Application Security Engineer

2 days ago


London Area, United Kingdom IFX Payments Full time £60,000 - £120,000 per year

About IFX Payments

We're an award-winning global provider of foreign exchange and payment solutions. At IFX, our mission is to become the number one service-led alternative banking partner in EMEA for corporates and Financial Institutions that add value beyond the transaction. We have one guiding principle: to
Win. Properly.

Overview of the role

IFX Payments is seeking a technically skilled and proactive Application Security Engineer to embed secure development practices across its software delivery lifecycle. This role is critical in reducing application-layer risks, implementing secure coding standards, and ensuring that threat modelling and architecture reviews are consistently applied across all development efforts.

You will work closely with engineering, and platform teams to integrate security into CI/CD pipelines, automate vulnerability detection, and drive continuous improvement in application security posture.

Responsibilities

Secure Development Lifecycle (SDLC)

  • Embed security controls into CI/CD pipelines and development workflows.
  • Implement and manage SAST, DAST, and SCA tools to detect vulnerabilities early in the lifecycle
  • Conduct secure code reviews and support developers in remediating findings.

Threat Modelling & Architecture Review

  • Lead threat modelling sessions using standard methodologies to identify design flaws
  • Review application architectures to ensure alignment with security objectives and mitigation of common threats.
  • Maintain and update reference architectures based on threat modelling insights.

Tooling & Automation

  • Deploy and manage application security tools and integrate them with existing platforms.
  • Automate security tasks using scripting (e.g., Python, PowerShell) or SOAR platforms.

Governance & Compliance

  • Ensure alignment with ISO 27001, FCA, and NIST standards.
  • Contribute to audit readiness and support compliance automation platforms such as Drata

Collaboration & Training

  • Work with engineering teams to promote secure coding practices.
  • Support the rollout of role-based security training and awareness initiatives.
  • Act as a security champion within development squads and mentor junior engineers.

Requirements

  • Broad experience in application security or secure software development.
  • Strong understanding of OWASP Top 10, secure coding techniques, and threat modelling.
  • Experience with security tools such as SAST, DAST, SCA, and vulnerability scanners.
  • Familiarity with cloud platforms (Azure or AWS), CI/CD pipelines, and DevOps practices.
  • Knowledge of regulatory frameworks (ISO 27001, FCA, NIST).
  • Excellent communication skills and ability to work cross-functionally.
  • Experience in fintech or regulated environments.
  • Certifications such as OSCP, CSSLP, or CISSP.
  • Familiarity with compliance automation platforms (e.g., Drata).
  • Exposure to legacy system security challenges and modernisation strategies.
  • A true team player with a winning mentality and strong work ethic committed to continuous improvement and high performance.
  • Adaptable, tenacious and flexible who is able to perform under pressure.

What we offer

Everyone at IFX Payments has a meaningful and impactful role to play in helping us achieve that goal. We take pride in the quality of our work but balance that with the speed, intent, tenacity, and focus needed to win. We're a high-performance team who can trust each other as individuals to get the job done so we can be successful together.

Being part of IFX Payments, you'll receive every opportunity to thrive in your role to contribute to that success. We'll invest in you along the way to genuinely help you grow and take your career to new and exciting places. You'll work alongside experienced industry leaders, receive guidance from pioneering performance coaches and have the option to gain qualifications in your field that help you realise your ambitions. In exchange, we don't expect anything extra from you during your time here. We only ask you to do one thing:
Make it count.

Benefits

  • 25 days' annual leave, plus bank holidays and an extra day off for your birthday
  • Life Insurance.
  • Holiday loyalty scheme.
  • Work abroad scheme.
  • Enrolment into our pension scheme, which we offer via a salary exchange scheme.
  • Access to a financial education, planning and coaching platform.
  • Membership with Healthcare platform, which offers cash back on healthcare focused on
  • dental, optical & physio, plus access to stress helplines, a virtual GP and more.
  • Salary exchange nursery fees.
  • Enhanced parental leave.
  • Cycle to work.
  • Career development and progression tools.
  • Company events – Sporting events, pub nights, seasonal parties, socials.

Diversity & Inclusion

We believe that diversity and inclusion are essential to our success. We are committed to fostering a culture where everyone feels valued and respected, regardless of their background, identity or experiences. By embracing diverse perspectives and promoting equity, we aim to create an environment where all employees can perform and reach their full potential.

Additional Information

  • We work on a hybrid basis from our office in central London.

  • You must be eligible to work in the UK to be considered for this position.

  • Full background check will be carried out.



  • London Area, United Kingdom Siena Partnership Full time

    Partnered with a VC backed Fintech organisation I'm looking for a Senior Application Security Engineer to embed application security into there product development lifecycle and CI/CD pipelines. This is an individual contributor role working closely with engineering, SRE and product teams to assess, improve, and scale AppSec across a high‑volume...


  • London Area, United Kingdom Siena Partnership Full time

    Partnered with a VC backed Fintech organisation I'm looking for a Senior Application Security Engineer to embed application security into there product development lifecycle and CI/CD pipelines. This is an individual contributor role working closely with engineering, SRE and product teams to assess, improve, and scale AppSec across a high‑volume...


  • London Area, United Kingdom Acre Security Full time £40,000 - £80,000 per year

    Position:Security Systems EngineerLocation:London, UKMove Security Forward with AcreAre you passionate about transforming the future of security? Do you thrive in a collaborative, innovative environment where your contributions drive real impact? If so, Acre Security is the place for you. Join us in making the world a safer place — one innovation at a...


  • Greater Bristol Area, United Kingdom Sanderson Full time £90,000 - £120,000 per year

    Mobile Application Security EngineerRate:£650 per day Inside IR35Duration:6 monthsLocation:Bristol / Hybrid (onsite once a month)We have an exciting opportunity for a Mobile Application Security Engineer to join a leading organisation on a contract basis. You'll play a key role in strengthening the security of large-scale mobile applications, working across...


  • London, Greater London, United Kingdom Ignite Digital Full time £60,000 - £120,000 per year

    Application Security Engineer / AppSec Engineer / Cloud Security Engineer Hybrid London (2 days in-office) | Competitive Salary + Bonus + BenefitsAre you passionate about securing cutting-edge digital platforms in a fast-moving fintech environment? We're seeking an experienced Application Security Engineer to play a vital role in safeguarding our cloud...


  • London, United Kingdom Plexus Full time

    **Application Security Engineer l Full Time l Permanent** **Application Security Engineer l Full Time l Permanent** Plexus is working with a well-funded start-up who operate within the DeFi and Blockchain space. They offer a protocol that eliminates the necessity to pre-fund wallets on exchanges - therefore unlocking multiple benefits for the customer,...


  • london, United Kingdom Barclay Simpson Full time

    This leading investment management firm has an excellent reputation in the market and is currently investing in its Security function. The organisation is seeking an Application Security Engineer to join a growing team of three. This role will see you driving an 'automation first' and shift left approach. You will work to embed security across the SDLC...


  • London, Greater London, United Kingdom Amazon Full time £90,000 - £120,000 per year

    DESCRIPTIONAt Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon's products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build...


  • London, Greater London, United Kingdom Amazon Full time £60,000 - £120,000 per year

    At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon's products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience...


  • London, United Kingdom Amazon Full time

    At Amazon security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazons products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in...