Application Security (AppSec) Engineer

AND Digital

London

On-site

GBP 60,000 - 80,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A digital technology firm in London is seeking an experienced Application Security Engineer to enhance their security posture. This role involves managing core technical application security, contributing to compliance audits, and supporting security training. Ideal candidates have strong experience in application security concepts and tools with a minimum of 3 years in a relevant role. The position is full-time and encourages a proactive, collaborative work environment.

Qualifications

  • A minimum of three years of hands-on experience in an Application Security or similar technical security-focused role.
  • Strong understanding of application security concepts and secure development lifecycles.
  • Experience with a range of security tools and technologies.

Responsibilities

  • Take ownership of the security of core technical applications.
  • Contribute to internal and external audits related to ISO:27001.
  • Develop and maintain training materials for the security champion programme.
  • Contribute to the creation and improvement of security policies.
  • Identify and manage vulnerabilities within the application landscape.

Skills

Application Security
SAST
SDLC
OWASP Top 10
Vulnerability Management
Communication Skills

Tools

Gitlab
Atlassian products (Jira, Confluence)

Job description

Overview

Who We Are AND Digital is a tech company dedicated to accelerating digital delivery and closing the digital skills gap. Since 2014, we have supported organisations in building better digital products and stronger digital teams. We believe our work should always create a remarkable impact for our clients. Through our regional offices, known as ‘Clubs,' we build strong relationships with our partners, ensuring they are prioritised by teams located nearby. This unique model has driven success for both our clients and ourselves, reflected in our remarkable organic growth since 2014. Today, we are over 1,300 people strong, with Clubs across the UK, Europe, and the USA—and plans for global expansion in the coming years. Join us and help fulfil our mission to close the world\'s digital skills gap.

The Role Application (AppSec) Security Engineer. We are seeking an experienced and proactive Application Security Engineer to join our SecOps team. The team is responsible for maintaining the AND wide Security Champion program, responding to security threats and incidents, improving AND security posture, fulfilling compliance requirements and supporting improving AND\'s business platforms security posture. The ideal candidate will be a technical specialist with a passion for securing applications across the full development lifecycle. This role is a key part of our commitment to enhancing security posture and will focus on managing and improving the security of a diverse set of applications, from commercial off-the-shelf products to our own internally developed services. You\'ll be a self-starter who is eager to drive change and continuously develop your skills in a dynamic environment.

Key Responsibilities
  • Application Management: Take ownership of the security of core technical applications, including Gitlab, Atlassian products (Jira, Confluence), and other niche, internally built services.
  • Compliance & Audits: Aid in the preparation for, and contribute to, internal and external audits, particularly in relation to the ISO:27001 standard.
  • Security Champion Programme: Develop and maintain content and training materials for the security champion programme, providing guidance and support to development teams to foster a culture of security.
  • Policy & Process Contribution: Actively contribute to the creation, distribution, and continuous improvement of internal security policies and processes.
  • Vulnerability Management: Identify, triage, and manage vulnerabilities within the application landscape, working closely with engineering teams to ensure timely remediation.
Required Experience & Skills
  • A minimum of three years of hands-on experience in an Application Security or similar technical security-focused role (SAST, SCA, DAST, IaC etc). We are open to diverse backgrounds.
  • Strong understanding of application security concepts, secure development lifecycles (SDLC), and common vulnerabilities and attack vectors (e.g., OWASP Top 10).
  • Experience with a range of security tools and technologies.
  • Familiarity with compliance frameworks, particularly ISO:27001, is highly desirable.
  • Excellent communication skills, with the ability to articulate technical security concepts to both technical and non-technical audiences.
Desired Attributes
  • Eagerness to Learn: A demonstrable passion for continuous self-development and staying current with the latest security threats and technologies.
  • Coaching and Mentoring: Demonstrates true willingness to upskill and mentor others.
  • Proactive Mindset: A self-starter who can identify opportunities for improvement and take initiative to implement solutions.
  • Collaborative Spirit: The ability to work effectively with cross-functional teams and build strong working relationships.
  • Problem-Solving: Strong analytical and problem-solving skills, with a methodical approach to security challenges.
Equal Opportunities Statement

We are an equal opportunity employer and welcome applications from all qualified candidates. We actively encourage applications from women, ethnic minorities, and individuals with disabilities. We consider all flexible working arrangements, subject to the requirements of the role. Where reasonable adjustments are needed, we will strive to make changes to accommodate them.

Seniority level
  • Not Applicable
Employment type
  • Full-time
Job function
  • Information Technology
Industries
  • IT Services and IT Consulting
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Fullstack Product Developer
Senior Fullstack Product Developer

AND Digital • Bristol

Hybrid
GBP 45,000 - 75,000
26 days holiday allowance + bank holidays
Flexible bank holidays
£1000 flexifund for personalized benefits
+4
Application Security Engineer
Application Security Engineer

Ignite Digital • Greater London

Hybrid
GBP 90,000 - 120,000
Competitive Salary + Bonus
25 days of annual leave
Private medical and dental cover
+4
Senior Application Security Consultant
Senior Application Security Consultant

Salt • Greater London

Hybrid
GBP 90,000 - 120,000
Application Security Architect (Manchester)
Application Security Architect (Manchester)

Insight Investment • Manchester

On-site
GBP 70,000 - 100,000
Senior Application Security Manager
Senior Application Security Manager

United States Digital Space LLC • Greater London

Hybrid
GBP 120,000 - 180,000
Company card
Lunch provided
Private healthcare
+4
Lead Identity & Security Engineer (12 Month FTC)
Lead Identity & Security Engineer (12 Month FTC)

Hire Digital • Greater London

Hybrid
GBP 110,000 - 140,000
Blended working
Career development
Training budget
+1
Security Assurance Lead
Security Assurance Lead

Cambridge University Press & Assessment • Cambridgeshire and Peterborough

Hybrid
GBP 55,000 - 73,000
28 days leave
Private medical insurance
Permanent Health Insurance
+5
Senior Application Security Specialist
Senior Application Security Specialist

La Fosse • Greater London

Hybrid
Security Architect
Security Architect

Solirius Ltd. • Greater London

On-site
GBP 90,000 - 120,000
Competitive Salary
Bonus Scheme
Private Healthcare Insurance
+2
Senior Application Security Analyst - L3
Senior Application Security Analyst - L3

Global Relay • Greater London

On-site
GBP 90,000 - 130,000