Application Security Engineer

Centrica

Windsor

Hybrid

GBP 90,000 - 120,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Employee Energy Allowance
Company pension
Healthcare plan
25 days holiday

Job summary

Centrica is a family of brands energising a greener, fairer future and driving secure software delivery across multi-cloud environments. We are seeking an experienced Application Security Engineer to embed security in the development process, focusing on AWS, Azure DevOps and modern DevSecOps tooling.

Location: UK-based hybrid role with occasional travel to site. You will collaborate with engineering, platform and security teams to reduce risk, define standards, and enable secure, automated

Qualifications

  • Strong hands-on experience in application security.
  • Proficiency in Python or JavaScript with security automation experience.
  • Experience across cloud platforms such as AWS and Azure.
  • Solid understanding of secure SDLC, OAuth2/OIDC/SAML and API security.
  • CI/CD security integration in DevOps environments, including Azure DevOps and GitHub Actions.
  • Desirable certifications: GWAPT, GWEB, OSCP or AWS Security Specialty.

Responsibilities

  • Weave security best practices into the software development lifecycle with DevOps and engineering teams.
  • Provide guidance on secure design, implementation and architecture (API security, microservices, cloud-native).
  • Carry out ongoing manual security assessments and coordinate third-party engagements as needed.
  • Review SAST/DAST/SCA outputs; drive remediation to closure with clear ownership.
  • Provide on-demand application security support and drive tooling/process improvements.
  • Lead or contribute to the Security Champions programme and collaborate with GSOC/CSIRT.

Skills

Application security
OWASP Top 10
Python
JavaScript
AWS
Azure
DevSecOps
CI/CD security
Security automation
Security Champions

Tools

SAST
DAST
SCA
CycloneDX
Trivy
Terraform
Bicep
Ansible

Job description

Join us, be part of more.

We're so much more than an energy company. We're a family of brands revolutionising how we power the planet. We're energisers. One team of 21,000 colleagues that's energising a greener, fairer future by creating an energy system that doesn't rely on fossil fuels, whilst living our powerful commitment to igniting positive change in our communities. Here, you can find more purpose, more passion, and more potential. That's why working here is #MoreThanACareer. We do energy differently - we do it all. We make it, store it, move it, sell it, and mend it.

An opportunity to play your part - Are you passionate about building security into the heart of modern software delivery? We're looking for an experienced Application Security Engineer to help strengthen secure development practices across Centrica's multi-cloud environment, with a key focus on AWS, Azure DevOps and modern DevSecOps tooling. This is a brilliant opportunity to work closely with engineering, platform and security teams to reduce risk, improve our security posture and make secure, automated and scalable delivery feel like second nature. You'll help define and embed application standards, champion developer enablement and play an important role in shaping Centrica's wider security capability. If you love the idea of helping teams move fast without leaving security behind, this role gives you the chance to bring your expertise, curiosity and practical problem-solving to work that really matters.

Location: UK-based hybrid role, Occasional travel to site.

