Senior Application Security Engineer

Lorien

Greater London

Hybrid

GBP 75,000 - 110,000

Full time

39 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Lorien is seeking a Software Engineer - Cyber Security Engineering in London, a 6-month hybrid role. You will strengthen security across product and platform domains by turning bug-bounty findings into fixes, supporting incident response, and guiding identity and secrets management.

You’ll engage in HackerOne lifecycle activities, handle security incidents, advise on Okta and Doppler integrations, and design scalable security automations.

Qualifications

  • Experience with bug bounty programs (triage, PoCs, retesting, reporting).
  • Strong understanding of web security (OWASP Top 10 / ASVS) and threat modelling.
  • Ability to develop developer-friendly security tooling and automation.
  • Familiarity with web security testing tools (Burp Suite).
  • Exposure to incident response from an application security standpoint.
  • Clear written and verbal communication across technical and non-technical audiences.

Responsibilities

  • HackerOne lifecycle: triage, reproduce, assess risk, coordinate remediation, retest, close out with clear write-ups.
  • Security incidents: contribute engineering expertise during investigations and recovery; implement mitigations and durable fixes.
  • Okta & Doppler: advise engineers on integrations, reference playbooks, identify gaps, author new ones to standardise patterns.
  • Automation: design automations that scale application and cloud security.
  • Collaboration: partner with the Director of Cybersecurity on AppSec, DevSecOps, and cloud-security initiatives.

Skills

HackerOne / bug bounty platforms
OWASP Top 10 / ASVS
Threat modelling
Security tooling & automation
Burp Suite familiarity
Incident response exposure
Communication (written & verbal)

Tools

GitHub Actions
Terraform
Kubernetes
AWS
Okta
Doppler
Burp Suite

Job description

Job Title: Software Engineer - Cyber Security Engineering
Duration: 6 Months
Location: London - Hybrid
Description:

Join a hands-on cyber engineering team strengthening security across product and platform domains. You’ll turn bug-bounty findings into fixes, support incident response, and provide pragmatic guidance on identity and secrets management.

We’re committed to diversity and inclusion in tech, and we actively encourage applications from underrepresented groups.

What You’ll Do
  • HackerOne lifecycle: triage, reproduce, assess risk/severity, coordinate remediation, retest, and close out reports with clear write-ups.
  • Security incidents: contribute engineering expertise during investigations and recovery; implement short-term mitigations and drive durable fixes.
  • Okta & Doppler: advise engineers on integrations, use existing playbooks, identify gaps, and author new ones to standardise patterns.
  • Automation: design automations that scale application and cloud security.
  • Collaboration: partner with the Director of Cybersecurity on AppSec, DevSecOps, and cloud-security initiatives.
Skills & Experience Required
  • Experience with HackerOne or similar bug bounty platforms (triage, PoCs, retesting, communication).
  • Strong understanding of web application security (OWASP Top 10 / ASVS, common attack paths, practical mitigations) and threat modelling.
  • Ability to build developer-friendly security tooling and automation.
  • Familiarity with web security testing (e.g. Burp Suite, safe minimal PoCs).
  • Exposure to incident response from an application security standpoint.
  • Clear written and verbal communication across technical and non-technical audiences.
Highly Useful
  • Good scripting experience (e.g. Python).
  • Hands-on use of SAST, SCA, secrets scanning, and DAST tools, especially in CI/CD pipelines.
  • Awareness of CI/CD and infrastructure security patterns (GitHub Actions, Terraform, Kubernetes, least-privilege IAM).
  • Practical experience with Okta (OIDC/SAML, MFA, policies, workflows) and Doppler (secrets lifecycle, rotation, environments).
  • Hands-on Cloud Security (AWS) experience
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior AppSec Engineer — Bug Bounty & Cloud Security
Senior AppSec Engineer — Bug Bounty & Cloud Security

Lorien • Greater London

Hybrid
GBP 75,000 - 110,000
Software Security Engineer - Hybrid Working
Software Security Engineer - Hybrid Working

Oliver James • England

On-site
GBP 70,000 - 90,000
Application Security Specialist
Application Security Specialist

Experis - ManpowerGroup • Greater London

Hybrid
GBP 75,000 - 110,000
Competitive salary
Annual bonus
Car allowance
+7
Application Security Specialist
Application Security Specialist

Experis UK • Greater London

Hybrid
GBP 70,000 - 120,000
Car allowance
Hybrid working
Annual bonus
+2
Senior Application Security Specialist
Senior Application Security Specialist

La Fosse • Greater London

Hybrid
Senior Security Engineer
Senior Security Engineer

Spendesk • Greater London

On-site
GBP 90,000 - 120,000
Senior Security Engineer - Contract
Senior Security Engineer - Contract

United States Digital Space LLC • Greater London

On-site
GBP 70,000 - 110,000
Senior Application Security Engineer / DevSecOps Engineer
Senior Application Security Engineer / DevSecOps Engineer

Additional Resources • City Of London

Hybrid
GBP 72,000 - 88,000
Senior Security Engineer
Senior Security Engineer

Sanderson • Greater London

On-site
GBP 70,000 - 90,000
Senior Application Security Engineer
Senior Application Security Engineer

Clear Corp • Greater London

On-site
GBP 127,000 - 161,000
Comprehensive healthcare plans
Flexible time off
401(k) retirement plan with employer match