Application Security Engineer
Application Security Engineer Location: London (Hybrid) Contract: Inside IR35
Required Experience
Desirable Skills
We're looking for a hands-on Application Security Engineer to join a growing cyber engineering team. You'll play a key role in vulnerability remediation, security incident response, identity and secrets management, and security automation across cloud and application environments.
Key Responsibilities- Manage the end-to-end HackerOne life cycle, from triage to remediation and closure.
- Support security incident investigations and implement effective fixes.
- Provide guidance on Okta and Doppler integrations and best practices.
- Design and build security automation to improve scale and efficiency.
- Partner with the Director of Cybersecurity on AppSec, DevSecOps, and cloud security initiatives.
Required Experience
- Hands-on experience with HackerOne or similar bug bounty platforms.
- Strong web application security knowledge (OWASP Top 10, ASVS, threat modelling).
- Experience building security tooling and automation.
- Familiarity with security testing tools such as Burp Suite.
- Exposure to incident response and application security.
- Strong communication and stakeholder engagement skills.
Desirable Skills
- Python Scripting.
- SAST, DAST, SCA, and secrets-scanning tools.
- GitHub Actions, Terraform, Kubernetes, and IAM security.
- Okta (OIDC, SAML, MFA) and Doppler experience.
- AWS Cloud Security expertise.
Guidant, Carbon60, Lorien & SRG - The Impellam Group Portfolio are acting as an Employment Business in relation to this vacancy.