Application Security Engineer

London, GBR •
Security

DescriptionJob Title: Application Security EngineerWorking Time: Full timeLocation: UK, London - HybridAbout CloudBeesCloudBees helps organizations build, run, and govern software factories, giving enterprises the confidence to ship software better, faster, and safer.

Writing code is no longer the bottleneck. Governing what reaches production and validating its impact is. As enterprises adopt agentic coding, software is created faster than most teams can review, secure, and validate. Without consistent governance, organizations risk shipping code they cannot explain, audit, or trust.

CloudBees addresses this challenge without asking teams to replace the tools they already use. Across every toolchain a customer runs, CloudBees makes each change, human or AI, visible, auditable, and accountable before it reaches production. CloudBees Unify is the product behind this: a governance layer, with context and control-plane capabilities, that enforces consistent policy and evidence across every tool, team, and workflow.

Founded in 2010, CloudBees is backed by Goldman Sachs, Morgan Stanley, Bridgepoint Capital, HSBC, Golub Capital, Delta-v Capital, Matrix Partners, and Lightspeed Venture Partners.

Visit us at .About the RoleCloudBees builds and runs the internal applications, tools, and AI workflows that power the business. This role brings the same security discipline we build into our own products to that internal estate: threat modelling, secure design, and technical review for the applications, services, and AI-enabled tools our teams build and use.

You'll work closely with the CISO and the wider Security team, partnering with engineering and the business to make sure what gets built in-house is secure by design, not secured after the fact. Your place within the team will depend on your individual strengths and interests.

What You'll DoSecurity architecture and design reviewConduct architecture and design reviews for our applications and servicesLead threat modelling for new tools and features, identifying design flaws and defining security requirementsAdvise engineering and business teams on security best practice as they buildVulnerability management and testingManage penetration testing engagements, from scoping through remediationUse SAST/DAST and vulnerability scanning tools to prioritise and drive down riskPerform secure code reviews where neededSecure SDLCBuild and maintain secure SDLC standards for application developmentCreate patterns and reference architectures that let teams across the business self-serve on securityEvangelise secure development practices, especially for AI and low-code work, and coach rather than gatekeepIntegrate security checks into CI/CDAI and agentic toolingExtend the same rigour to AI tools and agents we build or deploy, including non-human identitiesAdvise on safe adoption of AI coding and agentic tools across engineeringCompliance and incident responseWork with GRC to translate regulatory and compliance requirements (e.g. SOC 2, ISO 27001) into concrete technical controlsLead or support incident response for application security events, grounded in Zero Trust principlesTranslate technical risk into terms non-technical stakeholders can act onWhat You BringRequired: Solid experience in a security-focused engineering role, as a technical strategist as much as a hands-on implementerReal depth in threat modelling and architectural security reviewDeep understanding of common attack vectors and application/infrastructure vulnerabilities (e.g. OWASP Top 10)A thorough understanding of the incident response process and Zero Trust architecture principlesExperience managing penetration testing engagements and working with engineering on remediationComfortable reading and writing code (Python, Go, TypeScript, or similar)Experience with SAST/DAST, vulnerability management toolingStrong written and verbal communication — able to explain technical risk to non-technical stakeholdersComfortable evangelising and coaching security practices with teams that don't have security as their day jobPractical understanding of integrating security into the SDLCDesirable: Cloud security experience (AWS/GCP)Experience with SOC 2, ISO 27001, or similar compliance frameworksExposure to AI/ML security or agentic AI frameworksExperience building automation or tooling to scale a security functionRelevant security certifications (e.g. CISSP, CCSP, CISM, AWS/GCP security specialty) are a plus, not a requirementWorking ConditionsHybrid - Full time Travel requiredAdjustments will be considered to accommodate individual needs in line with applicable equality and disability legislation.

Equal Opportunity StatementCloudBees is committed to providing equal opportunities in employment. We value diversity and inclusion and make decisions based on skills, qualifications, and experience. We do not discriminate on the basis of age, disability, gender identity, marital or civil status, pregnancy, maternity, race, religion or belief, sex, or sexual orientation, in accordance with applicable laws.

Data Protection StatementAll personal data collected during the recruitment process will be processed in line with CloudBees's Privacy Policy and applicable data protection legislation, including the EU General Data Protection Regulation (GDPR).DisclaimerThis job description provides an overview of the role and key responsibilities. It is not an exhaustive list, and responsibilities may evolve in line with business needs.

Job Details

Company
CloudBees
Location
London, UK
Employment Type
Full-time
Posted