Application Security Engineer
Job description
Application Security Engineer
Location: London (Hybrid)
Contract: Inside IR35We're looking for a hands-on Application Security Engineer to join a growing cyber engineering team. You'll play a key role in vulnerability remediation, security incident response, identity and secrets management, and security automation across cloud and application environments.
Key ResponsibilitiesManage the end-to-end HackerOne lifecycle, from triage to remediation and closure.Support security incident investigations and implement effective fixes.Provide guidance on Okta and Doppler integrations and best practices.Design and build security automation to improve scale and efficiency.Partner with the Director of Cybersecurity on AppSec, DevSecOps, and cloud security initiatives.Required ExperienceHands-on experience with HackerOne or similar bug bounty platforms.Strong web application security knowledge (OWASP Top 10, ASVS, threat modelling).Experience building security tooling and automation.Familiarity with security testing tools such as Burp Suite.Exposure to incident response and application security.Strong communication and stakeholder engagement skills.Desirable SkillsPython scripting.SAST, DAST, SCA, and secrets-scanning tools.GitHub Actions, Terraform, Kubernetes, and IAM security.Okta (OIDC, SAML, MFA) and Doppler experience.AWS Cloud Security expertise.
Guidant, Carbon60, Lorien & SRG - The Impellam Group Portfolio are acting as an Employment Business in relation to this vacancy.
first seen 2026-09-02 12:00:01 · last verified 2026-09-16 16:00:01
pentestcareers.com // breach the job market