Sure Exec Search
Lead Application Security Engineer

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Lead Application Security Engineer
Location: London (2-3 days in the office)
Salary: £100,000 – £120,000 + annual discretionary bonus
(Sponsorship not provided)
Our client, a global strategic advisory firm, is looking for a Lead Application Security Engineer to shape how security is built into the way it designs, develops and delivers technology.
The role starts as a senior individual-contributor position with a genuine chance to build something. You'll establish the firm's application security capability: its standards, review processes and guardrails. You'll also help define what the function needs as it grows, potentially including future team members.
You'll work closely with ICT, AI Engineering, application owners and business stakeholders. The scope covers internally developed applications, APIs, integrations, cloud services, SaaS platforms and selected AI-enabled workstreams. It suits someone who leads through technical credibility and influence rather than by owning every implementation themselves.
Key Responsibilities
- Lead the development of the firm's application security capability: standards, secure design patterns, review processes and practical guardrails that let delivery teams move at pace.
- Review application designs, architecture decisions, APIs, integrations and deployment patterns, so risks are identified early in the delivery lifecycle.
- Lead threat modelling, using STRIDE or similar, for internally developed applications, integrations, automation and AI-enabled workflows.
- Guide secure SDLC practice: security requirements, design and code review, dependency and secrets management, security testing and release assurance.
- Review CI/CD pipelines, infrastructure as code, containerised workloads and cloud infrastructure, and define practical controls for engineering and platform teams.
- Assess third-party platforms, SaaS solutions and new technology features, including AI-enabled tools where there are material application, integration or data security considerations.
- Oversee security assurance, including penetration testing, application security testing and remediation tracking, and drive agreed remediation with the relevant owning teams.
- Define and document security requirements, architecture decisions and risk-based recommendations.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Skills & Experience
- Substantial experience (typically 7+ years) in application security, DevSecOps, cloud security or security engineering. This should include time as a senior technical lead or adviser, with clear examples of reviews, standards and decisions you personally drove.
- Experience working alongside software engineering, DevOps and platform teams to secure applications throughout the delivery lifecycle.
- Strong secure SDLC knowledge: threat modelling, secure design, API security, authentication and authorisation, secrets and dependency management, security testing and remediation planning.
- Practical experience reviewing application architectures, CI/CD pipelines, containers or infrastructure as code.
- Working knowledge of Azure application security controls (Entra ID, managed identities, Key Vault, API Management, container security, logging and secure configuration), alongside Microsoft 365 and SaaS platforms.
- Experience creating security standards, patterns or review processes that engineering teams actually adopt.
- Sound risk judgement, including knowing when compensating controls are appropriate, and the ability to explain technical risk clearly to non-technical stakeholders.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Desirable
- Familiarity with AI-enabled applications and their risks, such as data exposure, prompt injection, insecure integrations and excessive agent permissions.
- Experience in an ISO 27001-aligned or regulated environment.
- Certifications such as CSSLP, CISSP, CCSP, GIAC or Azure security certifications. Equivalent experience counts just as much.
Why it's worth a conversation
- You'll build an application security capability, and help shape its team, rather than inherit one.
- You'll have influence across a broad, modern technology estate, including the firm's growing AI engineering work.
- The firm is collegiate and intellectually curious, with a strong benefits package and discretionary bonus.
If you are passionate about this opportunity and meet the qualifications and skills outlined, we encourage you to promptly submit your CV for consideration. Please note that the duties mentioned above are not exhaustive, and the role's responsibilities may evolve in response to changing circumstances and requirements.
Sure Commercial Limited (trading as Sure Exec Search) is a proud Equal Opportunities employer and does not discriminate against any candidate on the grounds of age, disability, sex, gender identity, sexual orientation, pregnancy and maternity, race, religion or belief, marriage and civil partnerships, or other applicable legally protected characteristics. Our Diversity, Equity, and Inclusion Policy is available on request.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location