JOBSEARCHER

Application Security Engineer

Overview In this role you will strengthen the security of applications and APIs for a financial services team. You will work with cross‑functional colleagues to weave security into the software lifecycle, focusing on scalable vulnerability management and secure coding practices. You will drive threat modelling and guide security reviews to mitigate risks at scale. This role offers the chance to shape the security posture across critical applications and participate in a Security Champions program. ResponsibilitiesPerform application security scans (DAST and SCA) on applications and APIs to identify vulnerabilitiesTriage findings and partner with development teams to prioritize and remediate issuesDrive threat modelling as part of the SDLC and maintain models for critical appsLead the Security Champions program and promote secure coding patterns and standardsConduct security reviews and advise on security requirements for new features/projectsAssist in evaluating and rolling out new application security tools, processes, and standards Key requirementsProven experience in application security with testing and vulnerability managementHands-on experience with application security toolsStrong understanding of OWASP Top 10 and mitigation techniquesExperience with threat modelling methodologies and toolsProficiency in at least one programming language (Java, Python, JavaScript)Excellent communication and collaboration skills in cross-functional teamsStrong understanding of risk managementDegree in a technology discipline (Computer Science, Information Management, Computer Engineering, Cybersecurity or equivalent) or equivalent experienceRelevant security certifications (e.g., CISSP, CEH, CSSLP) or equivalent preferredexcellent communicationcollaboration in cross-functional teamsproblem-solving mindsetDAST and SCA toolingthreat modelling methodologies and toolsOWASP Top 10 knowledge