In 2023, 2024 and 2025 we were recognised as one of the Best Workplaces in Tech by Great Place To Work UK, the global authority on workplace culture.
Senior Application Security Engineer
Location
United Kingdom
Posted
13 days ago
Salary
0
Seniority
Senior
Job Description
Senior Application Security Engineer
Leighton
Role Description Are you passionate about building security into software from the ground up? We’re looking for a Senior Application Security Engineer to take charge of strengthening and evolving security across our Loyalty division. In this role, you won’t just identify risks; you’ll lead the charge in transforming how secure software is built, working side-by-side with engineering and product teams to make security an intrinsic part of everything we deliver. - Own and drive application security strategy, influencing key security metrics and outcomes - Embed secure-by-design principles into every stage of the development lifecycle - Partner with engineers and product teams to elevate security awareness and capability - Introduce and optimise automated security controls within CI/CD pipelines - Lead threat modelling and secure design discussions, shaping decisions around critical areas like authentication and data protection - Ensure security tooling (SAST, DAST, SCA) is effective, scalable, and delivering real value - Oversee and enhance testing initiatives including penetration testing, scanning, and bug bounty programmes - Act as a trusted advisor to engineering teams triaging issues and guiding practical remediation - Contribute to security standards, documentation, and audit readiness - Champion a strong, proactive security culture across the organisation Qualifications - A background in software engineering with a security-first mindset - Strong knowledge of modern web and API vulnerabilities (OWASP Top 10 and beyond) - Hands-on experience with automation, scripting, and integrating security into CI/CD workflows - Familiarity with security tooling such as SAST, DAST, and SCA - Experience working in cloud-native environments (AWS), microservices, and containerised systems - Confidence in reviewing architecture, leading threat modelling, and influencing secure design decisions - Excellent communication skills, ability to engage, educate, and inspire engineering teams Requirements - An open and genuine communicator - Able to take responsibility for your actions - Always learning and wanting to improve - Takes responsibility for own development - Love what you do - Value and support your team - Embrace who you are - Open minded and willing to explore new ideas Benefits - A competitive salary this will be dependent on experience - A contributory pension scheme - Private healthcare - 25 days annual leave, plus bank holidays and the opportunity to buy or sell holiday - A flexible approach to working hours - Continuous personal development, career path and training - And more...
Related Guides
Related Categories
Related Job Pages
More Application Engineer Jobs
Copilot and Power Platform Application Engineer
Arrow ElectronicsArrow Electronics is a Fortune 500 company that delivers a variety of products, services, and solutions to commercial and industrial users of enterprise computi
Title: Copilot & Power Platform Application Engineer Location: Denver United States Job Description: Position: Copilot & Power Platform Application Engineer Job Description: This role designs and delivers Workplace A.I. (Copilot) and Power Platform enablement services that accelerate safe, practical adoption across the enterprise. The position partners with executive, business, and department stakeholders to identify high-value scenarios, run discovery and solution-shaping workshops, and build rapid prototypes/POCs using Microsoft 365 Copilot, Copilot Agent Builder, Copilot Studio, and Power Platform. The role also develops reusable templates, a Copilot communication and training approach, and coaching programs that help teams move from idea to prototype to deployment-collaborating with Security/Compliance and platform owners to align with guardrails and maximize stakeholder outcomes. What You'll Be Doing: - Designs and delivers A.I. technology demonstrations, workshops, and prototypes aligned to business outcomes and user workflows. - Assesses opportunities and constraints (data readiness, permissions, integration options, and guardrails) and advises teams on solution approaches and effort. - Builds rapid prototypes (prompt patterns, agent conversation flows, and lightweight integrations) to validate feasibility and user experience. - Leads strategic workplace technology initiatives through research, POCs, and advisory consulting, translating stakeholder needs into prioritized scenarios and actionable plans. - Produces clear documentation and deployment plans (architecture options, backlog, evaluation approach, and operational considerations) to support transition to end user teams. - Creates and maintains reusable enablement assets (starter kits, templates, prompt libraries, checklists, and reference architectures) to reduce time-to-value and improve consistency. - Drives Workplace A.I. (Copilot) adoption through communications and training: contributes to communication planning, develops and delivers targeted training, and runs office hours/coaching to grow a champions network. - Identifies opportunities to improve operational efficiency by recommending and prototyping automation patterns (e.g., Power Platform workflows) that reduce manual effort and improve service quality. - Recommends and socializes governance best practices, usage guidelines, and guardrails-helping ensure secure, compliant, and scalable adoption aligned with enterprise policies, data protection requirements, and responsible AI principles. - Monitors adoption and value signals and recommends iterative improvements to drive sustained usage and measurable outcomes. What We Are Looking For: - Typically requires a minimum of 6-8 years of related experience in Microsoft 365, Power Platform, product delivery, consulting, or