Enable job alerts via email!

Application Security Engineer in Cambridge

Energy Jobline CVL

Cambridge

Hybrid

GBP 60,000 - 80,000

Full time

Today
Be an early applicant

Job summary

A leading tech firm in Cambridge is seeking an Application Security Specialist to guide teams on security best practices. The role includes collaborating with developers and performing application security testing in a hybrid work environment. Candidates should have significant experience in software engineering and application security, along with strong communication skills. Benefits include private healthcare, pension contributions, and flexible working hours.

Benefits

Private healthcare
Pension contributions
Wellbeing support
Life insurance
Annual performance bonus
Enhanced family leave
25 days holiday plus bank holidays

Qualifications

  • 3+ years in software engineering plus 2+ years in application security.
  • Strong knowledge of OWASP and security testing techniques.
  • Experience with Agile/DevOps methodologies.

Responsibilities

  • Guide teams on security best practices and compliance.
  • Review designs and code for vulnerabilities.
  • Design and integrate security testing plans.

Skills

Secure coding practices
Application security
Collaboration with developers
Threat modeling
Vulnerability management
Communication skills
Job description
Application Security Specialist (DevOps)

Hybrid – Cambridge, UK (1 day a week in office)

What you’ll be doing
  • Guiding teams on security best practices, compliance, and secure coding.
  • Collaborating with architects and developers to review designs and code for vulnerabilities.
  • Embedding/improving threat modelling and secure development practices into the SDLC.
  • Designing and integrating security testing plans.
  • Performing and overseeing application security testing and driving remediation.
  • Managing end-to-end vulnerability workflows, including bug bounty findings.
  • Supporting incident response activities when needed.
  • Monitoring and reporting on application security metrics, KPIs, and emerging threats.
  • Automating processes for vulnerability detection and integrating tools into the pipeline.

Note: this position includes participation in an on‑call rotation.

What we’re looking for
  • 3+ years in software engineering plus 2+ years in application security.
  • Strong knowledge of OWASP, application vulnerabilities, and security testing techniques.
  • Experience with secure web application development and Agile/DevOps methodologies.
  • Familiarity with pen testing, bug bounty, or hacker community collaboration.
  • Strong communication skills – able to influence stakeholders up to senior management.
  • Self‑starter with the ability to prioritise, work independently, and drive initiatives.
  • Knowledge of wider IT and information security practices.
What’s on offer
  • Private healthcare (including dental).
  • Pension contributions.
  • Employee Assistance Programme & wellbeing support.
  • Life insurance.
  • Annual performance bonus.
  • Enhanced family leave from day one.
  • Flexible working hours.25 days holiday + bank holidays (with buy/sell options)
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.