Senior Application Security Engineer
Cambridge, England, United Kingdom (Hybrid) · Full Time
Be the first to apply
- Experience
- Any
- Salary
- GBP 60,000 – GBP 75,000 / year
- Openings
- 1
- Posted
- 1 week ago
- Work mode
- Hybrid
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Overview
Based in Cambridge with a flexible hybrid schedule requiring office presence every two weeks, this permanent position offers a salary range from £60,000 to £75,000 depending on experience. Redgate Software's product teams rapidly develop AI and cloud-native solutions, where security integration is crucial throughout the development cycle rather than a final checkpoint.
About Redgate
Redgate fosters a culture of trust, accountability, and teamwork, creating tools for data professionals to securely manage organizational data and databases amid increasing data regulations and AI use. By 2028, Redgate aims to integrate expert knowledge with AI assistance to accelerate customer value, utilizing advanced AI tools from the outset.
Role Purpose
The Product Security team embedding security principles into multiple product and engineering teams needs a senior engineer who will shape security standards, guide threat modeling, and make critical security decisions that align with fast-paced software delivery. The focus is on pragmatic security practices over mere compliance.
Key Responsibilities
- Collaborate closely with engineering and product teams to establish and enforce security requirements across the entire software development lifecycle.
- Manage application security governance by developing secure-by-default standards, reusable patterns, guardrails, and handling risk exceptions.
- Lead threat modeling for feature development and architectural changes, translating insights into actionable engineering tasks.
- Enhance the use and quality of static and dynamic application security testing (SAST/DAST), including configuring tools, calibrating severity levels, and providing developer-focused triage support.
- Support product teams working with AI technologies such as large language models (LLMs), secure language models (SLMs), and model content protection (MCP), engaging in advanced security challenges few roles experience.
Required Qualifications and Experience
- Practical experience in product or application security, successfully integrating security processes within modern SDLC frameworks.
- Code review proficiency with the ability to clearly communicate security findings to developers; primary expertise in C# with exposure to Java and Python.
- Strong familiarity with OWASP Top 10 vulnerabilities and effective mitigation strategies.
- Experience setting up or improving SAST/DAST pipelines, including tuning tools, triage methods, and minimizing false positives.
- Knowledge of cloud and container security basics, ideally including AWS and Docker ecosystems.
Benefits and Working Conditions
- Competitive salary £60,000 to £75,000, adjusted for experience.
- Hybrid working model blending home and office presence in Cambridge.
- Monthly wellbeing allowance plus generous paid leave.
- Commitment to professional growth and career advancement.
- Private health insurance coverage.
Recruitment Process
- Applications are evaluated directly by human Talent Partners; no AI or automated screening tools used.
- Candidates receive timely feedback within days.
- The interview process is designed to be clear and consistent to candidates.
Diversity and Inclusion
Redgate values a respectful, fair, and trustworthy workplace where diverse perspectives improve outcomes. Hiring decisions prioritize skill, potential, and value alignment, supporting an inclusive culture.