digital transformation. - Typical hands-on experience is 1-2 years with Microsoft 365 Copilot along with Copilot Studio / copilot agents, including running workshops, building prototypes, and supporting early deployments. - Requires in-depth knowledge of workplace A.I., Microsoft 365, Copilot capabilities, and modern productivity workflows. - Solves complex, ambiguous problems where success depends on clarifying needs, shaping scope, and balancing speed, quality, and enterprise constraints. - Works independently with minimal guidance; prioritizes multiple concurrent engagements and stakeholder asks based on value and feasibility. - Takes a new perspective using existing platforms (Microsoft 365, Power Platform, Copilot, and Copilot Studio) to create repeatable reference solutions. - Operates in a consultative model across departments and executive initiatives-aligning diverse stakeholders and tailoring recommendations to context. - Acts as a resource for colleagues with less experience; may facilitate community learning and provide informal training. - Uses best practices and internal/external trends to improve enablement approaches, prototype quality, and adoption outcomes. Work Arrangement: Hybrid: Tuesday, Wednesday, Thursday required office days for Panorama Office site; Monday, Friday-work from home. What's In It For You : At Arrow, we recognize that financial rewards and great benefits are important aspects of an ideal job. That's why we offer competitive financial compensation, including various compensation plans and a solid benefits package. - Medical, Dental, Vision Insurance - 401k, With Matching Contributions - Short-Term/Long-Term Disability Insurance - Health Savings Account (HSA)/Health Reimbursement Account (HRA) Options - Paid Time Off (including sick, holiday, vacation, etc.) - Tuition Reimbursement - Growth Opportunities - Discounted RTD Passes, with convenient office location off RTD Light Rail (Dry Creek Exit) - On-site Café with Catering Option for Busy Lifestyles - 24/7/365 On-site Gym and Lockers, Free for Use to All Employees! - Bike Racks - And more! Are you being referred to one of our roles? If so, ask your connection at Arrow about our Employee Referral Process! Annual Hiring Range/Hourly Rate: $102,900.00 - $148,500.00 Actual compensation offer to candidate may vary from posted hiring range based upon geographic location, work experience, education, and/or skill level. The pay ratio between base pay and target incentive (if applicable) will be finalized at offer. Location: US-CO-Denver, Colorado (Panorama Arrow Building) Time Type: Full time Job Category: Information Technology EEO Statement: Arrow is an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, gender, age, sexual orientation, gender identity, national origin, veteran or disability status. (Arrow EEO/AAP policy) All Arrow job postings are for existing job vacancies. We anticipate this requisition will be open for a minimum of five days, though it may be open for a longer period of time. We encourage your prompt application. In any materials you submit, you may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information.
Role Description You could be the one who changes everything for our 28 million members by using technology to improve health outcomes around the world. As a diversified, national organization, Centene's technology professionals have access to competitive benefits including a fresh perspective on workplace flexibility. - Design, develop, test, and deploy software solutions and process flows complying with standards, guidelines, and best practices. - Identify, assess, and formulate architectural impacts and solutions from business requirements. - Collaborate to ensure application designs utilize appropriate patterns and standards. - Analyze user needs and software requirements to determine feasibility of design within time and cost constraints, including the ability to estimate work needed. - Assess functional and nonfunctional requirements and create designs to meet both business and technical needs. - Create conceptual and detailed technical design documents and work with the business to update, as needed. - Identify and resolve problems, often anticipating issues before they occur or before they grow, develop and evaluate options, and implement solutions. - Utilize and contribute to the development of application coding techniques and standards. - Collaborate with Application Solution Architects, IS Business Analysts, and other technical resources on the delivery of application functionality. - Participate in tier 3 application support activities including incident management and the assessment and delivery of application upgrades and patches. - Perform other duties as assigned. - Comply with all policies and standards. Qualifications - Bachelor’s degree in Electronic Engineering, Statistics, Mathematics, Engineering, Computer Science, or related or equivalent experience. - 4 years of relevant work experience. - Experience with developing or prototyping software modules using the Pega platform. - Experience with Pega Development utilizing integrations with MongoDB, GoLang, Java services, and Oracle Databases. - Experience evaluating and improving Code Quality/Standards to maintain 80% coding Unit Testing. - Experience working with and directing third-party Application Developers. - Experience using Provider Lifecycle Management systems and Low Code Technologies including Pega and Salesforce. - Experience utilizing Pega structures including Smart PLM, Pega BIX, Pega Infinity Cloud Version 23+, and Pega UI Cosmos. Requirements - Job site: 7700 Forsyth Boulevard, St. Louis, MO 63105. - Work hours: Monday-Friday, 40 hours/week [8:00 am to 5:00 pm]. - Pay range: $148,553.90 to $169,300.00 per year. Benefits - Competitive pay. - Health insurance. - 401K and stock purchase plans. - Tuition reimbursement. - Paid time off plus holidays. - Flexible approach to work with remote, hybrid, field, or office work schedules. - Total compensation may include additional forms of incentives.
