Application Security Engineer Jobs

Specialists who ensure the security of software applications. A critical role in the defence against cyber threats, combining technical expertise with a deep understanding of application vulnerabilities.

Open roles
1
Salary range
£58k – £93k
Hiring companies
1

Application Security Engineers play a vital role in the cyber security landscape by identifying and mitigating vulnerabilities in software applications. They work closely with development teams to integrate security into the software development lifecycle (SDLC), ensuring that applications are robust and resilient against attacks. This role is in high demand across various sectors, including finance, healthcare, and technology, where the protection of sensitive data is paramount.

What the role does

Inside the role of an Application Security Engineer

A typical week is split between code reviews, vulnerability assessments, and collaborating with developers to implement security measures.

  1. 01
    Conduct code reviews to identify security flaws
  2. 02
    Perform vulnerability assessments and penetration testing
  3. 03
    Collaborate with developers to integrate security into the SDLC
  4. 04
    Monitor and respond to security alerts and incidents
  5. 05
    Document findings and provide recommendations for improvement
Salary on the board

£58k – £93k

Based on advertised midpoints across the 5 priced listings posted in the last 12 months. Base salary only.

Salary visibility
11% of listings advertise a salary — up from 0% the year before.
Skills & tools

What hiring managers ask for

% of 5 listings posted in the last 12 months that mention each skill, extracted from job descriptions.

CI/CD
80%
SAST
80%
DAST
80%
Azure
80%
Terraform
80%
Threat Modelling
60%
Application Security
60%
AWS
40%
GCP
40%
AI/ML
40%
OAuth2
40%
OIDC
40%
Career ladder

From Junior to Principal

A typical UK progression for application security engineers. Years are guidance — strong people move faster, and many senior folks sidestep into research, product or management.

  1. Level 1

    Junior Application Security Engineer

    0–2 yrs

    Assists in code reviews and vulnerability assessments, learning the fundamentals of application security.

  2. Level 2

    Application Security Engineer

    2–5 yrs

    Leads code reviews and vulnerability assessments, and collaborates with development teams to implement security measures.

  3. Level 3

    Senior Application Security Engineer

    5–8 yrs

    Takes ownership of complex security projects, mentors junior engineers, and advises on security strategy.

  4. Level 4

    Principal Application Security Engineer

    8+ yrs

    Drives the overall security vision, leads major initiatives, and influences organisational security policies.

Pathway

How to become a Application Security Engineer

There's no single route, but most people follow some version of these steps.

  1. 1

    Learn the basics

    Start with foundational knowledge in programming, networking, and security principles.

  2. 2

    Gain practical experience

    Work on real-world projects, such as code reviews and vulnerability assessments, to apply your knowledge.

  3. 3

    Specialise in application security

    Focus on application security frameworks, tools, and best practices to deepen your expertise.

  4. 4

    Obtain relevant certifications

    Consider certifications like Certified Secure Software Lifecycle Professional (CSSLP) or Offensive Security Certified Professional (OSCP) to validate your skills.

  5. 5

    Lead security initiatives

    Take on leadership roles, guiding teams and driving security improvements across the organisation.

  6. 6

    Influence security strategy

    Shape the overall security strategy, influencing organisational policies and driving innovation in application security.

Live jobs

1 live role

Amazon logo

Application Security Engineer

This role involves conducting application security reviews, penetration testing, and developing security tools to safeguard Amazon's services and customer-facing applications. The engineer will also contribute to security training, documentation, and metrics, while collaborating with development teams to embed security best practices. Work spans proactive research, automation, and rapid response to emerging threats in a large-scale cloud environment.

Amazon London, United Kingdom
Permanent
Hiring locations

Where this role is hiring

The locations with the most live listings for this role today.

FAQs

Common questions

  • Essential skills include programming, knowledge of security frameworks, experience with vulnerability assessment tools, and a strong understanding of the software development lifecycle.

  • Gain experience in software development or IT security, specialise in application security, and consider relevant certifications to demonstrate your expertise.

  • Working hours can vary, but most roles follow a standard 9-to-5 schedule. However, some roles may require on-call availability for incident response.

  • Salaries vary based on experience and location. For more detailed salary information, please refer to the salary section on this page.

Hiring application security engineers?

Post your role in 90 seconds and reach the specialist audience that already reads this page.