Application Security Engineer

CloudBees

Greater London

Hybrid

GBP 65,000 - 105,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

CloudBees in London, UK, is seeking a hands-on security-minded engineer to lead secure SDLC and AI security initiatives in a hybrid role.

You will develop secure patterns, perform threat modeling, and guide teams on secure practices for AI, low-code, and enterprise systems.

Travel is required; we offer a diverse, inclusive culture and opportunities to advance in DevSecOps across Jenkins, Cloud, and CI/CD.

Qualifications

  • Hands-on security experience in software and enterprise environments.
  • Knowledge of SaaS, cloud, IAM, or endpoint security is desirable.
  • Proficiency in secure SDLC fundamentals including threat modelling and CI/CD security.
  • Comfort writing code in Python, Go, or TypeScript.
  • Experience building integrations and automating security workflows.
  • Experience with security tools such as SAST, DAST, SIEM, and vulnerability management platforms.

Responsibilities

  • Develop secure SDLC standards for internal apps and AI workflows.
  • Create patterns, reference architectures, and self-serve documentation for teams.
  • Raise security profile with business teams, especially for AI and low-code.
  • Conduct threat modeling, risk assessments, and technical security reviews.
  • Identify and prioritize security risks; advise on mitigations.
  • Translate findings into enterprise controls and detection requirements.
  • Design safeguards for enterprise AI tooling, including agents and non-human identities.
  • Evaluate and integrate emerging AI/ML security tools.
  • Stay current with the AI security landscape.
  • Engineer and automate AI-first security workflows at scale.

Skills

Hands-on security experience
Secure SDLC knowledge
Threat modelling
Secure design
Vulnerability management
CI/CD security
Python
Go
TypeScript
Automation of security workflows
SAST/DAST/ SIEM experience
AI/ML security knowledge
Generative AI tools familiarity
Communication skills
Interpersonal skills
Self-starter
Ambiguity tolerance

Tools

Jenkins
Python
TypeScript
CI/CD
Cloud
DevSecOps
IAM
Security tooling

Job description

Salary: £65,000 - 105,000 per year

Requirements
  • Hands-on experience in software and enterprise security
  • Working knowledge in any of SaaS, cloud, IAM, or endpoint security is desirable
  • Proficiency in secure SDLC fundamentals, including threat modelling, secure design, vulnerability management, and CI/CD security
  • Comfortable writing and reviewing code in Python, Go, TypeScript, or similar
  • Experience building integrations and automating security workflows
  • Experience with security tools at scale, including SAST, DAST, SIEM, endpoint, cloud, identity, AI/ML, and vulnerability management platforms
  • Understanding of AI/ML security risks, attack vectors, and vulnerabilities
  • Familiarity with agentic AI frameworks and generative AI tools
  • Exceptional written and verbal communication skills, with the ability to translate complex security concepts for any audience
  • Strong interpersonal skills, with the ability to build trust and credibility quickly across technical and non-technical teams
  • Self-starter with initiative and ownership
  • Hacker mindset: figures out the problem, then solves it
  • Thrives in ambiguity
Responsibilities
  • Develop secure SDLC standards for internal apps and AI workflows
  • Build patterns, reference architectures, and documentation that enable teams to self-serve
  • Work with business teams to raise the profile of security and adopt secure practices, especially for AI and low-code
  • Conduct threat modeling, risk assessments, and technical security reviews for enterprise systems, internal apps, and AI and agentic deployments
  • Identify and prioritize security risks, and advise risk, compliance, audit, and business teams on mitigations
  • Translate findings into actionable enterprise controls and detection requirements
  • Design safeguards for enterprise AI tooling, including agents and non-human identities
  • Evaluate and integrate emerging AI/ML security tools
  • Stay current with the AI security landscape
  • Engineer and automate AI-first security workflows that scale the wider Security team
  • Build for the enterprise domain in a way that benefits Product Security, SOC, and GRC
Technologies
  • Agentic AI
  • AI
  • CI/CD
  • Cloud
  • DevSecOps
  • IAM
  • Support
  • Jenkins
  • Python
  • Security
  • TypeScript
More:

We are CloudBees, and we enable enterprises to deliver scalable, compliant, and secure software while empowering developers to do their best work. We integrate into hybrid and heterogeneous environments and support organizations across their DevSecOps journey, whether they use Jenkins on-premise or transition software delivery to the cloud. This is a full-time hybrid role based in London, UK, with travel required. We are committed to equal opportunities, diversity, and inclusion, and adjustments will be considered to accommodate individual needs in line with applicable equality and disability legislation.

last updated 36 week of 2026

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Engineer
Security Operations Engineer

CloudBees • Greater London

Hybrid
GBP 65,000 - 105,000
Application Security Engineer
Application Security Engineer

Hargreaves Lansdown • West of England

Hybrid
GBP 62,000 - 90,000
Hybrid working (2 days in Bristol)
Discretionary annual bonus
Pension contributions up to 11%
+4
AI-Savvy Application Security Engineer
AI-Savvy Application Security Engineer

CloudBees • Greater London

Hybrid
GBP 65,000 - 105,000
Senior Cloud & AI Security Enablement Engineer
Senior Cloud & AI Security Enablement Engineer

RELX Group • Exeter

On-site
GBP 45,000 - 85,000
Generous holiday allowance
Life assurance
Pension scheme
+2
Application Security Engineer JavaScript
Application Security Engineer JavaScript

Client Server • City Of London

Hybrid
GBP 72,000 - 88,000
Equity
Bonus
Lead Cybersecurity
Lead Cybersecurity

The Placement Group • Greater London

On-site
GBP 66,000 - 106,000
Senior Application Security Engineer
Senior Application Security Engineer

Hackajob Ltd • Chesterton

Hybrid
GBP 60,000 - 75,000
Wellbeing allowance
Private health insurance
Paid time off
+1
Software Security Engineer
Software Security Engineer

Data Science Festival • Greater London

Hybrid
GBP 90,000 - 150,000
Hybrid working model
Pension scheme
Generous holiday allowance
Senior Security Engineer
Senior Security Engineer

Data Science Festival • Greater London

Hybrid
GBP 100,000 - 135,000
Generous holiday allowance
Pension scheme
Ongoing learning and professional development
+2
Security Engineer - AI and Emerging Technologies
Security Engineer - AI and Emerging Technologies

Harrington Starr • Greater London

Hybrid
GBP 85,000 - 110,000
Hybrid work environment
Exposure to senior stakeholders
Career development opportunities
+1