Application Security Engineer

2 weeks ago


London, UK, United Kingdom Roka Search Full time

Job Title: Application Security Engineer

Location: London / Remote with Flexible Working Arrangements

Salary: Up to £80k per annum


About the Role

As an Application Security Engineer, you will play a critical role in ensuring the secure development of software across a global FinTech organisation. Working closely with software development, infrastructure, and business teams, you will help embed security practices into every stage of the software development lifecycle. You will also be responsible for threat modelling, automating security testing, and configuring security defences like Web Application Firewalls (WAF). This role is well-suited for an individual with strong technical expertise in application security and excellent communication skills.


Key Responsibilities

  • Integrate Security Practices: Collaborate with development teams to embed security into the software development lifecycle, promoting a shift-left security culture.
  • Security Automation: Configure and manage security tools in CI/CD pipelines (e.g., GitLab, Jenkins) to automate security testing.
  • Threat Modelling: Conduct threat modelling exercises with development and architecture teams to identify and mitigate potential risks early.
  • WAF Configuration & Defence: Configure Web Application Firewalls (WAF) and other security defences, particularly using Akamai technologies.
  • Monitoring & Incident Response: Build proactive monitoring tools and automation for security events, and support incident response efforts.
  • Security Training & Advocacy: Deliver training on security best practices and tools, and write accessible documentation for security guidelines across the organization.
  • Collaboration & Communication: Work cross-functionally with other teams to communicate security requirements and foster an inclusive security culture.


Required Skills & Experience

  • Application Security Experience: Proven experience in application security, with knowledge of security best practices and risk mitigation strategies.
  • CI/CD Expertise: Proficiency with CI/CD pipeline tools such as GitLab, Jenkins, Azure DevOps, or GitHub Actions for security automation.
  • Programming & Scripting: Ability to read and write code in languages such as Java, Python, JavaScript, and script in languages like Bash or PowerShell.
  • Cloud Security Knowledge: Experience with cloud infrastructure (preferably Azure) and security measures in cloud environments.
  • Security Tooling: Experience with common Application Security tools such as SAST, DAST, SCA, and IaC security scanning.
  • Web Application Firewalls: Experience configuring and managing WAFs, particularly using Akamai.
  • Relevant security certifications such as CompTIA Security+, CEH (Certified Ethical Hacker), CISSP (Certified Information Systems Security Professional), or equivalent.


Desirable Skills

  • Threat Intelligence: Familiarity with OWASP Top 10, MITRE ATT&CK, and other threat frameworks, and their application to business risk management.
  • Containerisation & Orchestration: Knowledge of Docker and Kubernetes for securing containerized applications.
  • Agile Methodology: Experience working in agile teams, using tools like Jira for tracking and development.


Soft Skills

  • Communication: Excellent written and verbal communication skills, with the ability to explain complex security concepts in simple terms.
  • Collaboration: Strong team player, capable of working collaboratively across departments and with diverse teams.
  • Problem-Solving: Adept at troubleshooting security issues, identifying root causes, and implementing innovative solutions.



  • London,, UK, United Kingdom Acumin Full time

    Application Security Engineer (Remote)We are seeking a skilled Application Security Engineer to join our growing cybersecurity team. In this role, you will be responsible for identifying, analyzing, and remediating security vulnerabilities in software applications across the organization. You'll collaborate closely with engineering teams to provide...

  • Security Engineer

    5 days ago


    London,, UK, United Kingdom acre security Full time

    Are you passionate about shaping the future of security solutions? Do you thrive in an environment that values innovation and teamwork? If so, acre security is the place for you! Join us in making the world a safer place, one innovation at a time.Position: Security EngineerLocation: London, UK.A Bit About Us:At acre, we're not just creating security...


  • London,, UK, United Kingdom intro Full time

    Security Software Engineer/DevSecOps Engineer/Application Security Engineer Onsite - London, Madrid or Malaga (4 days in the office, 1 day remote)Our client's expanding Cyber Security team is seeking a skilled professional to contribute to security enhancements across their diverse product range. In this role, you will collaborate seamlessly with...


  • London,, UK, United Kingdom Iceberg Cyber Security Full time

    Senior Security Engineer – Network Security Working in the financial trading industry is highly motivating for security technologists because the environment is constantly changing at a fast pace, allowing you to work with cutting-edge technology. The exciting aspect of this opportunity is that you do not need current or previous experience within the...


  • London,, UK, United Kingdom Iceberg Cyber Security Full time

    I’m currently representing a global tech organisation whose base of operations is in London and this year they have grown strength to strength in investing heavily in their platforms and tech stack. With this level of innovation, the senior leadership have identified the need for a senior Network Security Engineer with a deep understanding of CISCO...


  • London,, UK, United Kingdom Woolf Group Full time

    We are working with a fund who are number one in their specialist area and currently rebuilding their entire pricing & risk management platform from scratch.Responsibilities:Become an integral part of our Security Engineering team, where you'll be directly involved in designing, implementing, and maintaining key security services.We are hands-on...


