Senior Application Security Engineer - London

Additional Resources

Greater London

Hybrid

GBP 70,000 - 80,000

Full time

44 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Excellent benefits package

Job summary

Additional Resources is seeking a hands-on Application Security Engineer in Central London for a hybrid role. The position focuses on secure design, CI/CD security, cloud-native tech, Kubernetes, API security, code analysis and security-as-code, collaborating with engineering and cloud teams to build and maintain secure applications and deployment processes.

The role requires substantial security expertise with Azure, AKS, Terraform, Python, and experience in threat modelling and ISO 27001.

Qualifications

  • Hands-on experience embedding application security into the SDLC.
  • Experience securing APIs, internet-facing services and Kubernetes (AKS) and containerised environments.
  • Experience with SAST, DAST, IAST and SCA tooling.
  • Familiarity with security automation, policy-as-code and secure engineering practices.
  • Experience with CI/CD tooling such as GitHub Actions.
  • Strong Terraform and Python skills.
  • Understanding of Azure security controls and cloud governance.
  • Experience with threat modelling in software engineering contexts.
  • Knowledge of ISO 27001 and secure engineering relevance.
  • Familiarity with Agile and DevSecOps methodologies.
  • Eligibility to work in the UK.

Responsibilities

  • Collaborate with engineering and architecture teams to promote secure development from the earliest stages.
  • Implement and maintain application security testing solutions enabling remediation of risks.
  • Enhance secure development processes by integrating security controls into CI/CD pipelines.
  • Strengthen security of GitHub Actions and other CI/CD platforms.
  • Provide technical guidance on secure API design and protection of externally accessible systems.
  • Support security of Azure cloud infrastructure including AKS.
  • Protect cloud-hosted data platforms and related technologies.
  • Develop and maintain security-as-code and policy-as-code using appropriate tooling.
  • Automate security processes via infrastructure-as-code and scripting.
  • Produce and maintain technical documentation and security procedures.
  • Support development teams with adoption of security tooling and best practices.
  • Contribute to wider cyber security initiatives including threat modelling and compliance.

Skills

Security in SDLC
API security
Kubernetes
Azure security
Terraform
Python
GitHub Actions
Threat modelling
ISO 27001 knowledge
Cloud security governance
Automation / security-as-code

Tools

GitHub Actions
Azure Kubernetes Service (AKS)
Terraform
SAST/DAST/IAST/SCA tooling

Job description

Salary: £25,000 - 50,000 per year

Requirements:
  • We are looking for someone who has previously worked as a Senior Application Security Engineer, Lead Application Security Engineer, Principal Application Security Engineer, Application Security Engineer, Senior Product Security Engineer, Product Security Engineer, Senior DevSecOps Engineer, DevSecOps Engineer, Application Security Consultant or in a similar role.
  • We need hands‑on experience embedding application security into the SDLC.
  • We need experience securing APIs, internet‑facing services, and Kubernetes, preferably AKS, and containerised environments.
  • We need experience working with engineering teams and implementing security testing tools such as SAST, DAST, IAST and SCA.
  • We need knowledge of security automation, security-/policy‑as‑code, and secure engineering practices including code review, testing, source control and documentation.
  • We need familiarity with CI/CD tools such as GitHub and GitHub Actions.
  • We need strong skills in Terraform and Python.
  • We need a strong understanding of Azure security controls and cloud security governance.
  • We need experience with threat modelling in software engineering contexts.
  • We need knowledge of ISO 27001 and its relevance to secure engineering.
  • We need familiarity with Agile and DevSecOps methodologies.
  • You must be eligible to work in the UK.
Responsibilities:
  • We will work closely with engineering and architecture teams to promote secure development from the earliest stages of delivery.
  • We will implement and maintain application security testing solutions, enabling developers to identify and remediate security risks.
  • We will enhance secure development processes by integrating security controls throughout CI/CD pipelines.
  • We will strengthen the security of GitHub Actions and comparable continuous integration and deployment platforms.
  • We will provide technical guidance on secure API design and protecting externally accessible systems.
  • We will support the security of Azure cloud infrastructure, including Azure Kubernetes Service (AKS).
  • We will assist with the protection of cloud-hosted data platforms and associated technologies.
  • We will develop and maintain security‑as‑code and policy‑as‑code using appropriate tooling.
  • We will automate security processes through infrastructure‑as‑code and scripting technologies.
  • We will produce and maintain technical documentation, security procedures and service documentation.
  • We will support development teams with the adoption and integration of security tooling and best practices.
  • We will contribute to wider cyber security initiatives, including threat modelling and compliance activities.
Technologies:
  • API
  • Azure
  • CI/CD
  • Cloud
  • DevSecOps
  • GitHub
  • Support
  • Kubernetes
  • Python
  • Security
  • Terraform
More:

We are a well‑established health research organisation and charity that supports large‑scale medical research to improve disease prevention, diagnosis and treatment. This is a full‑time, permanent hybrid role based in Central London, with a salary of 70,000 to 80,000 per annum and an excellent benefits package. The role is a hands‑on Application Security position focused on secure design, CI/CD security, cloud‑native technologies, Kubernetes, API security, code analysis and security‑as‑code, working alongside engineering and cloud teams to build, improve and maintain secure applications, platforms and deployment processes. Visa sponsorship is not available.

last updated 40 week of 2026

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer / DevSecOps Engineer
Senior Application Security Engineer / DevSecOps Engineer

Additional Resources • City Of London

On-site
GBP 72,000 - 88,000
Senior Application Security Engineer / DevSecOps Engineer
Senior Application Security Engineer / DevSecOps Engineer

Additional Resources Ltd. • Greater London

On-site
GBP 80,000 - 90,000
London office
Remote/hybrid work
Excellent benefits package
Senior Application Security Engineer
Senior Application Security Engineer

Hackajob Ltd • Chesterton

On-site
GBP 60,000 - 75,000
Wellbeing allowance
Private health insurance
Paid time off
+1
Application Security Engineer
Application Security Engineer

Barclay Simpson • Greater London, Manchester, Glasgow

Hybrid
GBP 72,000 - 98,000
Application Security Specialist
Application Security Specialist

Experis - ManpowerGroup • Greater London

On-site
GBP 75,000 - 110,000
Competitive salary
Annual bonus
Car allowance
+7
Application Security Engineer
Application Security Engineer

Barclay Simpson • City Of London

Hybrid
GBP 51,000 - 85,000
Application Security Engineer
Application Security Engineer

Cyber Security training courses • Greater London

Hybrid
GBP 77,000 - 94,000
Senior Security Engineer
Senior Security Engineer

Data Science Festival • Greater London

On-site
GBP 100,000 - 135,000
Generous holiday allowance
Pension scheme
Ongoing learning and professional development
+2
Senior Application Security Specialist
Senior Application Security Specialist

Sanderson • Greater London

Hybrid
GBP 67,000 - 89,000
Software Security Engineer
Software Security Engineer

Data Science Festival • Greater London

On-site
GBP 90,000 - 150,000
Hybrid working model
Pension scheme
Generous holiday allowance