Senior Application Security Engineer

3 months ago


England, UK, United Kingdom Nationwide Building Society Part time

It's easy to misunderstand what Nationwide is like. Why? Because we're not like a bank. We're not like other financial services companies either. As a Senior Security Engineer here, you'll sit within CTO, assisting a wide range of delivery teams in engineering secure solutions and protecting our member's money and data.


We believe security is a systemic concern; therefore, security problems should be solved by a systemic approach (take a look at our tenets here if you are interested to learn more about our vision). We will have regular forums in which we consult with other security engineers within the team, looking at the problems from each of our specialities' perspectives.


At Nationwide we offer hybrid working wherever possible. More rewarding relationships are supported through our hybrid approach, bringing colleagues together across our UK wide estate, whilst also supporting generous access to home working. We value our time in the office to solve problems, to learn, and to feel connected.


For this job you'll spend at least two days per week, or if part time you'll spend 40% of your working time, at one of our offices. If your application is successful, your hiring manager will provide further details on how this works. You can also find out more about our approach to hybrid working here.


This role can be based out of either our Swindon, Nationwide House office or our London, Threadneedle Street office. We'll also consider candidates who wish to be based at our Glasgow office or our Manchester hub as secondary options, with the view you'll be available for ad/hoc visits to our Swindon and London offices.


What you'll be doing

As a senior security engineer, you will work cross-functionally to assess risk and help deliver countermeasures that protect our member's data. You will work will engineering teams to create solutions that solve or remediate security problems. This will involve a range of activities, including (but not limited to) threat modelling, selection and configuration of DevSecOps tools, high-level and detailed security designs.


About you

We are looking for a Senior Security Engineer with experience in design and implementing cloud native applications in the cloud.

You should have demonstrable experience in

  • Threat modelling, design and implementing security controls in the cloud environment (AWS or Azure)
  • Design and implementing cloud native and hybrid solutions in major public cloud platforms.
  • Understanding of cryptographic primitives and protocols and their implementations in the cloud environment
  • Programming with at least one modern language, an appreciation of software development lifecycle, software delivery methodologies and experience with industry-standard tools and methods for delivering software in an enterprise environment (version control, CI/CD pipeline, etc.)
  • Experience with Authentication and authorisation, Attribute-Based Access Control (ABAC), Role Based Access Control (RBAC))
  • Teamwork skills and resourcefulness with a proven sense of ownership and drive

It would also be beneficial if you have.

  • Containerisation and serverless technologies (i.e., Docker, K8s, AWS Lambda) and their security implications
  • Application perimeter defence (i.e., Web Application Firewalls)
  • Experience with API gateway and Service Mesh and their security implications (i.e., APIGEE, ISTIO…)
  • Degree in computer science or related field
  • Professional certifications in AWS or Azure

Our Customer First behaviours are all about putting customers and members at the heart of how we work together. You can strengthen your application by showing the behaviours that resonate with you, and how you might have already demonstrated these.

  • Say it straight - This is about being honest and direct with good intent and saying what needs to be said in the room. It’s also about being clear, precise, and using language that we and, importantly, our customers and members can understand.
  • Push for better - This is about aiming high and constantly looking for better in how we work together and serve our customers and members.
  • Get it done - This is about prioritising what will have the greatest impact, being decisive and taking accountability for delivering on the end-to-end outcome.

We know applying for jobs can sometimes feel like you’re sending an application into a black hole. We review each application individually. So, it’s a good idea to call out your most relevant experience on your application to give yourself the best chance.


The extras you'll get

There are all sorts of employee benefits available at Nationwide, including:

  • A personal pension – if you put in 7% of your salary, we’ll top up by a further 16%
  • Up to 2 days of paid volunteering a year
  • Life assurance worth 8x your salary
  • A great selection of additional benefits through our salary sacrifice scheme
  • Access to an annual performance related bonus
  • Access to training to help you develop and progress your career
  • Gympass – Access to a range of free and paid options for health and wellness.
  • 25 days holiday, pro rata

  • Principal Engineer

    1 month ago


    England,, UK, United Kingdom Iceberg Cyber Security Full time

    We are looking for a highly skilled Cyber Security Assurance Engineer to join our team and play a crucial role in safeguarding our systems and data. If you hold a Security Clearance and are passionate about protecting critical information, this is the opportunity for you!Key Responsibilities:Conduct comprehensive security assessments and audits to ensure...


  • England,, UK, United Kingdom Dragonfly People Full time

    Application Security SpecialistSecurity | Application | DevSecOps | CI/CD | Burp Suite | Penetration Testing | Vulnerability Management | Fin-TechAn Application Security Specialist is required by a rapidly growing consumer Fin-Tech business who are based in London. The Application Security Specialist will need to have advanced knowledge of secure software...


  • England,, UK, United Kingdom iO Associates - UKEU Full time

    Data/Cloud Security Engineer Fully Remote (UK based) £500 per day, Outside IR35 - 6 month contract Must be eligible to go through SC ClearanceI am currently looking for a Senior Data & Cloud Security Engineer to join a data intelligence company focused on AI, Machine Learning, and Secure Cloud solutions. You will oversee the AWS cloud infrastructure and...

  • Senior Engineer

    1 week ago


    England,, UK, United Kingdom Candour Solutions Full time

    Senior Engineer – Microsoft Cloud Security – Remote#TeamCandour are working with a thriving Microsoft Gold Partner to build out their team offering consultancy services in the areas of Cloud / Azure / Microsoft Security. These roles would suit accomplished senior engineers working with tech like Defender / Sentinel / Identity looking to develop their...


