Rodeo
Get started

Remarkable Resourcing

Senior Application Security Engineer

London
Posted about 12 hours ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Senior Application Security Engineer

Location: London – On-site
Contract: 6 months initially
Rate: Inside IR35
Industry: Cybersecurity / Technology Consultancy

We are looking for a Senior Application Security Engineer to join a global security team on an initial 6-month contract in London. This is a hands-on application security role, working closely with software development teams to identify vulnerabilities, improve secure development practices and embed security throughout the SDLC.

You will act as an Application Security SME, providing security guidance across development teams while carrying out code reviews, penetration testing, architectural reviews and application security testing. You will also contribute to vulnerability research and help shape application security standards, processes and tooling across the organisation.

Key Responsibilities

  • Act as a subject matter expert for application security, providing guidance and security recommendations to development teams.
  • Perform manual source-code reviews, application penetration testing and security architecture reviews.
  • Identify vulnerabilities and develop practical remediation and mitigation strategies with development teams.
  • Drive the use of SAST, DAST, IAST and SCA tooling across the application development lifecycle.
  • Support the responsible disclosure process and investigate externally reported vulnerabilities.
  • Develop and implement security controls, processes and tooling to ensure security and privacy are built into applications by design.
  • Advise engineering teams on secure SDLC, DevSecOps and application security best practices.
  • Research emerging application attack vectors and assess their potential impact on applications and infrastructure.
  • Define and promote application security architecture patterns and standards.
  • Work collaboratively within a global application security team, sharing knowledge and coaching colleagues on security practices.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Key Skills & Experience

  • 5+ years' experience working in Information Security, Application Security, Security Research or a closely related discipline.
  • 3+ years' experience performing manual source-code security reviews and/or strong programming experience in Java,.NET, Python or JavaScript.
  • Strong knowledge of the OWASP Top 10, web application security and API security.
  • Proven application penetration testing and security code review experience.
  • Hands-on experience with SAST, DAST, IAST and SCA tools and processes.
  • Strong understanding of cloud-native architectures, microservices, containers and secure cloud deployments.
  • Good knowledge of authentication, authorisation, security protocols and applied cryptography.
  • Experience with web security technologies including CSP, CORS, OAuth and JWT.
  • Understanding of CI/CD pipelines, build systems and DevSecOps principles.
  • Experience developing security architecture patterns and standards within enterprise environments.
  • Experience with cloud security solutions and major cloud platforms.
  • Knowledge of threat modelling methodologies such as STRIDE, PASTA and MITRE ATT&CK.
  • Practical experience with web application proxies such as Burp Suite, OWASP ZAP or Fiddler.
  • Strong communication skills, with the ability to work effectively with both technical and non-technical stakeholders.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Desirable

  • Experience with CSPM and/or ASPM platforms.
  • OSWE, OSCP, GWEB, GPEN or similar security certification.
  • Mobile application penetration testing experience.
  • Knowledge of AI/ML, LLM security, AI red teaming or AI guardrails.
  • Degree in Computer Science, Cybersecurity or another relevant technical discipline, or equivalent experience.

This is an excellent opportunity for an experienced Application Security Engineer to work in a highly technical environment, influence secure development practices at scale and collaborate with a global security function.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Application Security
Source Code Review
Penetration Testing
Security Architecture Review
SAST
DAST
IAST
SCA
OWASP Top 10
API Security
Cloud-Native Architecture
DevSecOps
Threat Modelling
Burp Suite
Java
Python

Location

London, England, United Kingdom

Sign up to applySee more jobs like this