Enable job alerts via email!

Lead Application Security Engineer

JR United Kingdom

Coventry

Remote

GBP 70,000 - 100,000

Full time

Yesterday
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

A leading FinTech company seeks a Lead Application Security Engineer to enhance its security posture against real-world threats. This role requires a hands-on expert with a hacker mindset, focusing on improving code security and application architecture. You will collaborate closely with senior management, drive AppSec strategy, and build your own team in an established environment with existing DevSecOps practices.

Qualifications

  • Deep hands-on experience in application security.
  • Proven background in credit cards or payment systems.
  • Experience in modern application architectures.
  • Familiarity with OWASP Top 10 and pen testing techniques.

Responsibilities

  • Identify vulnerabilities in applications and security.
  • Perform penetration testing and secure code reviews.
  • Integrate security best practices within DevSecOps pipeline.
  • Shape AppSec strategy while being hands-on with coding.

Skills

Application Security
Penetration Testing
Threat Modelling
Secure Coding
Problem Solving

Job description

Social network you want to login/join with:

Lead Application Security Engineer, coventry

col-narrow-left

Client:

WeDo

Location:

coventry, United Kingdom

Job Category:

Other

-

EU work permit required:

Yes

col-narrow-right

Job Views:

5

Posted:

26.06.2025

Expiry Date:

10.08.2025

col-wide

Job Description:

Title: Lead Application Security Engineer

Location: Fully Remote (UK-based)

Sector: FinTech / Digital Consumer Finance

We’re recruiting on behalf of a UK-based FinTech that’s simplifying how consumers engage with credit – offering digital credit cards and financial services built on cloud-native architecture and driven by data.

They are looking to hire a highly technical, hands-on Lead Application Security Engineer to take full ownership of the application security landscape – not from a policy or governance standpoint, but through deep, practical expertise in identifying and fixing vulnerabilities across live systems.

This role is perfect for a white hat hacker mindset – someone who thrives in proactively breaking applications, exposing flaws in logic, authentication, payment processing, or APIs, and using creativity (not just tooling) to harden applications from real-world threats.

What Makes This Role Stand Out?

  • You’ll be hands-on: This is not a governance or compliance function. It’s about deep technical engagement with the codebase, systems, and application architecture.
  • You’re walking into a mature environment: The company already has Secure SDLC and DevSecOps practices in place. This isn’t a ground-up build – it’s about stress-testing and strengthening what’s already built.
  • You’ll have impact and visibility: Reporting to the CIO, with close collaboration with the Head of Information Security (compliance), you’ll shape the AppSec strategy while also getting into the code.
  • You’ll build your own team: This role includes team growth – you’ll start as a leader and grow your own capability beneath you.

What You’ll Be Doing:

  • Actively identifying vulnerabilities in applications, especially around authentication flows, payments, and sensitive data handling
  • Thinking creatively and adversarially – “breaking the app” to protect it
  • Performing penetration testing, threat modelling, and secure code reviews
  • Working directly with developers to integrate security best practices into an already-operational DevSecOps pipeline
  • Advising on product and architectural design from a security-first lens
  • Contributing to a security culture that prioritises customer trust and system integrity

What We’re Looking For:

  • Deep hands-on experience in application security – not just theory, but experience in secure coding, manual testing, and fixing complex vulnerabilities
  • A proven background in credit cards, payments, or financial transaction systems
  • Understanding of modern application architectures (APIs, microservices, cloud platforms – likely Azure)
  • Familiarity with OWASP Top 10, SAST/DAST, and a variety of pen testing techniques
  • A desire to build and lead a team, while remaining technical and practical day to day
  • Right to work in the UK and ability to work remotely from within the UK

Recruitment Process:

  • Initial call with Head of Engineering
  • Second stage with CIO
  • Final conversation and potentially a take-home exercise

If you're ready to be the attacker before the attacker is, and want to lead AppSec in an ambitious and growing FinTech, we’d love to hear from you.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Lead Application Security Engineer

JR United Kingdom

Birmingham null

Remote

Remote

GBP 80,000 - 110,000

Full time

Today
Be an early applicant

Lead Application Security Engineer

JR United Kingdom

Bedford null

Remote

Remote

GBP 60,000 - 90,000

Full time

Today
Be an early applicant

Lead Application Security Engineer

JR United Kingdom

Oxford null

Remote

Remote

GBP 70,000 - 100,000

Full time

Today
Be an early applicant

Lead Application Security Engineer

JR United Kingdom

Cheltenham null

Remote

Remote

GBP 70,000 - 100,000

Full time

Today
Be an early applicant

Lead Application Security Engineer

JR United Kingdom

Nottingham null

Remote

Remote

GBP 70,000 - 100,000

Full time

Today
Be an early applicant

Lead Application Security Engineer

JR United Kingdom

Gloucester null

Remote

Remote

GBP 70,000 - 100,000

Full time

Today
Be an early applicant

Lead Application Security Engineer

JR United Kingdom

Milton Keynes null

Remote

Remote

GBP 60,000 - 90,000

Full time

Today
Be an early applicant

Lead Application Security Engineer

JR United Kingdom

Northampton null

Remote

Remote

GBP 70,000 - 95,000

Full time

Today
Be an early applicant

Lead Application Security Engineer

JR United Kingdom

Worcester null

Remote

Remote

GBP 60,000 - 90,000

Full time

Today
Be an early applicant