Application Security Engineer

Genomics plc

Oxford, Greater London

Hybrid

GBP 100,000 - 140,000

Full time

15 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Life insurance
Pension
Private medical cover
Cycle to work scheme
Bank your Bank Holidays
Critical illness cover

Job summary

Genomics plc is seeking an experienced Application Security Engineer to own security across multi-tenant AI-enabled data platforms. You will lead threat modelling, design reviews and build tooling that makes secure coding the standard.

You will partner with product, SRE and ML teams to protect sensitive genomic data and ensure resilient cloud deployments. Applicants should have production-grade security engineering experience, hands-on coding in Python/Go/TypeScript, and a track record of

Qualifications

  • Experience within application security in production.
  • Hands-on security engineering across web services, APIs and data interfaces.
  • Experience building and operating security tooling in CI/CD pipelines.
  • Knowledge of multi-tenant architectures and cloud security best practices.

Responsibilities

  • Lead threat modelling and design reviews for new products and infrastructure.
  • Build libraries, patterns and CI/CD guardrails for secure development.

Skills

Application security
Security tooling
CI/CD security
Cloud security
AI in security

Tools

AWS
Kubernetes
LLM tooling
CI/CD tooling

Job description

Important notice to applicants

Genomics is aware of an individual falsely presenting themselves as a representative of Genomics and attempting to recruit candidates on our behalf.

Please be vigilant when responding to recruitment approaches. Genuine communications from Genomics will come from an email address ending in @genomics.com. Emails or other communications relating to recruitment that come from individuals or organisations using a different email domain may not be genuine.

If you receive a recruitment communication and you are unsure, please do not provide personal information. Instead, please reach out to us directly via our form on the Contact Us page.

Why work with us?

The growth of Genomics is partnered with the personal growth of our people. We ensure that all employees have the tools, technologies, benefits, and support systems to develop and flourish. We offer a competitive package of benefits, training opportunities, and initiatives to ensure our employees thrive.

Be part of a globally diverse team

Our workforce operates across the UK and US from offices based in Oxford, UK, London, UK Cambridge, UK, and North Carolina, US.

Our diversity and multinationalism, with our people hailing from over 30 countries, helps to bring together the best minds to harness the power of genomics and transform healthcare and drug discovery.

Perks and benefits

Life insurance

Charities trust

Pension

Group income protection

Cycle to work scheme

Critical illness cover

Private medical cover

Bank your Bank Holidays

A collaborative andsocial culture

Social events

Training and development opportunities

Organised sports activities

Join our team
Application Security Engineer
Location

London; Oxford

Location Type

Hybrid

Department

Location: Oxford or London (Hybrid)

The Mission: Why We Exist

Genomics is a science-led transatlantic TechBio combining large-scale genetic and health data with proprietary analytics to accelerate drug discovery and advance predictive, preventative healthcare. We are united by a single vision to help people live longer, healthier lives, using the power of genomics.

Genomics aims to help people live longer, healthier lives in two ways: super-charging drug discovery and development for novel treatments with our AI-enabled advanced genetic analytics platform, and by helping people understand their personal risk of common chronic diseases through polygenic risk scores - giving doctors and health systems the chance to get the right people into the right prevention, screening and treatment programmes at the right time.

Role Purpose

Genomic data is some of the most sensitive data there is, and our customers trust us with it. As Senior Application Security Engineer on Mystra, you'll own application security end-to-end across multi-tenant, trillion-row-scale, AI-enabled data platforms.

You'll lead threat modelling and design review with product teams, build the tooling and patterns that make secure codet, and find and fix the vulnerabilities that slip through. You'll do it with security-focused AI tooling, steered by your own expert judgement and intuition, to keep Genomics secure against state-of-the-art threats.

A Day in the Life

Leading threat modelling and design reviews for new products and infrastructure, and defining the security invariants every team builds against: tenant isolation, authentication and authorisation, secrets, least privilege, and trust boundaries

Building the libraries, patterns, and CI/CD guardrails that make the secure way the easy way, and deciding what is enforced versus advised

Building and tuning AI tooling for code analysis, triage, and remediation, and deciding where its output can be trusted and where it must be verified

Hunting for vulnerabilities through code review, testing, and proof-of-concept exploits, then running the disclosure programme and driving every finding through to a verified fix

Securing our agentic and AI surfaces, from prompt injection and tool boundaries to delegated credentials and tenant-scoped access, and proving the controls hold under adversarial testing

Working as an embedded, trusted partner to product teams, SRE, detection and response, the data platform team, and the MystraAI / ML team, unblocking rather than gating

Who You Are

Experience within application security in production. You've found and fixed exploitable bugs in software you were responsible for, through threat modelling, secure design, code review, and proof-of-concept exploitation across web services, APIs, and data-serving interfaces. Triaging scanner output doesn't count

Production-quality software engineering in at least one mainstream language (such as Python, Go, or TypeScript), and you can read several. You've built and operated security or developer tooling in CI/CD pipelines, such as static and dependency analysis, secrets detection, or policy-as-code, and engineers actually adopted it

Hands-on depth securing multi-tenant systems on a major cloud. We run on AWS (RDS, EC2, S3, EKS, Batch), and comparable GCP or Azure depth transfers. You know tenant isolation, IAM and least privilege, secrets management, Kubernetes and container security, and the trust boundaries between services

Daily use of frontier AI models for code analysis, vulnerability triage, remediation drafting, and research, with sharp judgement about where they're reliable and where they mislead. You've built or tuned LLM-driven tooling rather than only used a chat interface, and you understand the attack surface it introduces

Experience running, or being core to, a vulnerability disclosure or bug bounty programme and the remediation lifecycle behind it, covering severity, prioritisation, SLAs, root cause, and systemic fixes. You've also worked application-layer incidents alongside detection and response, using security telemetry and SIEM data as evidence

Risk-led judgement. You know which designs need deep review, which findings matter and which are noise, and you make accepted risk explicitly so leadership can decide with open eyes

Clear communication. You explain risk and trade-offs precisely to engineers, product, and leadership, write guidance people actually use, and mentor others to grow security capability across teams

Your Package

We are committed to providing a transparent, supportive, and rewarding work environment.

Compensation & Growth

Competitive Reward: Salaries are externally benchmarked annually to ensure market-aligned compensation.

Clear Career Path: A straightforward, open progression framework means you'll always know the path to promotion and how to achieve your next career goal.

Continuous Learning: Including external courses and a wide library of L&D materials, because your growth is our success.

Holiday: 25 days annual leave, plus bank holidays, plus an extra 3-day company-wide shutdown at year-end.

Financial & Health Security: Robust benefits including a market-leading pension scheme, comprehensive private health insurance for you and your family with NO excess, critical illness, and life assurance.

Enhanced Leave: Enhanced paid family leave to support all new parents.

Hybrid Working

Truly Inclusive Time Off: Our 'Bank Your Bank Holiday' program allows you to exchange public holidays for dates that hold personal or cultural significance to you.

Vibrant Social Culture: From regular Town Halls and team picnics to organised sports events, our social committee ensures frequent opportunities to connect and celebrate.

Green Commute: Cycle-to-Work scheme and convenient office locations near major transport hubs.

Ready to Build the Future?

We are dedicated to creating a diverse environment and are proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.

Genomics politely requests no contact from recruitment agencies. We do not accept speculative CVs from recruitment agencies nor accept the fees associated with them.

Contact us at talent@genomics.com or connect with us on LinkedIn.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Genomics Ltd • City Of London

Hybrid
GBP 110,000 - 150,000
Hybrid working
Pension plan
Private health insurance
+2
Application Security Engineer
Application Security Engineer

F-Prime Capital • Greater London

Hybrid
GBP 110,000 - 180,000
Hybrid Working
Bank Your Bank Holiday
Cycle-to-Work
+1
Product Engineer
Product Engineer

F-Prime Capital • Greater London

On-site
GBP 120,000 - 180,000
Project Manager - 6 month Fixed Term Contract
Project Manager - 6 month Fixed Term Contract

Qman • Greater London

On-site
GBP 65,000 - 95,000
Life insurance
Pension
Group income protection
+4
Scientist
Scientist

F-Prime Capital • Greater London

On-site
GBP 40,000 - 60,000
25 days annual leave
Market-leading pension scheme
Comprehensive private health insurance
+3
Data Scientist
Data Scientist

Genomics • Greater London

On-site
GBP 65,000 - 95,000
Hybrid Working (London/Oxford)
Director, Data Strategy & Partnerships
Director, Data Strategy & Partnerships

Genomics • Oxford

Hybrid
GBP 90,000 - 130,000
Hybrid Working
Bank Your Bank Holidays
Pension scheme
+2
Product Manager - Data and Analytics
Product Manager - Data and Analytics

Genomics • Greater London

Hybrid
GBP 70,000 - 110,000
Market-leading pension scheme
Private health insurance (no excess)
Critical illness cover
+2
Product Manager for Data and Analytics on Mystra
Product Manager for Data and Analytics on Mystra

Genomics plc • City of Westminster

Hybrid
GBP 70,000 - 110,000
25 days annual leave
Market-leading pension scheme
Comprehensive private health insurance
Product Manager for Data and Analytics on Mystra
Product Manager for Data and Analytics on Mystra

Genomics plc • City of Westminster

Hybrid
GBP 70,000 - 110,000
25 days annual leave
Market-leading pension scheme
Comprehensive private health insurance