Day to day -
  • Collaborate with DevOps and engineering teams to weave security best practice into the software development lifecycle, helping teams deliver at pace without compromising on protection.
  • Provide practical guidance on secure design, implementation and architecture, including API security, microservices patterns and cloud-native application security.
  • Carry out ongoing manual security assessments, coordinate third-party engagements where needed, and turn findings into clear, prioritised actions.
  • Review SAST, DAST and SCA outputs, driving remediation through to closure and keeping tracking, ownership and prioritisation firmly on course.
  • Provide on-demand application security support while driving continuous improvement across processes, tooling and ways of working, making security simpler, smarter and more scalable.
  • Lead or contribute to the Security Champions programme and work closely with GSOC and CSIRT teams on application-layer security incidents, helping build a strong, distributed security culture across engineering.
What you would bring -
  • Strong hands-on experience in application security, with a solid understanding of secure software development, OWASP Top 10, common application vulnerabilities and secure SDLC practices.
  • Proficiency in one or more programming languages, such as Python or JavaScript, with experience using code to support security automation, tooling, custom rule development or other clever ways to make security scale.
  • Experience working across cloud platforms such as AWS, Azure or SAP, alongside a good understanding of modern application architectures, container security, API security, network protocols and identity frameworks such as OAuth 2.0, OIDC and SAML.
  • A strong working knowledge of DevOps pipelines, repositories and CI/CD security integration, including platforms such as Azure DevOps and GitHub Actions, with the confidence to bring security into delivery without slowing everyone down.
  • Practical experience with security tooling and practices including SAST, DAST, SCA, container scanning, vulnerability management, SBOM tooling such as CycloneDX, IaC security across Terraform, Bicep, Ansible and tools such as Trivy, plus Policy as Code and threat modelling.
  • A proactive, curious and collaborative approach, with the ability to guide engineering teams, support third-party supply chain security and make complex topics feel practical; desirable extras include certifications such as GWAPT, GWEB, OSCP or AWS Security Specialty, Security Champions or developer training experience, and exposure to SOC or Incident Response environments.
What's in it for you?
  • Enjoy a generous market salary, along with fantastic growth opportunities and a vibrant work environment!
  • Power up your pay with a 15% Employee Energy Allowance, surpassing the government's price cap!
  • Secure your future with our comprehensive pension plan, designed for peace of mind.
  • Elevate your health with our fully-funded company healthcare plan, prioritizing your well-being.
  • Recharge with a generous 25-day holiday allowance, plus public holidays, and even purchase up to 5 extra days for extended relaxation!
  • Experience unparalleled work-life balance with an exceptional selection of flexible benefits, from tech treats and eco-friendly car leases to travel insurance for your adventures!
Why should you apply?

We're not a perfect place - but we're a people place. Our priority is supporting all of the different realities our people face. Life is about so much more than work. We get it. That's why we've designed our total rewards to give you the flexibility to choose what you need, when you need it, making sure that you and your family are supported not only financially, but physically and emotionally too. Visit the link below to discover why we're a great place to work and what being part of more means for you.

https://www.morethanacareer.energy/centrica

If you're full of energy, fired up about sustainability, and ready to craft not only a better tomorrow, but a better you, then come and find your purpose in a team where your voice matters, your growth is non-negotiable, and your ambitions are our priority.

Help us, help you. We would love for you to share any information about yourself throughout our recruitment process so that we can better understand you and help shape your journey.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Centrica • Clewer Village

Hybrid
GBP 70,000 - 100,000
Market salary
Energy allowance 15%
Pension plan
+3
Application Security Engineer
Application Security Engineer

Centrica plc • Windsor

Hybrid
GBP 70,000 - 90,000
15% Employee Energy Allowance
Company pension
Fully-funded healthcare
Information Security Third Party Assurance Analyst
Information Security Third Party Assurance Analyst

Centrica plc • United Kingdom

Hybrid
GBP 55,000 - 75,000
15% Energy Allowance
Pension Plan
Healthcare Plan
+1
Information Security Third Party Assurance Analyst
Information Security Third Party Assurance Analyst

Centrica • Windsor

On-site
GBP 60,000 - 82,000
15% Employee Energy Allowance
Pension plan
Healthcare – fully funded
+3
Domain Architect (Energy Supply)
Domain Architect (Energy Supply)

Centrica plc • United Kingdom

Hybrid
GBP 90,000 - 130,000
Car allowance
Employee Energy Allowance 15%
Company pension
+2
OT Analyst/Technician
OT Analyst/Technician

Centrica plc • United Kingdom

Hybrid
GBP 60,000 - 90,000
Mechanical Engineer
Mechanical Engineer

Centrica plc • United Kingdom

Hybrid
GBP 75,000 - 110,000
Mechanical Engineer
Mechanical Engineer

Centrica plc • Hessle

Hybrid
GBP 65,000 - 90,000
OT Analyst/Technician
OT Analyst/Technician

Centrica • Windsor

Hybrid
GBP 60,000 - 85,000
Senior Business Analyst
Senior Business Analyst

Centrica • Windsor

On-site
GBP 60,000 - 85,000