  • England,, UK, United Kingdom IC Resources Full time

    IC Resources is seeking an Embedded Software Solutions Engineer to join a leader in MCU solutions. This role will have a focus on their MCU product line as well as Embedded Security applications covering key accounts across the UK, Ireland and parts of Benelux. Ideally you will have experience with MCUs as well as Embedded C and are eager to interact with...

  • Application Engineer

    3 weeks ago


    England,, UK, United Kingdom New Iron, Inc. Full time

    Application EngineerNew Iron is leading the search for Application Engineer in the UK to deploy and support our client’s process control and maintenance software.The ideal candidate for this position possesses a strong analytical background, hands-on experience in semiconductor manufacturing, familiarity with external sensors, and basic knowledge of...


  • England,, UK, United Kingdom 55 Exec Search Full time

    Senior Security Consultant – Operational Technology (OT) REMOTE - Travel as required Do you want to work for a consulting firm with multiple industry accreditations and certifications, growing significantly and offering each employee an annual training budget to expand on your skillset and knowledge in areas you choose?Our client is a global growing...


  • England,, UK, United Kingdom Akkar Full time

    On behalf of a globally established provider of professional services, I'm hiring OT Security Talent for multiple positions including Senior Manager and Assistant Manager.If you're an OT Security Leader open to hearing about new opportunities, please do consider applying, and I'll reach out with the full description.Until then, here would be some...


  • England,, UK, United Kingdom acre security Full time

    Are you passionate about shaping the future of security solutions? Do you thrive in an environment that values innovation and teamwork? If so, acre security is the place for you! Join us in making the world a safer place, one innovation at a time.Position: Channel Business Manager (UK)Location: UK (South)A Bit About Us: At acre, we're not just creating...


  • England,, UK, United Kingdom Cyber Nexus Full time

    Cyber Nexus are proud to be partnering with highly reputable, industry leading information security company who are currently looking to hire a managing information security consultant. This is an exciting opportunity to work closely with the information security consulting manager to help lead, build and develop the security consulting team. Furthermore,...


  • England,, UK, United Kingdom Fruition IT Full time

    Senior Backend Engineer (Go)Remote, UK6 Month Contract An incredible opportunity for an experienced Senior Backend Engineer with advanced Go skills to join a prestigious tech client on a contract basis. This company is renowned for its engineering excellence, and they're looking for a Senior Backend Engineer who can take their distributed systems to the...


  • England,, UK, United Kingdom Eurobase People Full time

    Our client is within the housing association industry and they have offices countrywide, they are looking for a Senior Software Engineer on a permanent basisThe role is 90% Remote The role works in a function that is responsible for the design, delivery, maintenance, and support of the software and underlying microservice based architecture (N.B. management...


  • England,, UK, United Kingdom developrec Full time

    Senior Software Engineer- Contract- Inside IR35- £550- Midlands/RemoteOur client a household FTSE 100 brand are looking to hire a number of contract Senior Software Engineers to join a number of projects they need to deliver before the end of the financial year.We are looking for Engineers with the following experience for one project;C#.NET...


  • England,, UK, United Kingdom F5 Consultants Full time

    Job Title: Principal Security Architects x 2Location: North England (3 days a week onsite, more details discussed on call)Role: Full Time, PermanentSalary: £100,000+ (Flexible DOE)Preferred Start: ASAPClearance: Active DV ClearanceF5 are delighted to be partnering with one of the fastest growing Cyber Security Consultancies in the UK, an award-winning...


  • England,, UK, United Kingdom 55 Exec Search Full time

    Our client is a global cyber security solution, services and support advisory business, that is expanding the cyber GRC team.They are seeking a Senior PCI DSS Security Consultant who has in-depth PCI DSS knowledge with aspirations to become a PCI QSA.The ideal candidate will have a broad range of cyber risk advisory skills (PCI DSS, ISO27001, GDPR, Data...


  • England,, UK, United Kingdom Cognitive Group | Part of the Focus Cloud Group Full time

    SENIOR TECHNICAL SALES SPECIALIST MICROSOFT SECURITY HYBRID WORKING - LONDON OFFICE I'm working with a recognised, global consultancy who provide services across multi-disciplinaries. There is an opportunity for a highly motivated Senior Technical Sales Specialist to focus on solutioning their range of Microsoft Security technology and advisory services...

  • Software Engineer

    4 weeks ago


    England,, UK, United Kingdom Shift F5 - Technology Recruitment Full time

    We're currently recruiting several Mid-Level Developers for a FinTech company revolutionising payments within the Life Sciences space. They develop innovative financial solutions that streamline trasnactions and empower all stakeholders involved in clinical research. They're a passionate team working at the forefront of finance and healthcare...


  • England,, UK, United Kingdom McDermott International, Ltd Full time

    The role is for a Senior Civil Underground Engineer with a market leading provider of Oil & Gas, LNG and Renewable facilities. Deliverables to include undergrounds drainage design and drawings, utilities, paving, roads, specifications, design philosophies etc. Work includes discipline support, concept studies, layouts, design calculations, specifications and...


  • England,, UK, United Kingdom Synapri Full time

    Sector: Public Sector / Government / Law EnforcementJob Title: AWS DevOps EngineerDuration: 12 months + Type: ContractLocation: Remote WorkingClearance: Need to have SC security clearance (ideally NPPV3 also)The DevOps is responsible for maintaining and supporting our platforms. Agile in nature, predominantly working in a SCRUM or Kanban methodology, the...


  • England,, UK, United Kingdom RED Engineering Design Full time

    Senior Control Systems Engineer - London, Bicester or NewcastleRED are an expanding international M&E consultancy, with a proven track record in low energy design, focused on providing excellent design solutions to clients.Through our market leading technical expertise, we enable the world’s digital infrastructure and develop the built environment whilst...