Haystack
← Back to Jobs
Full time
Technology
SR

Application Security Engineer

Spencer Rose LtdUnited Kingdom🇬🇧United KingdomPosted 30 Sept 2026

Quick Overview

Salary
£55k/yr
Seniority
Mid Senior
Employment type
Full Time
Work mode
Hybrid
Location
United Kingdom
OWASPSOC 2SonarQubeC#C++JavaPython

Job Description

Application Security Engineer

Location: Remote/Hybrid (UK & Ireland)
Salary: c.£55K dependent on experience

About the Role

We are looking for an experienced Application Security Engineer to work directly with development teams and embed security into every stage of the software development life cycle.

This is a hands-on technical role focused on building secure software rather than simply auditing it. You'll partner with engineers to identify vulnerabilities before they reach production, implement automated security controls within CI/CD pipelines, and provide practical guidance that helps developers remediate risks quickly and effectively.

You will act as the bridge between Cyber Security and Engineering, ensuring security becomes a natural part of how applications are designed, developed, tested, and deployed.

Key Responsibilities

Application Security Engineering

  • Partner with development teams throughout the SDLC to identify, prioritise, and remediate application security vulnerabilities.
  • Conduct manual code reviews and security testing on high-risk applications and components where automated tooling cannot provide sufficient coverage.
  • Support secure software delivery by integrating security requirements into engineering practices and workflows.
  • Provide technical guidance during security incidents involving application-layer vulnerabilities.

Security Tooling & Automation

  • Design, implement, and optimise SAST, DAST, and Software Composition Analysis (SCA) tooling within CI/CD pipelines.
  • Manage and tune security tools such as SonarQube, Snyk, and similar platforms to ensure findings remain actionable and relevant.
  • Improve automation and developer feedback loops to identify security issues earlier in the development process.
  • Support vulnerability management activities by tracking remediation progress and reducing recurring risks.

Threat Modelling & Secure Design

  • Conduct threat modelling exercises for new products, features, and architectural changes.
  • Work with engineering teams to design out security risks during the design phase rather than addressing them later in development.
  • Review application and API architectures to ensure security requirements are Embedded from the outset.
  • Support secure-by-design initiatives across engineering teams.

Developer Enablement

  • Develop and maintain secure coding standards, best practices, and implementation guidance.
  • Provide hands-on support to developers in understanding, prioritising, and fixing security vulnerabilities.
  • Deliver security awareness activities focused on secure coding and application security.
  • Run or support a Security Champions programme to scale security expertise throughout the engineering organisation.

Software Supply Chain Security

  • Review third-party libraries, frameworks, and dependencies for known vulnerabilities and licensing risks.
  • Support software supply chain security initiatives and dependency management processes.
  • Ensure security is considered throughout the application life cycle, including open-source component management.

Compliance & Assurance

  • Support internal and external security assessments, including customer security reviews.
  • Contribute evidence and control documentation for compliance frameworks such as ISO 27001 and SOC 2.
  • Collaborate with Product Security and Cyber Security teams to maintain effective application security controls.

What We're Looking ForEssential Experience

  • Proven experience in Application Security with practical vulnerability remediation and code review responsibilities.
  • Strong understanding of common vulnerability classes including:
    • OWASP Top 10
    • Injection vulnerabilities
    • Authentication and authorisation flaws
    • SSRF
    • Deserialisation vulnerabilities
    • API security risks
  • Hands-on experience implementing and operating SAST, DAST, and SCA tooling within CI/CD environments.
  • Ability to review, understand, and discuss code in at least one of the following languages:
    • Java
    • Python
    • C++
    • C#
  • Experience conducting threat modelling and translating security findings into practical engineering actions.
  • Strong communication skills with the ability to work collaboratively as an Embedded partner within engineering teams.
  • Experience supporting secure API design and modern cloud-native application architectures.

Desirable

  • Experience supporting compliance frameworks such as ISO 27001 or SOC 2.
  • Experience running Security Champions programmes.
  • Familiarity with software supply chain security initiatives and dependency governance.
  • Relevant application security certifications or training.

Core Technology Stack

Java Python C++ C# SonarQube Snyk SAST DAST Software Composition Analysis (SCA) CI/CD Pipelines Threat Modelling Secure Coding Standards OWASP Top 10 API Security Vulnerability Management Software Supply Chain Security

Similar jobs