- Company Name
- Tesco Technology
- Job Title
- Security Engineer - Application Security
- Job Description
-
Job Title: Security Engineer – Application Security
Role Summary: Lead application security activities by selecting, deploying, and maintaining security tooling that integrates into the DevOps pipeline. Provide technical guidance, training, and support to engineering teams, ensuring secure code practices and compliance with security policies throughout the software development lifecycle.
Expectations: Deliver secure tooling solutions, draft comprehensive guidance, conduct secure code reviews, present risk trade‑offs to business stakeholders, and actively collaborate with cross‑functional teams in an agile environment.
Key Responsibilities:
- Identify and evaluate security toolsets (SCA, SAST, DAST, IaC security) that uncover code and dependency vulnerabilities.
- Deploy and maintain tooling within CI/CD pipelines and DevOps environments.
- Conduct secure code reviews for at least one language (Java, JavaScript/TypeScript, C#).
- Provide domain expertise on application security, privacy, OWASP, Mitre, and CVSS.
- Recommend and implement streamlined security solutions to close gaps in engineering practices.
- Deliver training sessions on core security products to engineering and security teams.
- Create and maintain documentation, guidance, and best‑practice playbooks for security tooling.
- Offer technical support and incident response assistance for security tooling and engineering teams.
Required Skills:
- Strong programming expertise in one or more of: Python, Java, JavaScript/TypeScript, C#, Go.
- Proficiency in secure code review for Java, Javascript, or C#.
- Experience deploying security tooling in DevOps environments (CI/CD, container orchestration).
- Deep understanding of application security disciplines (Web, API, Mobile).
- Knowledge of microservices, container orchestration, and cloud security.
- Solid grasp of SCA, SAST, DAST, IaC security tools.
- Familiarity with OWASP Top 10, Mitre Top 25, CVSS frameworks and risk mapping.
- Excellent written and verbal communication, with ability to translate technical risk to business stakeholders.
Required Education & Certifications:
- Bachelor’s degree or higher in Computer Science, Information Security, or related field (or equivalent practical experience).
- Industry certifications such as CISSP, CISM, or relevant security certifications are advantageous.
Welwyn garden city, United kingdom
On site
13-03-2026