Application Security Engineer

Source Group International

Greater London

Hybrid

GBP 68,000 - 108,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Source Group International is seeking a cybersecurity engineer with strong application security and web development experience to join our growing Information Security team in London. The role emphasizes secure SDLC practices, vulnerability mitigation, and collaboration with developers to deliver secure code quickly.

You will work with OWASP, threat modelling, AI-enabled security, and cloud platforms (Azure/AWS).

Qualifications

  • We are looking for a cybersecurity engineer with expertise in the application security domain.
  • Strong application security and web application development experience.
  • Team leadership skills and the ability to join a growing Information Security team.
  • Deep understanding of OWASP, CWE 25, data protection, access management, software vulnerabilities, best-practice design, and threat modelling.
  • Experience working with developers to produce secure code in short time frames.
  • A Computer Science or Cyber Security degree.
  • An application development background.
  • Azure DevOps experience.
  • Prior experience using AI models and cyber harnesses to support security evaluation of application and software code.
  • Experience with GitHub, Copilot, Codex, OWASP Top 10 for Agentic AI, AI skills development, and security triage.
  • Ability to code in Python, JavaScript, C#, or PowerShell.
  • Preference for experience in large organisations or Financial Services.
  • Excellent analytical skills and attention to detail.
  • CISSP, CSSLP, CEH, OSCP, or similar certification.
  • Presentation skills and ability to explain complex solutions to a less technical audience.
  • Strong interpersonal, teamwork, communication, and collaboration skills.
  • Excellent written and spoken English.
  • Passionate about developing a career in Information Security.
  • Inspired by agile leadership, continuous improvement, and problem solving.

Responsibilities

  • Define consistent Secure Software Development Lifecycle practices for technology projects throughout planning and delivery.
  • Help ensure application security vulnerabilities are mitigated to tolerable levels.
  • Work with software and security engineers to design, maintain, and build product security tools and services.
  • Act as the technical point of contact for product teams on automation, CI/CD, and Product Application Security Operations.
  • Use approved AI models and cyber harnesses to assess application code for business logic weaknesses, misconfiguration, and vulnerabilities.
  • Build tools and automation scripts that help developers consume security services delivered by the Security Engineering and Automation team.
  • Be responsible for security product QA and testing.
  • Build strong relationships with product development teams.
  • Run software composition analysis (SCA) tools.
  • Explain penetration testing findings to software engineering teams and help triage and mitigate risks.
  • Articulate business risk when assessing software vulnerabilities.
  • Continuously improve the operations of SAST, DAST, and IaC security tools.
  • Continuously improve the operations of Web Application Firewalls (WAF) or IDS.
  • Continuously improve security tooling coverage in cloud environments such as Microsoft Azure and Amazon AWS.

Skills

Cybersecurity
Application Security
Team Leadership
Threat Modelling
OWASP
Data Protection
Security Automation
AI in security
Python
JavaScript
PowerShell
C#
Azure
GitHub
Copilot
Codex

