Remote job
Staff Application Security Engineer
Job details
About this role
Role overview
A Staff Application Security Engineer position responsible for shaping the technical direction of application security and vulnerability management across cloud services, internal systems, and firmware running on connected IoT hardware. The role combines program ownership with hands-on influence over a broad attack surface, including the flexibility to dive deep into evolving security priorities. The position is remote, with candidates based in the UK.
Responsibilities
- Lead the strategy, operation, and continuous improvement of the vulnerability management program and other core application security initiatives - Reduce mean time to remediate (MTTR) across the vulnerability backlog as service-level expectations tighten - Build and champion automation and tooling that scale vulnerability detection and response across cloud, firmware/IoT, and corporate environments - Set technical and architectural direction, translating leadership strategy into a concrete execution plan for the team - Partner with engineering teams to drive remediation through clear, actionable guidance rather than manual case-by-case review - Mentor engineers on secure design and remediation practices, serving as a trusted technical voice when priorities are unclear - Communicate risk and remediation tradeoffs to engineering leadership in terms they can act on - Participate in security incident investigations involving high-profile vulnerabilities and assess potential impact on infrastructure - Be on call periodically to support critical vulnerability response
Requirements
- Extensive background in application security, vulnerability management, or a closely related discipline at scale - Proven ability to design and build automation and tooling for security detection and response across diverse environments - Track record of setting architectural direction and leading the technical strategy of a security program - Strong collaboration skills with engineering teams and leadership, including clear written and verbal communication of risk - Demonstrated mentoring experience with other engineers on secure development practices - Eligibility to work remotely in the UK
Benefits and work setup
- Fully remote role open to candidates residing in the UK - Relocation assistance is not provided for this position