  • London, UK, UK, United Kingdom Client Server Full time

    Application Security Engineer (Akamai WAF Gitlab) London / WFH to £80k Fixed Term ContractOpportunity to progress your career as an Application Security Engineer at a global FinTech on a 12 month fixed term contract (FTC).As an Application Security Engineer you will join a small team that collaborates with software development, infrastructure and business...


  • London,, UK, United Kingdom RX Global Full time

    Application Security Leader - Richmond - Hybrid Are you able to make strategic decisions based on advances in technology? About our Team RX is in the business of building businesses for individuals, communities and organisations. We elevate the power of face-to-face events by combining data and digital products to help customers learn about markets, source...


  • London,, UK, United Kingdom CornerStone - Risk, Cyber & Security Full time

    CornerStone is a leading independent Security Risk Consultancy, and we are now looking for a Technical Security Consultant to join our award-winning team in a UK-wide capacity. We are seeking an individual who enjoys working in a fast-paced, collaborative environment that is built upon innovation, teamwork, taking ownership, and supporting each other....


  • London,, UK, United Kingdom Eames Consulting Full time

    Application Security ConsultantLondon (Hybrid)£85,000Duties and Responsibilities:Be comfortable providing secure coding practises training to the development teams engagingly and collaboratively.Threat Modelling expertise is required to train developers to threat model themselves and provide further expertise when it is escalated.Comfortable with...


  • London,, UK, United Kingdom Corriculo Recruitment Full time

    COR5774 Software Security Engineer, Software Security SpecialistA rare and exciting opportunity has arisen for an experienced Software Security Engineer, to join a pioneering scientific R&D company, who specialise in the development of medical devices.The RoleThe Software Security Engineer will join a highly skilled team of engineers to ensure the security...

  • Founding Engineer

    2 weeks ago


    London,, UK, United Kingdom Cofide Security Full time

    About CofideCofide is an early-stage startup focused on workload identity and access management (IAM) for multi and hybrid-cloud environments. We're building on open standards, including OAuth, SPIFFE et al. Based in the UK, we are currently in stealth mode and are actively seeking a strong founding engineering team to help shape the future of identity...

  • Security Engineer

    2 weeks ago


    London, UK, United Kingdom Dare Full time

    Who we are We are an energy trading company generating liquidity across global commodities markets. We combine deep trading expertise with proprietary technology and the power of data science to be the best-in-class. Our understanding of volatile, data-intensive markets is a key part of our edge. At Dare, you will be joining a team of ambitious individuals...

  • Security Engineer

    3 days ago


    London,, UK, United Kingdom QCIC Full time

    About the roleWe are seeking an experienced Security Engineer to play a pivotal role within a client team based in London. You will oversee and drive the successful mobilisation and delivery of access control and CCTV projects across the client’s portfolio. This lead position will involve supporting enterprise-level application implementations, managing...


  • London,, UK, United Kingdom Eames Consulting Full time

    Cloud Security Engineer (Azure)London£70,000Design, build, and maintain resilient cloud infrastructures on Azure that are robust against security threats.Develop and evaluate cloud security solutions to protect systems, databases, and networks.Perform thorough assessments and provide actionable recommendations to ensure the implementation of appropriate...


  • London,, UK, United Kingdom Ntrinsic Consulting Full time

    Ntrinsic Consulting have partnered with an Oil and Gas company based in London. This organisation are looking for a Senior Cyber Security Engineer. You as the Senior Cyber Security Engineer will play a critical role in identifying vulnerabilities, implementing robust security measures, and ensuring the integrity and confidentiality of our digital assets...

  • Security Engineer

    3 weeks ago


    London,, UK, United Kingdom Locke and McCloud Full time

    Cyber Security EngineerThe OpportunityWe are seeking a skilled Cyber Security Engineer to join our team, playing a crucial role in safeguarding our digital assets and IT infrastructure. Based in the EU, you will be the primary cyber security resource for the region, contributing to our global security efforts. This role involves leading incident response,...

  • Security Engineer

    3 weeks ago


    London, UK, UK, United Kingdom InterEx Group Full time

    Job SummaryWex is looking for a security engineer with Antivirus platform experience.The engineer will be responsible for enhancing Trend Deep Security and CrowdStrike policies tooptimize the usage and operation of the tools. This individual will also be reasonable foranalysis of existing policies to provide recommendations for optimization.Responsibilities...


  • London,, UK, United Kingdom Harrington Starr Full time

    Lead DevSecOps EngineerA leading global financial services firm is seeking an experienced Lead DevSecOps Engineer to join their dynamic team. This firm operates across a range of markets, providing essential services in commodities, energy, and financial sectors with a global reach and a strong balance sheet.Key Responsibilities:Secure and enhance the CI/CD...


  • London,, UK, United Kingdom Ntrinsic Consulting Full time

    Senior Cyber Security Engineer is sought by a highly innovative start-up in the energy space to join their IT team who are rapidly expanding. Consequentially they require bright a well-practised Senior Cyber Security Engineer to impact their mission to innovate security technology across Microsoft, Cisco Meraki as well as the network connectivity across...