Rodeo
Get started

SGI

Application Security Engineer (Cyber) - Financial Services

London
Posted about 17 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Application Security Engineer (Cyber) - Financial Services

Contract - Inside I35
London - Hybrid

Who we’re looking for

Our client’s Cyber Security team is looking for a Cybersecurity engineer with expertise in the Application Security domain, who will be responsible for defining consistent Secure Software Development Lifecycle practices for all technology projects throughout the planning and delivery cycles that assure application security vulnerabilities are mitigated to tolerable levels.

The successful candidate will have very strong application security, web application development experience, and team leadership skills to join a growing Information Security team and assist with the operation of the AppSec function.

What you’ll do

In this position, you are a passionate and talented application security engineer with a very deep understanding of OWASP, CWE 25, Data Protection, Access management, software vulnerabilities, best practices design, and threat modeling skills, who can work in a dynamic environment. You must be dedicated and able to work with developers in producing secure code in short timeframes and be willing to go beyond the standard routine.

Your primary responsibilities include:

  • Work as part of a team of software and security engineers to design/maintain and build best-in-class product security tools and services.
  • Technical point of contact for product teams as it relates to automation, CI/CD, and Product Application Security Operations.
  • Using approved AI models and cyber harnesses to assess application code for business logic weaknesses, misconfiguration, and vulnerabilities.
  • Build tools and automation scripts that enable developers to easily consume security services delivered by Security Engineering and Automation team.
  • Responsible for security product QA and Testing.
  • Build strong relationships with product development teams.
  • Run software composition analysis (SCA) tools.
  • To understand and explain penetration testing findings to the software engineering teams helping them to triage the findings and explaining how to mitigate the risks.
  • To articulate business risk when assessing software vulnerabilities.
  • Continuously improve the operations of SAST, DAST, and IaC security tools.
  • Continuously improve the operations of Web Application Firewalls (WAF) or IDS.
  • Continuously improve the coverage of security tooling in Cloud environments, e.g., Microsoft Azure & Amazon AWS.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

The knowledge, experience, and qualifications you need

  • Computer Science / Cyber Security Degree.
  • Application Development background.
  • Azure DevOps experience.
  • Prior experience in using AI models and cyber harnesses to support security evaluation of application and software code.
  • GitHub, Copilot, Codex, OWASP Top 10 for Agentic AI, AI skills development, and security triage.
  • Ability to code in at least one programming language, e.g., Python/JavaScript/CSharp/Powershell.
  • Prior experience working in a large organization or Financial Services is an advantage.
  • Excellent analytical skills with attention to details.
  • CISSP/CSSLP/CEH/OSCP or similar certification.
  • Presentation skills - ability to present complex solutions to a less technical audience.
  • Team-player interpersonal skills, with the ability to communicate and collaborate effectively with different people in a variety of roles.
  • Passionate about developing a career in Information Security.
  • Excellent command of the English language, both written and spoken.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

What you’ll be like

  • Passionate about mastering and innovating best practice in business analysis.
  • Inspiring and collaborative leader, model of agile leadership approach.
  • Friendly, approachable, enjoys working with people from a variety of backgrounds.
  • Capable of remaining positive when under pressure.
  • Continuous improvement mindset, challenges the status quo, and seeks self-improvement.
  • Problem solver, comfortable taking the initiative in challenging and ambiguous circumstances.

By applying for this role, you consent to SGI contacting you by telephone regarding recruitment services, market updates, and relevant business opportunities.

We believe in equal opportunity for all and actively encourage applications from diverse backgrounds, experiences, and perspectives. Source Group International Ltd is acting as an Employment Business in relation to this vacancy.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Application Security
OWASP
Threat Modelling
CI/CD
SAST
DAST
SCA
WAF
Azure
AWS
Python
JavaScript
CSharp
Powershell
AI Security Triage
Secure Software Development Lifecycle

Location

London, England, United Kingdom

Sign up to applySee more jobs like this