Senior Application Security Engineer
Summary
Leads application security and threat modeling for cloud-native platforms, embedding security in SDLC and guiding engineering/product teams on secure-by-design solutions.
We are seeking an experienced Senior Application Security Engineer to join a high-performing security team supporting a large-scale technology environment.
This role is focused on Product Security and Application Security, working closely with engineering and product teams to embed security throughout the software development lifecycle. You will play a key role in identifying security risks early, leading threat modelling activities, conducting security design reviews, and helping teams implement secure-by-design solutions across modern cloud-native platforms.
Key responsibilities include:
This opportunity is best suited to candidates with a strong Application Security, Product Security or AppSec background. Candidates whose experience is primarily within SOC Operations, GRC, IAM or compliance-focused environments may not be closely aligned to the requirements of this role.
This role is focused on Product Security and Application Security, working closely with engineering and product teams to embed security throughout the software development lifecycle. You will play a key role in identifying security risks early, leading threat modelling activities, conducting security design reviews, and helping teams implement secure-by-design solutions across modern cloud-native platforms.
Key responsibilities include:
- Leading threat modelling workshops for new and existing applications, platforms and services
- Conducting security architecture and application security reviews
- Partnering with engineering teams to identify risks and recommend security controls
- Driving secure development practices across the SDLC
- Providing guidance on secure coding, application security and cloud security
- Supporting DevSecOps initiatives and security automation
- Collaborating with product, engineering and security stakeholders to prioritise and remediate security findings
- Developing reusable security patterns, standards and guidance for development teams
- Strong Application Security or Product Security experience
- Proven experience leading threat modelling exercises (STRIDE or similar)
- Security architecture and secure design review experience
- Secure SDLC and DevSecOps practices
- AWS cloud security experience
- Web application security and vulnerability management
- Modern architectures including APIs, microservices and cloud-native platforms
- Security frameworks such as OWASP, MITRE ATT&CK, NIST and/or ISO 27001
- Strong stakeholder engagement and the ability to influence engineering and product teams
- Experience within SaaS, product-led or technology-focused organisations
- Container and Kubernetes security
- Security Champion programs
- Secure coding and developer training initiatives
- AI security exposure
This opportunity is best suited to candidates with a strong Application Security, Product Security or AppSec background. Candidates whose experience is primarily within SOC Operations, GRC, IAM or compliance-focused environments may not be closely aligned to the requirements of this role.