Application Security Engineer
Would you like to kick start your career in a supportive, collaborative and innovative company? Do you enjoy working as part of an enthusiastic, passionate, and collaborative team? Join our Internal Technology Team! Softcat is an amazing success story and as part of our continued growth we are investing significantly more in a new technology strategy going forward. Softcat's internal Technology Team is undergoing an exciting transformation this evolution aims to provide greater opportunities for our people's professional development and prepare us to execute our more ambitious technology strategy effectively. We're passionate about what we do, how we do it and the positive impact our technologies have on the lives of our employees and customers. With new leadership, a clear vision, an ambitious technology roadmap and a new operating model, we are gearing up to drive some of the biggest technology initiatives in Softcat's history. This is a great opportunity to be a part of rapidly growing and successful company. Success. The Softcat Way. There is a uniqueness to Softcat – what we do, how we do it and why we do it. At the heart of our operations are our core values: Passion, Intelligence, Fun, Responsible and Community. These values are the pillars that Softcat and guide our every action. As one of the UK's leading IT infrastructure providers and a FTSE 250 listed company, we have built a reputation for excellence. Our strategy is simple – we believe that highly engaged employees are the key to building customer trust and loyalty over the years. This trust and loyalty, combined with our market leading growth and performance, enables us to invest in our technology and services capabilities. This investment in turns drives even more engaged employees. We are committed to giving everyone the opportunity to step up and show how much they can achieve. Our success is truly a collective effort - we succeed when all our people succeed. Softcat's Information Security team is seeking an Application Security Engineer with a strong emphasis on cloud security & secure development practice. This role is key to enabling developers to write secure, high-quality code and ensuring our applications and environments meet security standards while enabling teams to deliver value at pace. You will act as a Subject Matter Expert (SME) in application and cloud security, enabling teams to integrate security into the development lifecycle, utilising secure coding practices in their workflows and securing the environments they develop and publish into. As the Application Security Engineer, you'll be responsible for:
- Work with development teams to establish clear guidelines and best practices for secure coding and assist developers in implementing them across multiple languages (Java, C#, .NET, Python)
- Ensuring technologies like SAST, DAST and SCA are utilised effectively
- Establish and communicate metrics to help us understand effectiveness and measure improvement
- Support teams in developing, implementing and maintaining security best practice in cloud environments, including SaaS, PaaS and IaaS.
- Identify security vulnerabilities, devise mitigation strategies, track and address issues effectively, and resolve technical debt.
- Mid-level experience in DevOps / DevSecOps / Application Security roles.
- Strong understanding of secure coding principles and application security.
- Hands-on experience with enterprise data protection and vulnerability management tools.
- Familiarity with cloud security policy configuration.
- Proficiency in multiple programming languages: Java, C#, .NET, Python.
- Familiarity with Terraform and infrastructure-as-code concepts.
- Experience with AI tools for code analysis or automation.
- Hybrid working – 3 days in the office and 2 days working from home
- Working flexible hours - flexing the times you start and finish during the day
- Flexibility around school pick up and drop offs