This job has expired

This job posting is no longer active and is not accepting applications. Explore similar roles below!

Virgin Media O2
Posted 2mo ago

Senior Application Security Engineer - 12 Month Fixed Term Contract

Virgin Media O2
Uxbridge, England, United Kingdom
HybridFull Time
Responsibilities
  • embedding security
  • conducting reviews
  • managing vulnerabilities
Requirements
  • Expertise in application security including secure code review
  • Threat modeling, and vulnerability management
  • Experience with Java/TypeScript/Python
  • SAST/DAST/SCA tools
  • OWASP Top 10
  • AWS and Terraform
  • CI/CD and DevSecOps
  • Container/Kubernetes security
Technical tools mentioned
JavaTypeScriptPythonSASTDASTSCAOWASP Top 10AWSTerraformKubernetesCI/CD

Job description

This role is a 12 Month Fixed Term Contract

As a Senior Application Security Engineer at giffgaff on a 12-month fixed-term contract, you'll be responsible for embedding security into the way we design, build and operate our products. Working across a modern technology estate, you'll help ensure security is considered from the earliest stages of development through to production, enabling engineers to deliver secure software with confidence.
This role combines technical depth with collaboration and influence. You'll work alongside engineers, architects and platform teams to identify risks, improve security controls, drive vulnerability remediation and strengthen our DevSecOps capabilities. You'll also help foster a strong security culture by coaching teams and championing security best practice throughout the business.

Who we are

Do you want to join a connectivity provider that's up to good? At giffgaff, we do things differently. We call out the bad and find a better way. We're laser-focused on flexibility, value and mutual good. And we're proud to be a certified B Corp. This means we've joined a network of more than 2,000 UK companies who want to make a positive impact on people and the planet. Working at giffgaff is something you could be proud of too.
You'll get the best of both worlds, the energy and fast pace of giffgaff, plus all the benefits that come with being part of our parent company, Virgin Media O2.
Our business model is unique. We work with our members (our customers) to understand their needs in all areas of the business. We love this highly collaborative approach. We're always looking to acquire new members, and to do that we need the best people in our team.
In return for your outstanding efforts, you'll be rewarded with a competitive salary and excellent benefits that are all about making your work life a winner. Take a look at our culture and benefits - you might just be surprised.
Our bright and modern gaff is in Uxbridge, in leafy West London. But if commuting isn't for you, most of our roles can be hybrid or remote, or anywhere in between.

The other stuff we are looking for

We'd also love you to bring;
• Security certifications such as OSCP, GWAPT, CSSLP, CEH or Security+.
• Experience securing AWS environments and infrastructure-as-code solutions such as Terraform.
• Knowledge of AI-enabled security workflows and securing AI or LLM-powered features.
• Experience contributing to or maintaining open-source security tooling.

About Virgin Media O2

Provides mobile, broadband, and television communication services.

Similar jobs

Application Security Engineer roles near Uxbridge, England
3mo
Save
Mark Applied
Hide
Security engineer, application security (UK)
London, England, United Kingdom
HybridFull Time
Writer
Writer: Platform for building and deploying enterprise generative AI agents.
4+ YOE4+ years in application security; strong SDLC security; experience with SAST/DAST, CI/CD security; programming in Python/Java/Go/JS/TS; strong communication; automation mindset.
Python, Java, Go, JavaScript, TypeScript, SAST, DAST, CI/CD, DevSecOps
1d
Save
Mark Applied
Hide
Application Security Engineer
London, England, United Kingdom
OnsiteFull Time
Just Eat Takeaway.com
Just Eat Takeaway.comEuronext Amsterdam: TKWY: An online marketplace connecting consumers with restaurants for food delivery.
Experience defining security controls, applying OWASP Top 10, using SCA, SAST, and secrets tools, addressing SDLC vulnerabilities, securing AI applications, and managing stakeholders.
OWASP Top 10, SCA, SAST, Secrets, AI, LLM
1d
Save
Mark Applied
Hide
Application Security Engineer
London, England, United Kingdom
HybridFull Time
Simply Business
Simply Business: An insurance provider using technology to make small business insurance more accessible.
5+ YOE5+ years of application security experience, penetration testing and security tooling expertise, web vulnerability and secure coding knowledge, cloud experience with AWS, Azure, or GCP, and familiarity with DevSecOps.
OWASP Top 10, SAST, DAST, IAST, AWS, Microsoft Azure, GCP
3d
Save
Mark Applied
Hide
Senior Application Security Engineer
London or Oxford
HybridFull Time
Tripadvisor
TripadvisorNASDAQ: TRIP: Online platform for travel reviews, bookings, and trip guidance.
4+ YOERequires 4+ years in security engineering or application security, with secure coding, threat modeling, vulnerability assessment, incident response, cloud security, security testing, and leadership experience.
SAST, DAST, AWS, Azure, GDPR, PCI-DSS, SOC 2
1w
Save
Mark Applied
Hide
Senior Application Security Engineer
Toronto or London or New York City or Pune
OnsiteFull Time
TripleLift
TripleLift: Programmatic advertising platform for high-quality digital ad experiences.
5+ YOERequires 5+ years in application security or security engineering, secure coding, SAST/DAST/SCA, CI/CD security, penetration testing, threat modeling, AWS security, and cybersecurity frameworks.
GitHub Advanced Security, SAST, DAST, SCA, CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode, CI/CD, Python, Java, TypeScript, Go, NIST CSF, PCI, SOC2, HITRUST, ISO 27001/2, AWS, IAM, VPC, KMS, GuardDuty, CloudTrail, Claude
1w
Save
Mark Applied
Hide
Application Security Engineer
London, England, United Kingdom
OnsiteFull Time
Amazon
AmazonNASDAQ: AMZN: Global online retail and cloud computing technology provider.
3+ YOERequires a bachelor's degree, 3+ years programming experience, 2+ years security coding and troubleshooting, networking knowledge, and application security experience.
Python, Ruby, Go, Swift, Java, .Net, C++, HTTP, DNS, TCP/IP, command line tools, AWS, UDP, IPSEC, SSL/TLS, Perl
4w
Save
Mark Applied
Hide
Application Security Engineer
London, England, United Kingdom
OnsiteFull Time
Universal Music Group
Universal Music GroupEuronext Amsterdam: UMG: Produces, distributes, and publishes music and manages global artists.
3+ YOE3+ years vulnerability management experience, administer Veritas and Cortex XDR, familiarity with Nessus/Qualys/Tenable/OpenVAS, AWS/Azure, OS administration, scripting, and professional security certifications.
Veritas eDiscovery, Cortex XDR, Nessus, Qualys, Tenable, OpenVAS, Microsoft, Mac OS X, Linux, Python, PowerShell, Amazon AWS, Microsoft Azure, Google Compute, VMware Tanzu CloudHealth
1mo
Save
Mark Applied
Hide
Lead Application Security Engineer
London, England, United Kingdom
OnsiteFull Time
CAIS
CAIS: A financial technology platform for alternative investment marketplace access.
Experience in application/product security with a software engineering background; proficiency in Java/Kotlin and JavaScript/TypeScript (React); strong AWS and container (EKS) security experience; hands-on SAST/DAST and CI/CD automation; threat modeling and security architecture leadership; experience adopting AI-assisted security workflows.
Java, Kotlin, JavaScript, TypeScript, React, AWS, EKS, SAST, DAST, CI/CD
This job has expired