wagey.ggwagey.ggv1.0-38ee235-5-May
Browse Tech JobsCompaniesFeaturesPricingFAQs
Log InGet Started Free
Jobs/Application Security Engineer Role/teya - Application Security Engineer
teya

teya - Application Security Engineer

London, United Kingdom, Hybrid2mo ago
In OfficeSeniorEMEAPaymentsFintechApplication Security EngineerAdvisorNode.jsTypeScriptGoDocumentationCPC

Upload My Resume

Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT

Apply in One Click
Apply in One Click

Requirements

• 6+ years’ experience in application security, security engineering, or software engineering with a strong AppSec focus • Demonstrated experience designing or operating Secure SDLC practices in fast-moving product teams • Hands-on expertise in web and API security, including authentication, authorisation, data flows, and common vulnerability classes • Proven experience integrating SAST, DAST, and SCA into CI/CD pipelines • Strong threat modelling and secure design skills for complex, cloud-native systems • Experience with modern backend and frontend or mobile stacks (e.g. JVM, Node.js, Go, TypeScript) • Familiarity with AWS and cloud-native architectures (IAM, KMS, containers, microservices) • Clear, pragmatic communication skills and the ability to influence through partnership rather than mandate • Experience in fintech, payments, or other regulated environments • Familiarity with OWASP ASVS, OWASP Top 10, PCI DSS, DORA, or ISO 27001 • Exposure to mobile security, API gateways, WAFs, or infrastructure-as-code • Security or cloud certifications (e.g. OSWE, OSCP, CSSLP, CISSP, AWS Security) • Ways of working • Extreme ownership: You take end-to-end responsibility for outcomes, not just findings or tooling output • Pragmatic and delivery-aware: You balance risk reduction with product velocity, focusing on changes that materially reduce risk • Low-ego and collaborative: You build trust with engineers, product, and operations teams, influencing through credibility and partnership • Impact-driven: You measure success through outcomes—risk reduction, adoption, and time-to-remediate—not activity • Data-informed: You use metrics and trends to guide priorities and demonstrate impact • High bar for craft: You produce clear documentation, reusable patterns, and automation that scale across teams • AI-first mindset: You actively look for opportunities to use automation and AI to improve security outcomes

Responsibilities

• Design, implement, and continuously improve a Secure Software Development Life Cycle integrated from design through production. • Embed security into planning and delivery via threat modelling, security requirements, and automated controls. • Lead application security reviews for new systems, major features, and high-risk changes across web, API, mobile, and backend services. • Define and maintain secure architecture patterns for authentication, authorisation, APIs, data protection, and multi-tenant isolation. • Own the application security tooling stack (SAST, DAST, SCA), integrating it into CI/CD with high-signal, low-noise outputs. • Partner with engineers to triage and remediate vulnerabilities based on exploitability, impact, and regulatory risk. • Work with Security Operations to improve application-level logging, telemetry, and incident response readiness. • Act as a trusted advisor to engineering teams, raising the bar through practical guidance, documentation, and targeted training.

Benefits

• We trust you, so we offer flexible working hours, as long it suits both you and your team; • Health Insurance; • Physical and mental health support through our partnership with MyFitness; • 25 days of Annual leave (+ Bank Holidays); • Possibility to visit other Teya offices to meet colleagues in instances when travel is safe and appropriate; • Friday lunch in the office; • Friendly, comfortable and high-end work equipment and informal office environment; • Hybrid work mode policy.

Get Started Free

No credit card. Takes 10 seconds.

Privacy·Terms··Contact·FAQ·Wagey on X