Enable job alerts via email!

Application Security Engineer

Protecht Group

United Kingdom

Hybrid

GBP 40,000 - 80,000

Full time

6 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Join a fast-growing company as an Application Security Engineer, where your passion for application security will thrive. You will work within a dynamic technology team, ensuring that every step of the software development lifecycle follows security best practices. This role offers a unique opportunity to collaborate with talented developers, assess security vulnerabilities, and implement robust security measures for cutting-edge SaaS products. With a strong commitment to learning and development, flexible working arrangements, and a positive culture, this is an exciting opportunity to make a significant impact in the field of application security.

Benefits

Flexible working arrangements
Fortnightly L&D afternoons
Birthday leave
Paid parental leave
Monthly social events
Competitive remuneration
Annual Performance Bonus
Novated car leasing
Wellbeing support
Generous Employee Referral program

Qualifications

  • 2+ years of experience in application security and secure software development.
  • Strong understanding of OWASP Top 10 and secure coding practices.

Responsibilities

  • Review application code for security vulnerabilities and best practices.
  • Drive security awareness among development teams and enforce secure policies.
  • Collaborate with teams to integrate security throughout the software development lifecycle.

Skills

Application Security
Secure Software Development
Threat Modelling
Java
React
API Security
OWASP Top 10
Vulnerability Remediation

Education

Degree in Computer Science
Degree in Information Systems

Tools

JIRA
Confluence
SAST/DAST Tools
AWS
Docker
Kubernetes

Job description

About Protecht

We are a fast growth Governance, Risk & Compliance (GRC) SaaS business. We provide world-class enterprise risk management, compliance, training, and advisory services to over 350 customers across various industry sectors through our offices across APAC, USA & Europe.

Our cloud-based SaaS platform - Protecht.ERM is what makes us really stand out. It's one of the most comprehensive, flexible, and dynamic risk management solutions available today.

The Culture and Benefits you don't want to miss!

At Protecht, you will be part of a growing and high performing technology team. A positive and super friendly culture awaits you, where learning is valued and supported. We empower our people through leadership, training, knowledge-sharing, and mentorship. Here are some of the perks of working with Protecht:

  • A modern Tech Stack and great opportunity to work within a dynamic security team
  • A highly flexible culture - our way of working lets people work across home and our offices
  • A strong commitment to your learning and development - fortnightly dedicated L&D afternoons
  • Reward & Recognition programs
  • A strong focus on work / life balance with access to Birthday leave, bonus days, paid parental leave and long service leave
  • Monthly social events
  • Competitive remuneration and Annual Performance Bonus
  • Novated car leasing
  • Wellbeing support
  • Generous Employee Referral program

Let's talk about your new role!

As our Application Security Engineer, you will help ensure that every step of the software development lifecycle follows security best practices in supporting and developing our SaaS product - Protecht.ERM (Enterprise Risk Management). Located in our central Sydney office and reporting to the Head of Cyber Security, you will be working in a fun and exciting security team that strives to implement best security practices for development, testing and agile project delivery.

Key responsibilities

  • Review application code for security vulnerabilities and best practices.
  • Help Protecht developers deliver high quality and security hardened code based on OWASP and Protecht secure coding standards - without the requirement to write code.
  • Help Protecht developers to assess and remediate security vulnerabilities.
  • Help Protecht developers to assess and review 3rd party libraries.
  • Drive and upskill Protecht developers to maintain a security aware culture.
  • Own and enforce secure development policies amongst the Protecht development teams.
  • Create and maintain documentation to support the development of secure software.
  • Review automated security testing tools (SAST, DAST).
  • Build and integrate automated security tools into CI/CD pipelines for continuous security testing.
  • Work closely with Protecht developers and platform teams to integrate security throughout the Software Development Life Cycle (SDLC).
  • Ensure security requirements are incorporated into the design phase and architecture reviews.
  • Perform threat modelling with the Protecht development teams to identify and prioritize potential security risks during the design phase.
  • Monitor the evolving threat landscape and proactively conduct security research to identify common application threats and attack vectors to then develop mitigating solutions and minimise risk.
  • Collaborate with external stakeholders for the scoping, managing, validating and remediating of vulnerability assessment and penetration tests.
  • Participate in audits and reviews to validate the security of applications (ISO27001, SOC2, IRAP).
  • Ensure applications comply with relevant security standards and regulations (e.g., OWASP, GDPR).
  • Collaborate in an agile environment with cyber security, development and platform teams.
  • Contribute to various security projects and assist the Head of Cyber Security in delivering the cyber security roadmap.

Skills / Experience you need for success...

This role suits you if you have:

  • A passion for application security!
  • Relevant tertiary qualification such as a degree in computer science or information systems
  • 2 or more years proven commercial experience in application security.
  • Strong understanding of secure software development fundamentals.
  • Understanding and experience with common security libraries, security controls, and common security vulnerabilities.
  • Experience with architecture and security reviews, threat modelling applications.
  • Familiarity with Java and React development and related security concerns, including secure coding practices and Java-specific vulnerabilities.
  • Understanding of API security and the ability to assess and secure RESTful APIs.
  • Understanding of OWASP Top 10 and the ability to apply it to identify and mitigate risks in web applications.
  • Expertise in identifying, analysing, and remediating common security vulnerabilities (e.g., injection attacks, cross-site scripting, cross-site request forgery).

Desirable attributes

  • Experience with cloud infrastructure environments (AWS) and containerized environments (Docker, Kubernetes)
  • Understanding of identity providers (SAML, SCIM)
  • Experience with SAST/DAST tools
  • Experience using JIRA and Confluence
  • Understanding of risk management
  • Exposure to penetration testing for web applications
  • Security / Application Security Certifications (CISSP, CEH, OSCP, CREST)

Next steps

With a swift screening and interview process in place, we are happy to invite you to apply. If you think this may be your next opportunity and you want to be part of a Great Place to Work - Certified organization, Apply online today!

Visit our website https://www.protechtgroup.com/ to find out a little more about working with us.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.