support growth with bunq Academy and €1500 annual learning budget Massive discount with Urban Sports Club Travel expenses are covered whether you come walking or by bike, bus or car (though we prefer green choices) A MacBook so you can Get Shit Done with us Delicious lunches from our fabulous in-house chefs with vegan and vegetarian options An optional pension plan with monthly contribution from bunq Monthly contribution to your phone and internet bills Friday drinks and other celebrations - bunq style
IT SAP Basis Administrator
Davey Tree Expert CompanyDavey Tree Expert Company is the largest employee-owned company in Ohio and provides a full range of forestry consulting, tree care, grounds maintenance, and utility line clearing
Title: IT SAP Basis Administrator Job Description: Company: The Davey Tree Expert Company Locations: Kent, OH Additional Locations: Hybrid Work Site: Hybrid Req ID: 223562 Position Overview The IT SAP Basis Administrator is responsible for the management, maintenance, and support of the SAP system landscape. This includes installing, configuring, monitoring, tuning, and troubleshooting all SAP environments to ensure high levels of availability, performance, and security. The SAP Basis Administrator works closely with IT teams, developers, and business stakeholders to support ongoing projects and daily operations. This is a hybrid position, but the first month would be onsite for training purposes. Job Duties - Install, configure, and maintain the organization's SAP system landscape - Perform daily system monitoring, verifying the integrity and availability of all SAP systems, server resources, and key processes. - Manage the Transport Management and change management using Revtrac to ensure all configuration and development objects are promoted properly. - Manage and support integrations (e.g. SAC, CRM, Revtrac, BTP, etc.) - Manage data backup processes and ensure the ability to recover data in case of system failures. - Apply system patches, kernel upgrades, and support packages (stacks) in a timely manner. - Execute system copies, client copies, and system refreshes to support project and testing requirements. - Perform regular system backups and conduct disaster recovery tests to ensure business continuity. - Analyze and troubleshoot system performance issues, providing resolutions to optimize performance. - Maintain comprehensive documentation of the SAP system landscape, configurations, and procedures. - Provide technical support and guidance to project teams and end-users. - Perform other related duties as assigned. - Follow all company policies, procedures, and work rules. Qualifications - A minimum of three years of experience in SAP Basis administration. - Demonstrated leadership abilities, with a proven track record of effective mentoring and leading technical teams. - In-depth knowledge of SAP architecture, including systems such as S/4HANA, ECC, ECP, BTP, Solution Manager, etc. - Advanced technical troubleshooting, performance tuning, and problem-solving skills for complex SAP issues. - Experience with database administration (e.g., HANA, SQL Server, Oracle) and operating systems (e.g., Windows, Linux). - Self-motivated and collaborative team player, with the ability to work effectively in diverse environments. Additional Information What We Offer: * - Paid time off and paid holidays - Opportunities for advancement - All job specific equipment and safety gear provided - 401(k) retirement savings plan with a company match - Employee-owned company & discounted stock purchase options - Group Health Plan - Employee referral bonus program - Locations throughout US in major cities and desirable areas - Career Development Program supported by Industry Expert Safety Specialists & Skills Trainers - Scholarship Program for Children of Employees - Charitable matching gift program *all listed benefits available to eligible employees Divisional Overview The Davey Tree Expert Company is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to protected class, including race, color, religion, sex, pregnancy, sexual orientation, gender identity or expression, national or ethnic origin, marital or familial status, disability, status as a protected veteran, status as an Aboriginal or Indigenous person, or other classification protected by law. The Davey Tree Expert Company provides research-driven tree services, grounds maintenance and environmental consulting for residential, utility, commercial and environmental partners in the U.S. and Canada. We care about our clients, each other and the world around us. We offer the resources, size and stability of a big company while maintaining the culture, entrepreneurial spirit and feel of a small one. We invest in our employees by offering industry-leading training, technology and benefits that lead to a rewarding and safe work experience at all levels. Wherever you want to grow your career, there’s a place for you at Davey. To learn more, visit Davey.com. Accommodations: If requested by employee or otherwise as required by law, reasonable accommodations will be made to enable employees with disabilities to perform essential job functions. Employment Type: Permanent Job Type: Full Time Travel Expectations: None

