about the company
A global financial technology organisation that provides secure and resilient financial messaging infrastructure used by banks and financial institutions worldwide. The organisation operates in a highly regulated, technology-driven environment where security, reliability and operational resilience are critical to its services.
...
about the job
We are looking for a Senior Application Security Engineer to strengthen application and software security across the organisation.
This role will work closely with Agile, Software Engineering and DevSecOps teams to embed security throughout the Software Development Lifecycle (SDLC) — from application architecture and design through development, testing and operations.
Key responsibilities include:
- Partner with engineering and DevSecOps teams to assess application and architecture security.
- Define security requirements based on business needs, technology architecture, threats and risks.
- Conduct threat modelling, security risk assessments and architecture reviews.
- Promote secure-by-design and secure coding practices across development teams.
- Integrate and manage application security controls within CI/CD pipelines.
- Work with SAST, DAST, SCA, API security/testing and container security capabilities.
- Identify application vulnerabilities, assess business impact and recommend appropriate remediation.
- Develop and maintain application security standards, guidelines and processes.
- Research emerging threats, vulnerabilities and security best practices and translate them into practical security improvements.
- Support cloud-native, containerised and modern application environments.
- Coach and advise development teams to build a stronger security culture.
- Continuously improve application security processes, automation and security testing capabilities.
Key requirements:
- Strong experience in Application Security / Product Security / Security Engineering.
- Hands-on experience with Security Architecture and Threat Modelling.
- Strong understanding of OWASP Top 10, secure coding and application vulnerabilities.
- Experience with SAST, DAST, SCA, API security/testing and/or container security.
- Good understanding of Agile, DevSecOps, CI/CD and Secure SDLC.
- Experience conducting security risk assessments and translating risks into practical security controls.
- Exposure to cloud-native technologies, containers and modern application architectures.
- Strong analytical, communication and stakeholder management skills.
This is not a pure penetration testing role. The focus is on embedding security into application architecture, development and the overall SDLC.
about the manager/team
You will work within a global cybersecurity and technology environment, partnering closely with software engineering, architecture, DevSecOps and other technology stakeholders across the organisation.
The team operates as a security partner to engineering teams, providing technical guidance and helping teams identify and address security risks early in the development lifecycle.
This is a collaborative role with strong exposure to global teams, modern application technologies and large-scale financial technology environments, with opportunities to influence how application security is implemented across the organisation.