Senior Application Security Engineer
BrexWe're empowering employees anywhere to make better financial decisions. Need Help? -> Email us at support@brex.
Role Description As a Senior Application Security Engineer, you will focus on finding and responding to security vulnerabilities across the Brex platform. In this role, you will: - Perform code reviews, design reviews, penetration testing, and vulnerability management. - Develop and maintain tooling to perform static and dynamic testing of the Brex platform and tooling which supports secure developer workflows. - Work closely with Security Operations, GRC, Product Security, Front End Platform, and IT Infrastructure teams. - Identify attack vectors in AI-powered features and partner with product and engineering teams to build secure AI capabilities. Qualifications - 5+ years work experience in an Application Security or related role. - Ability to find vulnerabilities in complex systems, demonstrating business impact through custom attack chains. - Experience with a wide range of secure development activities including threat modeling, developer education, and incident response. - Knowledge of Python, scripting languages, and AI/agentic workflows to automate tasks, build tools, and improve productivity. - Collaborative mindset paired with strong written and verbal communication skills. Requirements - Proficiency with Kotlin, gRPC, GraphQL, Kubernetes. - Previous experience as a software engineer. - Consultancy experience performing web application security reviews. - Experience with securing distributed systems in AWS and cloud environments. - Experience with pentesting and securing agentic features and systems. - Contributions to the wider technical community—open source, public research, mentorship, community organizing, blogging, CVEs, presentations, etc. - Experience submitting to bug bounty programs or responsible disclosure programs. Benefits - The expected salary range for this role is $192,000 - $240,000. - Starting base pay will depend on factors including location, skills, experience, market demands, and internal pay parity. - Equity and other forms of compensation may be provided as part of a total compensation package.
Senior Application Security Engineer
Apollo.ioHelping sales teams find their ideal buyers and convert them into customers.
• Own and continuously improve the secure software development lifecycle for Apollo applications so security is embedded into design, implementation, and deployment. • Perform application security reviews, threat modeling, and deep code-level analysis for high-impact product, platform, and AI features before launch. • Provide practical security architecture guidance to Engineering, Product, and IT teams. • Help define and maintain application-security guardrails, secure design expectations, code review standards, and risk models for new and existing systems. • Drive execution-heavy vulnerability management across internal reviews, bug bounty, pentests, SCA/runtime findings, and other research signals, ensuring findings are validated, prioritized, routed clearly, and tracked through remediation and verification within SLAs. • Go beyond identifying issues: read the code, explain root cause, propose the safest fix, and directly implement or support remediation when needed for complex vulnerabilities. • Perform hands-on validation and offensive security testing of applications and fixes, including exploit development, bypass testing, adversarial thinking, and focused red-team-style exercises, to confirm remediations address the underlying issue rather than only the initial symptom. • Work across the kinds of application security issues common in modern SaaS environments, including authentication and authorization weaknesses, access control risks, OAuth and CSRF design flaws, SSRF, cryptographic and verification issues, information disclosure and data exposure risks, unsafe execution and deserialization patterns, and dependency or runtime vulnerabilities. • Apply clear, risk-based severity decisions using exploitability, data sensitivity, customer impact, and blast radius. • Configure and improve AppSec tooling and integrations, including SAST configuration, ignore lists, dashboards, and other controls that maintain useful coverage without excessive noise. • Select, build, or refine security tooling, small automations, and workflow enrichments that reduce manual effort and scale AppSec operations responsibly. • Use AI to automate, transform, and scale security and engineering-adjacent processes where it materially improves speed, consistency, or signal quality, while still validating outputs with strong engineering judgment. • Embed AI-specific security checks into SSDLC reviews and code analysis, including input and output handling, AI-exposed APIs, prompt and response guardrails, and abuse or data-exfiltration paths. • Partner cross-functionally on AI security requirements and controls so AI systems and AI-powered features are designed, deployed, and operated securely. • Support and scale security enablement for engineers and security champions, including secure coding, AppSec, and AI-safety content. • Provide actionable remediation guidance, secure patterns, and examples that help engineering teams fix issues quickly and correctly. • Partner closely with Engineering, Product, Platform, Data, Legal, and other security teams to keep AppSec priorities aligned with business risk and product velocity. • Produce clear documentation, metrics, and written narratives that improve AppSec visibility, observability, and decision-making.