Education

Bachelor's degree in Computer Science or Cyber Security

Tools

Azure DevOps
GitHub
Copilot
Codex
CI/CD
WAF
SAST
DAST
IaC security
AI models

Job description

Salary: £68,000 - 108,000 per year

Requirements
  • We are looking for a cybersecurity engineer with expertise in the application security domain.
  • We need strong application security and web application development experience.
  • We need team leadership skills and the ability to join a growing Information Security team.
  • We need deep understanding of OWASP, CWE 25, data protection, access management, software vulnerabilities, best-practice design, and threat modelling.
  • We need experience working with developers to produce secure code in short time frames.
  • We need a Computer Science or Cyber Security degree.
  • We need an application development background.
  • We need Azure DevOps experience.
  • We need prior experience using AI models and cyber harnesses to support security evaluation of application and software code.
  • We need experience with GitHub, Copilot, Codex, OWASP Top 10 for Agentic AI, AI skills development, and security triage.
  • We need the ability to code in at least one programming language, such as Python, JavaScript, C#, or PowerShell.
  • We prefer prior experience in a large organisation or Financial Services.
  • We need excellent analytical skills and attention to detail.
  • We need a CISSP, CSSLP, CEH, OSCP, or similar certification.
  • We need presentation skills and the ability to explain complex solutions to a less technical audience.
  • We need strong interpersonal, teamwork, communication, and collaboration skills.
  • We need excellent written and spoken English.
  • We want someone passionate about developing a career in Information Security.
  • We want someone who is inspired by agile leadership, continuous improvement, and problem solving.
Responsibilities
  • Define consistent Secure Software Development Lifecycle practices for technology projects throughout planning and delivery.
  • Help ensure application security vulnerabilities are mitigated to tolerable levels.
  • Work with software and security engineers to design, maintain, and build product security tools and services.
  • Act as the technical point of contact for product teams on automation, CI/CD, and Product Application Security Operations.
  • Use approved AI models and cyber harnesses to assess application code for business logic weaknesses, misconfiguration, and vulnerabilities.
  • Build tools and automation scripts that help developers consume security services delivered by the Security Engineering and Automation team.
  • Be responsible for security product QA and testing.
  • Build strong relationships with product development teams.
  • Run software composition analysis (SCA) tools.
  • Explain penetration testing findings to software engineering teams and help triage and mitigate risks.
  • Articulate business risk when assessing software vulnerabilities.
  • Continuously improve the operations of SAST, DAST, and IaC security tools.
  • Continuously improve the operations of Web Application Firewalls (WAF) or IDS.
  • Continuously improve security tooling coverage in cloud environments such as Microsoft Azure and Amazon AWS.
Technologies
  • Agentic AI
  • AI
  • AWS
  • Azure
  • C#
  • CI/CD
  • Cloud
  • Copilot
  • DevOps
  • GitHub
  • Support
  • JavaScript
  • LESS
  • OWASP
  • PowerShell
  • Python
  • Security
  • WAF
  • Web
More

We are a global investment manager helping institutions, intermediaries, and individuals around the world invest money to meet their goals, fulfil their ambitions, and prepare for the future. We have around 5,000 people across six continents and have been established for over 200 years, while continuing to adapt as society and technology change. What does not change is our commitment to helping clients and society prosper. This is a contract inside IR35 role based in London on a hybrid working pattern.

last updated 37 week of 2026

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Hargreaves Lansdown • West of England

Hybrid
GBP 62,000 - 90,000
Hybrid working (2 days in Bristol)
Discretionary annual bonus
Pension contributions up to 11%
+4
Application Security Specialist
Application Security Specialist

Experis - ManpowerGroup • Greater London

Hybrid
GBP 75,000 - 110,000
Competitive salary
Annual bonus
Car allowance
+7
Application Security Specialist
Application Security Specialist

Experis IT • Greater London

Hybrid
GBP 90,000 - 120,000
Hybrid working
Competitive salary
Annual bonus
+2
Application Security Engineer JavaScript
Application Security Engineer JavaScript

Client Server • City Of London

Hybrid
GBP 72,000 - 88,000
Equity
Bonus
Application Security Architect (Manchester)
Application Security Architect (Manchester)

Insight • Manchester

On-site
GBP 90,000 - 120,000
Senior Application Security Engineer
Senior Application Security Engineer

Hackajob Ltd • Chesterton

Hybrid
GBP 60,000 - 75,000
Wellbeing allowance
Private health insurance
Paid time off
+1
Security Architect
Security Architect

DLA Piper • Greater London

On-site
GBP 34,000 - 38,000
Application Security Engineer
Application Security Engineer

CloudBees • Greater London

On-site
GBP 65,000 - 105,000
Security Architect
Security Architect

Version 1 • Greater London

Hybrid
GBP 49,000 - 66,000
Flexible/remote working
Private healthcare
Life assurance
+5
Senior Technical Security Consultant
Senior Technical Security Consultant

Accenture • Greater London

Hybrid
GBP 50,000 - 75,000
30 days vacation per year
Private medical insurance
3 extra days of leave for charitable工作