Senior Application Security Engineer
Team: Security Operations
Location: United Kingdom - Remote, Portugal - Remote, Spain - Remote, South Africa - Remote
Commitment: Full Time
Workplace Type: remote
What You Will Do
- Conduct threat modelling reviews of Technical Design Documents (TDDs) for new and existing features, providing clear, actionable security recommendations early in the design process.
- Perform and support application security assessments, including penetration testing, vulnerability assessments, and proof-of-concept (PoC) development where appropriate.
- Investigate, triage, and respond to Bug Bounty program submissions, validating findings and working with engineering teams to drive timely remediation.
- Own and continuously improve application-layer protections, including managing and tuning Cloudflare WAF and related security controls.
- Partner closely with engineering teams to embed security best practices throughout the SDLC, from design and development through deployment and maintenance.
- Research and track emerging threats and vulnerabilities, translating findings into practical mitigation strategies relevant to our technology stack.
- Develop and deliver security guidance, training, and awareness for engineering teams to raise the overall security maturity of the organization.
- Contribute to the creation, maintenance, and evolution of security standards, processes, and documentation.
- Participate in and eventually lead incident response activities, supporting investigation, containment, remediation, and post-incident improvements.
About You
- You have developed a breadth of experience across multiple security domains, including web and mobile application security, infrastructure and cloud security, and can connect these areas to drive a holistic security approach.
- You have hands-on experience performing white-box, source code-assisted web and mobile application penetration testing, from vulnerability discovery through triage and exploitation.
- You have the ability to read, understand, and review source code to identify security issues, with ideally, a particular focus on JavaScript and TypeScript codebases.
- You have a strong understanding of Threat Modelling principles and their practical application to the secure software development lifecycle (SDLC).
- You have experience working with web application firewalls to help protect applications, assess coverage, and support tuning rules to mitigate common attack patterns.
- You have experience embedding application security practices into CI/CD pipelines, enabling early detection of vulnerabilities and close collaboration with engineering teams throughout the development lifecycle.
- You have collaborated closely with engineering teams to clearly communicate security findings, explain vulnerabilities, attack paths, and mitigations, and support the implementation of effective fixes for both technical and non-technical audiences.
- You are self-motivated, proactive, and take strong ownership of your work, operating effectively in a remote environment while maintaining a collaborative, team-focused mindset.
- You have experience in JavaScript and TypeScript, including the ability to read, understand, and reason about modern web application codebases.
- You have experience working with Cloudflare, including its hosting and Web Application Firewall (WAF) capabilities, to help secure and operate internet-facing applications.
- You have experience testing and securing GraphQL, REST APIs, including understanding common GraphQL/REST-specific attack vectors and security considerations.
- You have experience or a strong interest in Web3 security testing, including assessing smart contracts, blockchain-based applications, or Web3 integrations.
- You have an interest in agentic engineering, including emerging patterns in autonomous systems, tooling, or workflows, and their security implications.
Bonus Points
- You contribute or have contributed to the security community through open source involvement, participation in CTFs, or speaking at local information security meetups and conferences.
- Your background includes experience working with disruptive technologies and successfully launching products, ideally within FinTech, SaaS, or Crypto.
- You hold one or more security relevant certifications such as OSCP or OSWE.
There are more than 50,000 engineering jobs:
Subscribe to membership and unlock all jobs
Engineering Jobs
60,000+ jobs from 4,500+ well-funded companies
Updated Daily
New jobs are added every day as companies post them
Refined Search
Use filters like skill, location, etc to narrow results
Become a member
🥳🥳🥳 452 happy customers and counting...
Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.
To try it out
For active job seekers
For those who are passive looking
Cancel anytime
Frequently Asked Questions
- We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
- We've got over 200,000 jobs from 15,000+ vetted companies. No fake or sleazy jobs here!
- We aggregate jobs from 15,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
- We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
- Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
- Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
- Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅
What Fellow Engineers Say
