Application Security Engineer
ETeam- Posted an hour ago
- Be among the first 10 applicants
Job Description
Minimum Qualifications
- 8-12 years in technology, with 5+ years in application security engineering, DevSecOps or a security-engineering role with hands-on pipeline and tooling ownership.
- Demonstrable experience designing and operating DevSecOps pipelines: SAST, DAST, SCA, secrets detection, container scanning and SBOM generation integrated into CI/CD.
- Hands-on experience with security tooling (GitHub Advanced Security, Checkmarx, Snyk, Trivy, OWASP ZAP or equivalent) in enterprise engineering environments.
- Azure cloud security engineering knowledge: IAM, Key Vault, network controls, container/Kubernetes security, IaC scanning.
- Working knowledge of OWASP Top 10, NIST, secure coding principles and vulnerability management, with ability to translate findings into engineer-ready remediation guidance.
Preferred Qualifications
- Insurance or financial-services industry experience.
- Security certifications (CSSLP, CEH, OSCP, GWEB) and/or Azure security certifications (AZ-500, SC-100).
- Experience applying AI and automation to security engineering (GenAI-assisted triage, agentic pipelines, GitHub Copilot for secure code review).
- Experience enabling federated engineering teams and security champions at scale, across distributed LOB structures.
- Familiarity with IriusRisk, threat modelling tooling or security architecture review as a consumer of outputs from those practices.
Key Skills & Competencies
- Technical: DevSecOps pipeline engineering, SAST / DAST / SCA / SBOM, build integrity and supply chain security, Azure cloud security (IAM, Key Vault, CSPM, IaC), secrets management, container and Kubernetes security, OWASP / NIST / ISO 27001, vulnerability triage and management, AI and automation (GenAI, Copilot, agents).
- Collaboration: clear written and verbal communication of technical risk to non-specialist audiences, ability to embed into delivery teams without becoming a bottleneck, structured prioritisation and critical thinking, coaching and enablement mindset.
Work Conditions
- Hybrid working model.
- Work with global teams across multiple time zones and across the HWC lines of business
Contract Length: 6 months
• Shift Schedule: 3PM – 12MM PHT / 8AM – 5PM UK
• Work Arrangement: Hybrid
• Hiring Timeline: ASAP, very urgent
• Non negotiable(must-have
• 8-12 years in technology, with 5+ years in application security engineering, DevSecOps or a security-engineering role with hands-on pipeline and tooling ownership.
• Demonstrable experience designing and operating DevSecOps pipelines: SAST, DAST, SCA, secrets detection, container scanning and SBOM generation integrated into CI/CD.
• Hands-on experience with security tooling (GitHub Advanced Security, Checkmarx, Snyk, Trivy, OWASP ZAP or equivalent) in enterprise engineering environments.
• Azure cloud security engineering knowledge: IAM, Key Vault, network controls, container/Kubernetes security, IaC scanning.
• Working knowledge of OWASP Top 10, NIST, secure coding principles and vulnerability management, with ability to translate findings into engineer-ready remediation guidance.
More Info
Key Skills
NIST secure coding principles
GenAI
AI and automation
Key Vault
container scanning
Kubernetes security
network controls
secrets detection
SBOM generation
OWASP ZAP
Trivy
Azure cloud security
Snyk
IaC scanning
GitHub Copilot
GitHub Advanced Security


