Remote job
Senior Application Security Engineer
Job details
About this role
Role overview A senior application security role within a global travel and experiences organisation, focused on protecting the platforms that connect travellers with partners across accommodations, restaurants, and bookable activities. The position is a hands-on technical lead role that combines architecture, code-level review, and people mentorship across multiple engineering teams. It is based in London, UK, on a permanent contract.
Responsibilities - Design and roll out advanced application security controls covering encryption, secure APIs, and identity management. - Run threat modelling and risk assessments, and lead manual security reviews including code audits. - Act as the subject matter expert during security incidents, performing root cause analysis and defining corrective actions. - Define, enforce, and scale application security policies across multiple engineering teams. - Coach and mentor junior engineers, raising the overall security skill level of the organisation. - Partner with engineering and product teams to embed security requirements throughout the software development lifecycle.
Requirements - Extensive experience in application security, including secure coding, threat modelling, vulnerability assessment, and incident response. - Hands-on experience with SAST and DAST tools and their integration into development pipelines. - Strong grasp of encryption, secure software design, identity management, and API security. - Experience securing cloud environments (AWS, Azure, or similar) and microservices architectures. - Demonstrated leadership and mentoring ability, with a track record of influencing security practices across teams. - Excellent communication and cross-functional collaboration skills, plus 4+ years working as a Security Engineer or Application Security Analyst.
Nice to have - Familiarity with regulatory frameworks such as GDPR, PCI-DSS, or SOC 2 and how they map to security processes. - Industry-recognised certifications such as OSCP or OSCE. - Passion for mentoring and continuous learning, and curiosity about new security tools and frameworks.
Benefits and work setup - Competitive base salary plus annual bonuses, benchmarked against industry data. - Remote-friendly collaboration model with optional office presence. - Flexible scheduling built on trust and accountability. - Donation matching for qualifying charitable contributions. - Annual tuition assistance for approved professional development programmes. - Lifestyle benefit allowance usable on travel, wellness, or personal priorities. - Travel discounts and perks, an employee assistance programme, health benefits, and a referral scheme.