Additional Resources
Senior Application Security Engineer - London
Job Description
Salary: £25,000 - 50,000 per year
Requirements:- We are looking for someone who has previously worked as a Senior Application Security Engineer, Lead Application Security Engineer, Principal Application Security Engineer, Application Security Engineer, Senior Product Security Engineer, Product Security Engineer, Senior DevSecOps Engineer, DevSecOps Engineer, Application Security Consultant or in a similar role.
- We need hands-on experience embedding application security into the SDLC.
- We need experience securing APIs, internet-facing services, and Kubernetes, preferably AKS, and containerised environments.
- We need experience working with engineering teams and implementing security testing tools such as SAST, DAST, IAST and SCA.
- We need knowledge of security automation, security-/policy-as-code, and secure engineering practices including code review, testing, source control and documentation.
- We need familiarity with CI/CD tools such as GitHub and GitHub Actions.
- We need strong skills in Terraform and Python.
- We need a strong understanding of Azure security controls and cloud security governance.
- We need experience with threat modelling in software engineering contexts.
- We need knowledge of ISO 27001 and its relevance to secure engineering.
- We need familiarity with Agile and DevSecOps methodologies.
- You must be eligible to work in the UK.
- We will work closely with engineering and architecture teams to promote secure development from the earliest stages of delivery.
- We will implement and maintain application security testing solutions, enabling developers to identify and remediate security risks.
- We will enhance secure development processes by integrating security controls throughout CI/CD pipelines.
- We will strengthen the security of GitHub Actions and comparable continuous integration and deployment platforms.
- We will provide technical guidance on secure API design and protecting externally accessible systems.
- We will support the security of Azure cloud infrastructure, including Azure Kubernetes Service (AKS).
- We will assist with the protection of cloud-hosted data platforms and associated technologies.
- We will develop and maintain security-as-code and policy-as-code using appropriate tooling.
- We will automate security processes through infrastructure-as-code and scripting technologies.
- We will produce and maintain technical documentation, security procedures and service documentation.
- We will support development teams with the adoption and integration of security tooling and best practices.
- We will contribute to wider cyber security initiatives, including threat modelling and compliance activities.
- API
- Azure
- CI/CD
- Cloud
- DevSecOps
- GitHub
- Support
- Kubernetes
- Python
- Security
- Terraform
More:
We are a well-established health research organisation and charity that supports large-scale medical research to improve disease prevention, diagnosis and treatment. This is a full-time, permanent hybrid role based in Central London, with a salary of 70,000 to 80,000 per annum and an excellent benefits package. The role is a hands-on Application Security position focused on secure design, CI/CD security, cloud-native technologies, Kubernetes, API security, code analysis and security-as-code, working alongside engineering and cloud teams to build, improve and maintain secure applications, platforms and deployment processes. Visa sponsorship is not available.
last updated 37 week of 2026
Interested in this role?
Submit your application now
How to Apply
About Additional Resources
Additional Resources
London
IT
Skills & Technologies
Inferred from job description
Salary Insight
£37,500
This role
£75,000
UK median
This salary is 50% below the UK median for Senior roles (£75,000/yr).
Based on 2024–2025 UK technology sector benchmarks