Application Security Engineer
Application Security Engineer
Reports to
Business Information Security Officer (BISO)
Role Summary
We are seeking a hands-on Application Security Engineer to strengthen the security of software products, platforms, APIs, cloud services, and supporting development practices. The role embeds security throughout the software development lifecycle by partnering with product, architecture, engineering, and platform teams to prevent, identify, and remediate vulnerabilities early.
The successful candidate combines strong software engineering capability with practical application security expertise and enables development teams through automation, reusable patterns, coaching, and risk-based guidance rather than acting as a late-stage approval gate. The role supports a secure-by-design approach in which software producers take ownership of customer security outcomes.
Responsibilities
- Embed application security requirements and activities across requirements, architecture, design, development, testing, release, and operations.
- Facilitate threat modeling and security design reviews for applications, APIs, integrations, cloud-native services, and AI-enabled capabilities.
- Perform secure code reviews and targeted manual security testing; reproduce vulnerabilities and provide actionable remediation guidance.
- Engineer, integrate, and continuously improve SAST, DAST, software composition analysis, secrets detection, and related controls in CI/CD workflows.
- Define and maintain secure coding standards, reusable security patterns, reference implementations, and developer guidance.
- Partner with Solution Architects, Security Architects, and platform teams to address authentication, authorization, data protection, cryptography, logging, and secure configuration.
- Triage technically complex application and dependency findings, validate exploitability, and advise on severity, business impact, and remediation options.
- Support development teams in correcting vulnerabilities and verify that fixes address root causes without introducing regressions.
- Coordinate application penetration tests and security assessments; translate findings into sustainable engineering improvements.
- Contribute application security evidence to product risk reviews, audits, and regulatory readiness, including expectations arising from the Cyber Resilience Act.
- Engineer security for desktop clients and hybrid desktop-to-cloud products, including secure update mechanisms, code signing, release integrity, and artifact provenance.
- Implement SBOM generation and dependency governance workflows that support software component visibility, vulnerability response, and regulatory readiness.
- Define and verify security requirements for engineering calculation, configuration, and specification workflows, protecting the integrity and correctness of customer outcomes and project data.
- Support security incident analysis where application behavior, source code, APIs, or software dependencies are involved.
- Support coordinated vulnerability disclosure and product security response by validating reported issues and helping define sustainable corrective actions.
- Establish and coach a network of security champions; deliver practical training and improve developer self-service capabilities.
- Track application security coverage, recurring weakness patterns, remediation performance, and effectiveness of preventive controls.
- Collaborate with cybersecurity, application security, architecture, DevSecOps, product teams, and enterprise security functions.
Required Qualifications
- Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, or a related field, or equivalent practical experience.
- Several years of hands-on experience in software engineering, application security, product security, or DevSecOps.
- Strong programming and scripting skills in at least one language commonly used in modern software development.
- Demonstrated experience with threat modeling, secure code review, and security testing of web applications and APIs.
- Practical knowledge of common vulnerability classes, including the OWASP Top 10, authentication and authorization flaws, injection, insecure design, and software supply chain risks.
- Experience integrating and tuning SAST, DAST, SCA, and secrets scanning tools within CI/CD pipelines.
- Understanding of cloud-native architectures, containers, identity, encryption, logging, and secure configuration.
- Ability to investigate findings, assess exploitability, and communicate technically precise remediation guidance.
- Strong collaboration and coaching skills, with the ability to influence engineering teams without direct authority.
- Strong written and verbal communication skills in English.
- High level of integrity, ownership, and commitment to protecting customers and software assets.
- Experience working with global teams.
- Ability to travel internationally when required for key workshops, assessments, or team collaboration.
- Ability to collaborate effectively across global time zones with teams distributed across multiple continents.
Preferred Qualifications
- Experience securing AWS-based, SaaS, microservices, mobile, or desktop applications.
- Knowledge of NIST Secure Software Development Framework, secure-by-design principles, and risk-driven software assurance using OWASP ASVS and SAMM.
- Experience applying OWASP ASVS at a risk-appropriate assurance level rather than treating every control as universally mandatory.
- Experience with tools such as Burp Suite, OWASP ZAP, Semgrep, SonarQube, Snyk, Checkmarx, GitHub Advanced Security, or equivalent.
- Knowledge of API security, OAuth 2.0, OpenID Connect, JWT, secrets management, and software bill of materials practices.
- Experience applying security to AI-enabled applications and modern software supply chains.
- Relevant certifications such as CSSLP, GIAC GWEB/GWAPT, OSWE, or equivalent.
- Familiarity with engineering or technical software environments is advantageous.
GCS is acting as an Employment Agency in relation to this vacancy.
Application Security Engineer
Other similar jobs
Popular job searches
Your next job
starts here.
JOB SPECIALISMS
LATEST JOBS
TOP SEARCHES
LOCATIONS
- IT Support & Infrastructure
- Engineering
- Controls & Automation
- Data
- Project Management
- BI & Data Analytics
- Network security consultant
- DevOps
- IT Audit & Risk
- Hardware & Electronics
- Testing & QA
- Software Development
LATEST JOBS
- Test Lead
- Senior DevSecOps Engineer
- Product Security Analyst - Vul...
- Application Security Engineer
- Product Owner (Security Cleare...
- Project Manager - Digital & St...
- Controls Technician
- Project Manager - Advertising...
- Project Manager - Ad Sales Cre...
- Fiber Optics Engineer
- Controls Engineer
- machine learning engineer
TOP SEARCHES
LOCATIONS
- Engineer
- Data Scientist
- Senior Data Scientist
- Head of Data Science
- Trainee Data Scientist
- Data Science Graduate
- Senior Financial Accountant
- Management Accountant
- Cost Accountant
- Civil Engineer
- Senior Civil Engineer
- Civil Design Engineer