Lead Application Security Engineer

Sure Exec Search

Greater London

Hybrid

GBP 100.000 - 120.000

Vollzeit

vor 6 Stunden
Sei unter den ersten Bewerbenden
Bewerbungsgenerator

Eine komplette Bewerbung in einer Minute — maßgeschneiderter Lebenslauf und Anschreiben, fertig zum Versenden.

Schaffe es an den ATS-Filtern vorbei

Benefits dieser Stelle

Discretionary bonus
Excellent benefits package

Zusammenfassung

Sure Exec Search is seeking a Lead Application Security Engineer in London to establish and scale the firm’s application security capability. You will define standards, guardrails, and review processes, working with ICT, AI Engineering, and business owners to secure internal apps, APIs, cloud services, and SaaS platforms.

The role starts as a senior individual contributor with influence over the function’s growth and potential future team members.

Qualifikationen

  • 7+ years in application security, DevSecOps, or security engineering.
  • Collaborate with software engineering, DevOps and platform teams.
  • Strong SDLC security knowledge: threat modelling, API security, secrets mgmt., security testing and remediation planning.
  • Experience reviewing architectures, CI/CD pipelines, containers or IaC.
  • Familiarity with Azure security controls and SaaS platforms.

Aufgaben

  • Lead the development of the firm's application security capability and guardrails.
  • Review designs, APIs, integrations and deployment patterns to identify risks early.
  • Lead threat modelling for internal apps, integrations, automation and AI-enabled workflows.
  • Guide secure SDLC practices including design reviews, secrets mgmt., and testing.
  • Oversee security assurance activities including penetration testing and remediation tracking.
  • Define security requirements and document architecture decisions and risk-based recommendations.

Kenntnisse

Application security
DevSecOps
Cloud security
Security engineering
Risk assessment

Ausbildung

CSSLP
CISSP
CCSP
GIAC

Tools

Azure Entra ID
Key Vault
API Management
Container security

Jobbeschreibung

Location: London (2-3 days in the office)

Salary: £100,000 – £120,000 + annual discretionary bonus

(Sponsorship not provided)

Our client, a global strategic advisory firm, is looking for a Lead Application Security Engineer to shape how security is built into the way it designs, develops and delivers technology.

The role starts as a senior individual-contributor position with a genuine chance to build something. You'll establish the firm's application security capability: its standards, review processes and guardrails. You'll also help define what the function needs as it grows, potentially including future team members.

You'll work closely with ICT, AI Engineering, application owners and business stakeholders. The scope covers internally developed applications, APIs, integrations, cloud services, SaaS platforms and selected AI-enabled workstreams. It suits someone who leads through technical credibility and influence rather than by owning every implementation themselves.

Key Responsibilities
  • Lead the development of the firm's application security capability: standards, secure design patterns, review processes and practical guardrails that let delivery teams move at pace.
  • Review application designs, architecture decisions, APIs, integrations and deployment patterns, so risks are identified early in the delivery lifecycle.
  • Lead threat modelling, using STRIDE or similar, for internally developed applications, integrations, automation and AI-enabled workflows.
  • Guide secure SDLC practice: security requirements, design and code review, dependency and secrets management, security testing and release assurance.
  • Review CI/CD pipelines, infrastructure as code, containerised workloads and cloud infrastructure, and define practical controls for engineering and platform teams.
  • Assess third-party platforms, SaaS solutions and new technology features, including AI-enabled tools where there are material application, integration or data security considerations.
  • Oversee security assurance, including penetration testing, application security testing and remediation tracking, and drive agreed remediation with the relevant owning teams.
  • Define and document security requirements, architecture decisions and risk-based recommendations.
Skills & Experience
  • Substantial experience (typically 7+ years) in application security, DevSecOps, cloud security or security engineering. This should include time as a senior technical lead or adviser, with clear examples of reviews, standards and decisions you personally drove.
  • Experience working alongside software engineering, DevOps and platform teams to secure applications throughout the delivery lifecycle.
  • Strong secure SDLC knowledge: threat modelling, secure design, API security, authentication and authorisation, secrets and dependency management, security testing and remediation planning.
  • Practical experience reviewing application architectures, CI/CD pipelines, containers or infrastructure as code.
  • Working knowledge of Azure application security controls (Entra ID, managed identities, Key Vault, API Management, container security, logging and secure configuration), alongside Microsoft 365 and SaaS platforms.
  • Experience creating security standards, patterns or review processes that engineering teams actually adopt.
  • Sound risk judgement, including knowing when compensating controls are appropriate, and the ability to explain technical risk clearly to non-technical stakeholders.
  • Familiarity with AI-enabled applications and their risks, such as data exposure, prompt injection, insecure integrations and excessive agent permissions.
  • Experience in an ISO 27001-aligned or regulated environment.
  • Certifications such as CSSLP, CISSP, CCSP, GIAC or Azure security certifications. Equivalent experience counts just as much.
Why it's worth a conversation
  • You'll build an application security capability, and help shape its team, rather than inherit one.
  • You'll have influence across a broad, modern technology estate, including the firm's growing AI engineering work.
  • The firm is collegiate and intellectually curious, with a strong benefits package and discretionary bonus.

Sure Commercial Limited (trading as Sure Exec Search) is a proud Equal Opportunities employer and does not discriminate against any candidate on the grounds of age, disability, sex, gender identity, sexual orientation, pregnancy and maternity, race, religion or belief, marriage and civil partnerships, or other applicable legally protected characteristics. Our Diversity, Equity, and Inclusion Policy is available on request.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.

oder ziehe deine Datei hierhin.

Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Lead Software Security Engineer
Lead Software Security Engineer

United States Digital Space LLC • Greater London

Hybrid
GBP 135.000 - 165.000
Pension scheme
Generous holiday allowance
Ongoing learning and professional development
Lead Application Security Architect & Capability Builder
Lead Application Security Architect & Capability Builder

Sure Exec Search • Greater London

Hybrid
GBP 100.000 - 120.000
Discretionary bonus
Excellent benefits package
Lead Security Engineer
Lead Security Engineer

Barclay Simpson • City Of London

Hybrid
GBP 48.000 - 80.000
Bonus
Benefits
Software Security Engineer
Software Security Engineer

Data Science Festival • Greater London

Vor Ort
GBP 90.000 - 150.000
Hybrid working model
Pension scheme
Generous holiday allowance
Senior Security Engineer
Senior Security Engineer

Data Science Festival • Greater London

Vor Ort
GBP 100.000 - 135.000
Generous holiday allowance
Pension scheme
Ongoing learning and professional development
+2
Application Security Specialist
Application Security Specialist

Experis - ManpowerGroup • Greater London

Vor Ort
GBP 75.000 - 110.000
Competitive salary
Annual bonus
Car allowance
+7
Product Security Engineer
Product Security Engineer

Arrows • Greater London

Hybrid
GBP 100.000 - 140.000
Sponsorship can be considered
Two-stage interview process
Lead Security Engineer
Lead Security Engineer

Eeze • Greater London

Vor Ort
GBP 80.000 - 100.000
26 days paid holiday
Hybrid Working
Pension and Life Assurance
+2
Senior Application Security Engineer / DevSecOps Engineer
Senior Application Security Engineer / DevSecOps Engineer

Additional Resources Ltd. • Greater London

Vor Ort
GBP 80.000 - 90.000
London office
Remote/hybrid work
Excellent benefits package
Lead Security Engineer
Lead Security Engineer

Barclay Simpson • Greater London

Hybrid
GBP 68.000 - 92.000
Bonus
Benefits
Hybrid work arrangement