Application Security Engineer UK or Europe Remote
Job Title: Application Security Engineer
Job Type: Permanent
Location: UK or Europe (Remote)
Salary: $150,000 – $180000
About the Role
My client is seeking an Application Security Engineer to strengthen our security posture by identifying vulnerabilities, integrating best practices into CI/CD pipelines, and ensuring compliance with PCI DSS, SOC 2, GDPR, and CCPA. You’ll work closely with development teams to embed security into the Software Development Lifecycle (SDLC) from the ground up. If you’re passionate about securing applications and solving complex security challenges, we want to hear from you!
Key Responsibilities
- Conduct security reviews and threat modeling during the application design phase.
- Perform static and dynamic application security testing (SAST/DAST) on internal and third-party applications.
- Define and maintain security standards for software development.
- Integrate security tools and processes into CI/CD pipelines.
- Conduct code reviews to identify vulnerabilities and ensure compliance with security best practices.
- Collaborate with engineers to design and implement secure coding practices.
- Investigate and remediate security incidents related to applications.
- Provide training and guidance to developers on secure coding principles.
- Represent the security posture of applications to key stakeholders, including customers.
What You Bring
- 5+ years of experience in application security or a related field.
- Strong understanding of OWASP Top 10 and common application vulnerabilities.
- Proficiency in at least one programming language (C# (.NET preferred), JavaScript frameworks, SQL Server, or mobile development languages).
- Hands-on experience with security testing tools (e.g., Veracode, Snyk, OWASP ZAP, Burp Suite).
- Strong knowledge of secure coding practices and secure SDLC methodologies.
- Experience in cloud security (Azure preferred) and securing cloud-native applications.
- Familiarity with CI/CD security integration.
- Understanding of compliance and regulatory frameworks (SOC 2, GDPR, PCI DSS).
Preferred Skills
- Experience with container security and Kubernetes.
- Knowledge of infrastructure security and security monitoring.
- Familiarity with Jira for issue tracking and Notion for documentation.
- Experience working in cross-functional teams in a fast-paced environment.
- Security certifications such as CSSLP, CISSP, OSCP, CEH, or GWEB are a plus.
How to Apply
Submit your CV or contact Ash Ali directly for immediate consideration.