Senior Application Security Engineer - 12 Month Fixed Term Contract

giffgaff | Certified B Corp

Uxbridge

Hybrid

GBP 90,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

giffgaff is seeking a Senior Application Security Engineer on a 12-month fixed-term contract in Uxbridge. You will embed security into how we design, build and run our products, working across a modern technology estate to ensure secure software from the earliest stages of development through to production.

You will collaborate with engineers, architects and platform teams to identify risks, drive vulnerability remediation, and strengthen our DevSecOps capabilities while coaching teams to

Qualifications

  • Experience assessing security impacts across codebases and APIs using languages such as Java, TypeScript and Python.
  • Strong knowledge of the OWASP Top 10, secure coding practices, and common web and API vulnerabilities.
  • Hands‑on experience triaging, validating and remediating vulnerabilities with both technical and non‑technical stakeholders.
  • Experience integrating security tooling into CI/CD pipelines and embedding DevSecOps practices.
  • Proven expertise in threat modelling, secure code review, architecture review, and container/Kubernetes security.

Responsibilities

  • Embed security into product design, development and operations.
  • Collaborate with engineers, architects and platform teams to identify risks and remediation.
  • Drive vulnerability remediation and strengthen DevSecOps capabilities.
  • Coach teams to foster a strong security culture across the business.

Skills

Java
TypeScript
Python
OWASP Top 10
CI/CD security
DevSecOps
Threat modelling
Container/Kubernetes security

Tools

Terraform
AWS
CI/CD tooling

Job description

Summary

As a Senior Application Security Engineer at giffgaff on a 12-month fixed-term contract, you'll be responsible for embedding security into the way we design, build and operate our products. Working across a modern technology estate, you'll help ensure security is considered from the earliest stages of development through to production, enabling engineers to deliver secure software with confidence.

This role combines technical depth with collaboration and influence. You'll work alongside engineers, architects and platform teams to identify risks, improve security controls, drive vulnerability remediation and strengthen our DevSecOps capabilities. You'll also help foster a strong security culture by coaching teams and championing security best practice throughout the business.

This role is a 12 Month Fixed Term Contract

This role is a 12 Month Fixed Term Contract

Location

Uxbridge

Job Type

Full Time

Ref #

74311

Who we are

Do you want to join a connectivity provider that’s up to good? At giffgaff, we do things differently. We call out the bad and find a better way. We’re laser-focused on flexibility, value and mutual good. And we’re proud to be a certified B Corp. This means we’ve joined a network of more than 2,000 UK companies who want to make a positive impact on people and the planet. Working at giffgaff is something you could be proud of too.

You’ll get the best of both worlds, the energy and fast pace of giffgaff, plus all the benefits that come with being part of our parent company, Virgin Media O2.

Our business model is unique. We work with our members (our customers) to understand their needs in all areas of the business. We love this highly collaborative approach. We’re always looking to acquire new members, and to do that we need the best people in our team.

In return for your outstanding efforts, you’ll be rewarded with a competitive salary and excellent benefits that are all about making your work life a winner. Take a look at our culture and benefits - you might just be surprised.

Our bright and modern gaff is in Uxbridge, in leafy West London. But if commuting isn’t for you, most of our roles can be hybrid or remote, or anywhere in between.

The must haves
  • Experience assessing security impacts across codebases and APIs using languages such as Java, TypeScript and Python.
  • Strong knowledge of the OWASP Top 10, secure coding practices, and common web and API vulnerabilities.
  • Hands‑on experience triaging, validating and remediating vulnerabilities with both technical and non‑technical stakeholders.
  • Experience integrating security tooling into CI/CD pipelines and embedding DevSecOps practices.
  • Proven expertise in threat modelling, secure code review, architecture review, and container/Kubernetes security.
The other stuff we are looking fo
  • Security certifications such as OSCP, GWAPT, CSSLP, CEH or Security+.
  • Experience securing AWS environments and infrastructure‑as‑code solutions such as Terraform.
  • Knowledge of AI‑enabled security workflows and securing AI or LLM‑powered features.
  • Experience contributing to or maintaining open‑source security tooling.
What's in it for you

Our goal is to celebrate our people and their lives. We aim to create a culture that empowers everyone to bring the best versions of themselves to work each and every day. We believe the most inclusive and diverse culture makes for a better business and a brighter world.

Working at giffgaff means you get a bumper reward package bursting with benefits, and loads of extras you can add if you’d like to. These are designed to support both you and your loved ones, making sure that you’re covered no matter what life throws your way.

We’re all about hybrid working here, so expect to have a base location where you’ll have the right facilities to enable amazing collaboration and quality time with your team, alongside all the right kit to work from home too.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior DevSecOps Security Engineer (12-Month Contract)
Senior DevSecOps Security Engineer (12-Month Contract)

giffgaff | Certified B Corp • Uxbridge

Hybrid
GBP 90,000 - 120,000
Software Engineer
Software Engineer

慨正橡扯 • Uxbridge

Hybrid
GBP 50,000 - 70,000
Senior Security Engineer
Senior Security Engineer

Pay.UK • Greater London

On-site
GBP 85,000 - 120,000
12% Non-contributory pension
Discretionary annual bonus
30 days annual leave
+5
Senior Application Security Manager
Senior Application Security Manager

United States Digital Space LLC • Greater London

Hybrid
GBP 120,000 - 180,000
Company card
Lunch provided
Private healthcare
+4
Security Tester
Security Tester

Pharmacy2U Ltd • Leeds

Hybrid
GBP 40,000 - 60,000
Occupational sick pay
Enhanced maternity and paternity pay
Contributory pension
+3
Senior Security Engineer
Senior Security Engineer

NCC Group • Manchester

On-site
GBP 65,000 - 95,000
Flexible Working
25 days holiday plus bank holidays
Pension and Life Assurance
+4
Senior Security Engineer
Senior Security Engineer

NCC Group plc • Manchester

On-site
GBP 90,000 - 120,000
Flexible Working
25 days holiday + bank holidays
Medicash & Critical Illness Scheme
+7
Application Security Engineer (Cyber)
Application Security Engineer (Cyber)

Source Technology Limited • Greater London

Hybrid
GBP 90,000 - 120,000
Senior Security Engineer
Senior Security Engineer

NCC Group • Greater Manchester

On-site
GBP 80,000 - 105,000
Flexible working
25 days holiday + bank holidays
Medicash & Critical Illness Scheme
+4
QAQC Specialist (57150)
QAQC Specialist (57150)

BT Business • Greater London

On-site
GBP 65,000 - 95,000
10% on target annual bonus
Private GP 24/7 for you and immediate家
Paid carers leave up to 2 weeks
+4