Senior Application Security Engineer

Redgate

Cambridge

Hybrid

GBP 60,000 - 75,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Private health insurance

Job summary

Redgate is seeking an embedded security expert within its Product Security team in Cambridge. You will define and operationalise security requirements across the SDLC, with authority to make independent security calls rather than relying on scanners.

The role works across multiple product teams to embed secure-by-default standards and governance, shaping how security is done. You will partner with engineering and product teams, lead threat modelling for new features, drive SAST/DAST adoption,

Qualifications

  • Hands-on product or application security experience across the SDLC.
  • Ability to review code and communicate security issues clearly to developers in a C# ecosystem, with exposure to Java or Python.
  • Strong knowledge of the OWASP Top 10 and practical mitigation patterns.
  • Experience implementing or improving SAST/DAST processes: tool tuning, triage workflows, reducing signal to noise.
  • Working understanding of cloud and container security fundamentals, ideally with AWS and Docker.

Responsibilities

  • Partner directly with engineering and product teams to define and operationalise security requirements across the full SDLC.
  • Own or co‑own application security governance: secure‑by‑default standards, patterns, guardrails, and risk exceptions.
  • Lead threat modelling for new features and architectural changes, turning findings into practical engineering work.
  • Drive SAST/DAST adoption and quality, from tool tuning to severity calibration and developer‑facing triage guidance.
  • Support product teams adopting AI, including LLMs, SLMs, and MCP, giving you visibility into work most security roles wouldn’t touch.

Skills

Application security
Code review
OWASP Top 10
SAST/DAST
AWS
Docker
C#
Java
Python

Tools

Docker
AWS

Job description

At a Glance

Location: Cambridge

In-office expectation: Flexible hybrid, once in the office every two weeks

Employment type: Permanent

Salary: £60,000 to £75,000, subject to experience

Why This Role Exists

Redgate's product teams move fast, across a growing set of AI and cloud-native technologies, and security can't just be a gate at the end of that process. This role exists to embed security expertise directly into how our engineering teams build and ship software: setting the standards, running the threat modelling, and making the judgement calls that keep pace with delivery instead of slowing it down.

About Redgate

Redgate brings together people who want to do their best work in an environment built on trust, accountability, and collaboration.

We build solutions that help data professionals securely manage the data and databases their organisations depend on, a space that's only becoming more critical as systems scale, data regulations increase, and AI adoption accelerates.

AI at Redgate

By 2028, Redgate will operate as an expert-plus-agent company: domain experts amplified by AI, delivering customer value at a pace our peers can't match. AI handles the heavy lifting, our people control the judgement. Everyone at Redgate works with Claude, giving you access to the best AI tools from day one.

Why Join Our Product Security Team
  • You’ll shape how security works across multiple product teams, rather than enforcing policy from the sidelines.
  • There’s real scope to specialise in emerging areas like AI security, work most security roles don’t get exposure to yet.
  • We value pragmatic, real risk reduction over checkbox compliance, so the judgement you bring carries genuine weight.
About the Role

This role sits within our Product Security function, embedded across multiple product and engineering teams rather than a single one. You’ll define and operationalise security requirements throughout the SDLC, from initial design through to release, with real authority to make independent security calls rather than deferring to what a scanner tells you. It's a role built on trust: teams will come to you for guidance, and the judgement you bring to triage, threat modelling, and governance decisions will shape how security actually gets done here.

  • Partner directly with engineering and product teams to define and operationalise security requirements across the full SDLC
  • Own or co‑own application security governance: secure‑by‑default standards, patterns, guardrails, and risk exceptions
  • Lead threat modelling for new features and architectural changes, turning findings into practical engineering work
  • Drive SAST/DAST adoption and quality, from tool tuning to severity calibration and developer‑facing triage guidance
  • Support product teams adopting AI, including LLMs, SLMs, and MCP, giving you visibility into work most security roles wouldn’t touch
What Makes You a Great Fit
  • Hands‑on product or application security experience, embedding security practices across a modern software development lifecycle
  • Ability to review code and communicate security issues clearly to developers, primarily within a C# ecosystem, with exposure to Java or Python
  • Strong knowledge of the OWASP Top 10 and practical mitigation patterns
  • Experience implementing or improving SAST/DAST processes: tool tuning, triage workflows, and reducing signal to noise
  • Working understanding of cloud and container security fundamentals, ideally with AWS and Docker
What We Offer

Salary range: £60,000 to £75,000, subject to experience

  • Hybrid working: home and Cambridge office
  • Monthly wellbeing allowance and generous paid time off
  • Genuine investment in learning, development, and career progression
  • Private health insurance

Link to full benefits page here

Belonging at Redgate

We believe that people do their best work in an environment built on respect, fairness, and trust, and that diverse perspectives lead to better outcomes. Redgate is an equal opportunity employer, and we make hiring decisions based on skill, potential, and alignment with our values.

You can read more about how we approach belonging and inclusion at Redgate on our Belonging at Redgate page here.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer
Senior Application Security Engineer

red-gate • Cambridge

Hybrid
GBP 60,000 - 75,000
Hybrid working
Wellbeing allowance
Paid time off
+1
Senior Application Security Engineer
Senior Application Security Engineer

Redgate Software • Cambridge

Hybrid
GBP 60,000 - 75,000
Hybrid Working
Wellbeing allowance
Paid time off
+2
Cyber Security Engineer
Cyber Security Engineer

RED GATE STORAGE • Cambridge

Hybrid
GBP 60,000 - 70,000
Monthly wellbeing allowance
Generous paid time off
Private health insurance
+1
Cyber Security Engineer
Cyber Security Engineer

Redgate Software • Cambridge

Hybrid
GBP 60,000 - 90,000
Hybrid working
Wellbeing allowance
Career development
+2
Product Security Engineer
Product Security Engineer

Redgate Software • Cambridge

Hybrid
GBP 60,000 - 75,000
Comprehensive health coverage
Monthly wellbeing allowance
Generous paid time off
+2
Software Engineer
Software Engineer

慨正橡扯 • Cambridge

Hybrid
GBP 33,000 - 55,000
Private health insurance
Hybrid work model
Wellbeing allowance
+1
Software Engineer
Software Engineer

Redgate Software • Cambridge

Hybrid
GBP 45,000 - 55,000
Hybrid working
Private health insurance
Monthly wellbeing allowance
+2
Software Engineer
Software Engineer

RED GATE STORAGE • Cambridge

Hybrid
GBP 33,000 - 55,000
Hybrid work (Cambridge)
Wellbeing allowance
Paid time off
+2
Senior Software Engineer
Senior Software Engineer

Redgate Software • Cambridgeshire and Peterborough

Hybrid
GBP 85,000 - 120,000
Hybrid working: home and Cambridge
Monthly wellbeing allowance
Generous paid time off
+1
Senior Software Engineer, Foundry
Senior Software Engineer, Foundry

RED GATE STORAGE • Cambridge

Hybrid
GBP 55,000 - 75,000
Monthly wellbeing allowance
Generous paid time off
Private health insurance