Назад
Company hidden
обновлено 11 дней назад

Application Security Engineer (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Английский
b2
Страна
UK/Bulgaria
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Engineer (Cybersecurity): Improving application security across a cloud-native technology estate with an accent on developer-friendly guardrails, vulnerability management, and secure engineering workflows. Focus on integrating SAST and secret scanning into CI/CD pipelines, supporting threat modelling, and automating security processes with Python.

Location: London or Sofia. Hybrid model requiring staff to work onsite 50% of the time.

Company

hirify.global is a global news organisation delivering quality information and services worldwide.

What you will do

  • Improve application security across a cloud-native technology estate.
  • Develop developer-friendly security guardrails for GitHub-based CI/CD pipelines, application repositories, and engineering workflows.
  • Support SAST, software composition analysis, secret scanning, vulnerability management, and secure coding guidance.
  • Work with engineers on threat modelling, vulnerability triage, remediation, and secure development practices.
  • Improve security playbooks and automate security workflows with scripts or small tools, ideally in Python.

Requirements

  • Practical application security experience in modern engineering environments.
  • Experience working with software engineers to explain and remediate security issues.
  • Familiarity with web application security risks, secure coding practices, vulnerability triage, prioritisation, and remediation tracking.
  • Experience using or interpreting SAST, software composition analysis, secret scanning, or similar security tooling.
  • Experience participating in or supporting threat-modelling activities.
  • Strong communication and collaboration skills, scripting ability, and familiarity with Agile or Scrum.

Nice to have

  • Exposure to AWS security, cloud security, infrastructure-as-code security, Terraform, or CloudFormation.
  • Experience with container or Kubernetes security.
  • Experience with bug bounty, penetration testing, security testing programmes, Splunk, dashboards, metrics, or vulnerability management reporting.
  • Exposure to AI security, including LLM-enabled applications, AI-assisted development workflows, or prompt and data leakage risks.
  • Relevant security certifications or training, including AWS security, secure coding, GIAC, ISC2, or CREST.

Culture & Benefits

  • Generous annual leave and medical cover.
  • Inclusive parental leave packages and subsidised gym memberships.
  • Opportunities to give back to the community.
  • Hybrid working designed to support collaboration, communication, team cohesion, and peer learning.
  • Reasonable adjustments are available during the application and interview process.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →