22 часа назад
Application Security Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Application Security Engineer (Cybersecurity): Building automated security checks, guardrails, and API integrations across CI/CD, source code management, and internal engineering platforms with an accent on application security tooling, cloud automation, and Secure by Design practices. Focus on embedding scalable controls into delivery pipelines, measuring security-tool effectiveness, and enabling engineering teams to identify and remediate vulnerabilities.
Location: Home based with hybrid working; based in Bristol, UK, with office attendance two days a week. Permanent full-time role, 37.5 hours per week, Monday to Friday.
Company
is a UK investment platform for private investors, helping people save and invest for the future.
What you will do
- Design, build, and maintain automated application security checks, guardrails, and policy-as-code controls in developer workflows.
- Develop automation and API integrations connecting security tooling with CI/CD, source code management platforms, and internal systems.
- Implement, optimise, and measure security tooling across engineering platforms, including dashboards and impact metrics.
- Embed secure development practices and testing into delivery pipelines, shared templates, and engineering standards.
- Evaluate security tools for integration, scalability, and developer experience, while supporting application security strategy.
- Partner with Engineering and the CISO function, and support the Security Champions programme through enablement and training.
Requirements
- Strong experience integrating security tooling into CI/CD pipelines and engineering platforms.
- Ability to develop automation and API-based integrations using Python, JavaScript, or another programming or scripting language.
- Knowledge of software development languages, frameworks, and build and deployment tools such as GitHub, GitLab CI/CD, Harness, and Jenkins.
- Hands-on experience with SAST, DAST, SCA, vulnerability aggregation, or ASPM platforms.
- Experience with AWS or Azure and containerised or lightweight workloads such as Docker, Lambda, or ECS.
- Understanding of CVSS, EPSS, common application vulnerabilities, Agile delivery, and developer-focused Security Champion programmes.
Nice to have
- Experience improving workflows and processes based on feedback.
- Experience supporting engineering teams with vulnerability remediation and communicating security risk.
Culture & Benefits
- Flexible working options, including hybrid working.
- 25 days of holiday plus bank holidays and an additional Christmas closure day, with the option to purchase additional holiday.
- Annual bonus, pay review, pension contributions of up to 11%, income protection, life insurance, and private medical insurance.
- Enhanced parental leave, health screening, wellbeing support, remote GP access, and fitness and wellness benefits.
- Two paid volunteering days per year, travel-to-work schemes, bike storage, shower facilities, and subsidised food and coffee.
Hiring process
- Two stages: an introductory conversation followed by technical competency-based questions and a task.
- Employment sponsorship is not available.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →