# Security Engineer, Application Security

**Company:** [Writer](https://hotfix.jobs/companies/writer)
**Location:** London, United Kingdom
**Role:** Security Engineering
**Experience:** 4+ years
**Skills:** Application Security, Threat Modeling, SAST, DAST, CI/CD, Python, Java, Go, JavaScript, TypeScript, DevSecOps, Penetration Testing, Llm Security, Vulnerability Management, Secure Coding
**Posted:** 2026-09-04

> Build and scale application security for an enterprise AI platform through threat modeling, secure architecture, automated controls, code review, penetration testing, and AI/ML threat research. Requires 4+ years of application security experience and proficiency in at least two programming languages.

## Job Description

## Responsibilities
- Conduct threat modeling with product teams and design secure architectures for new features.
- Own and evolve the application security program, including SAST/DAST scanning in CI/CD pipelines, security code reviews, and vulnerability-detection automation.
- Establish secure coding standards and create reusable security patterns and libraries.
- Design and recommend security features and products for customer environments.
- Integrate AI agents to increase security-team and engineering velocity while proactively minimizing risk.
- Lead security assessments and penetration testing for applications, AI services, and APIs.
- Design and implement controls protecting data pipelines, model-training environments, and customer-facing AI agents.
- Research emerging AI/ML security threats, including LLM and generative-AI attack vectors, and build proactive defenses.

## Requirements
- 4+ years of hands-on application security engineering experience securing large-scale production systems.
- Understanding of developer experience and workflows for shipping features and products.
- Expertise in at least two programming languages, such as Python, Java, Go, or JavaScript/TypeScript.
- Ability to read and review code across multiple languages, including business logic and security implications.
- Knowledge of SAST/DAST solutions, vulnerability-management platforms, security-testing frameworks, and DevSecOps practices.
- Strong communication skills for explaining security concepts to technical and non-technical audiences.
- Builder's mindset focused on automation, scalability, and enabling engineering teams.

## Benefits and Perks
- Generous paid time off and company holidays.
- Medical and dental insurance.
- 16 weeks of paid parental leave for all parents.
- Fertility and family-planning support.
- Early-detection cancer testing.
- Competitive pension scheme and company contribution.
- Wellness, learning and development, and work-life stipends.
- Company-wide and team off-sites.
- Company stock options.

## Similar jobs

- [Platform Security Engineer](https://hotfix.jobs/jobs/e556dd76-0f95-4dfa-9d3d-e476f24057c0) - Supabase - Remote
- [Software Engineer, Trust & Safety](https://hotfix.jobs/jobs/ccbdc9a4-a902-479b-845f-0d13a50d97a0) - Vercel - San Francisco, CA - $196k – $294k/yr
- [Security Engineer, Incident Response](https://hotfix.jobs/jobs/83eb71b2-95d7-4319-85af-294442d49213) - Twilio - Remote
- [Manager, Security Operations](https://hotfix.jobs/jobs/0a4637da-6072-4ec3-a0a9-8b6d4a412d45) - Vanta - Remote - $178k – $209k/yr
- [Senior Security Engineer, Offensive Security](https://hotfix.jobs/jobs/e6f5289c-9cb8-4a13-b321-e0ecc9a54c96) - Docker - Remote - €119k – €170k/yr

**Apply:** https://hotfix.jobs/jobs/8c8a3f77-9f1b-45b4-b825-819dd30e2fb0
**Canonical:** https://hotfix.jobs/jobs/8c8a3f77-9f1b-45b4-b825-819dd30e2fb0