Application Security Engineer
London, GBR Security
Description

Job Title: Application Security Engineer
Working Time: Full time
Location: UK, London - Hybrid


About CloudBees


CloudBees helps organizations build, run, and govern software factories, giving enterprises the confidence to ship software better, faster, and safer.


Writing code is no longer the bottleneck. Governing what reaches production and validating its impact is. As enterprises adopt agentic coding, software is created faster than most teams can review, secure, and validate. Without consistent governance, organizations risk shipping code they cannot explain, audit, or trust.


CloudBees addresses this challenge without asking teams to replace the tools they already use. Across every toolchain a customer runs, CloudBees makes each change, human or AI, visible, auditable, and accountable before it reaches production. CloudBees Unify is the product behind this: a governance layer, with context and control-plane capabilities, that enforces consistent policy and evidence across every tool, team, and workflow.


Founded in 2010, CloudBees is backed by Goldman Sachs, Morgan Stanley, Bridgepoint Capital, HSBC, Golub Capital, Delta-v Capital, Matrix Partners, and Lightspeed Venture Partners.


Visit us at www.cloudbees.com.


About the Role


CloudBees builds and runs the internal applications, tools, and AI workflows that power the business. This role brings the same security discipline we build into our own products to that internal estate: threat modelling, secure design, and technical review for the applications, services, and AI-enabled tools our teams build and use.

You'll work closely with the CISO and the wider Security team, partnering with engineering and the business to make sure what gets built in-house is secure by design, not secured after the fact. Your place within the team will depend on your individual strengths and interests.

What You'll Do

Security architecture and design review

  • Conduct architecture and design reviews for our applications and services
  • Lead threat modelling for new tools and features, identifying design flaws and defining security requirements
  • Advise engineering and business teams on security best practice as they build

Vulnerability management and testing

  • Manage penetration testing engagements, from scoping through remediation
  • Use SAST/DAST and vulnerability scanning tools to prioritise and drive down risk
  • Perform secure code reviews where needed

Secure SDLC

  • Build and maintain secure SDLC standards for application development
  • Create patterns and reference architectures that let teams across the business self-serve on security
  • Evangelise secure development practices, especially for AI and low-code work, and coach rather than gatekeep
  • Integrate security checks into CI/CD

AI and agentic tooling

  • Extend the same rigour to AI tools and agents we build or deploy, including non-human identities
  • Advise on safe adoption of AI coding and agentic tools across engineering

Compliance and incident response

  • Work with GRC to translate regulatory and compliance requirements (e.g. SOC 2, ISO 27001) into concrete technical controls
  • Lead or support incident response for application security events, grounded in Zero Trust principles
  • Translate technical risk into terms non-technical stakeholders can act on

What You Bring


Required:

  • Solid experience in a security-focused engineering role, as a technical strategist as much as a hands-on implementer
  • Real depth in threat modelling and architectural security review
  • Deep understanding of common attack vectors and application/infrastructure vulnerabilities (e.g. OWASP Top 10)
  • A thorough understanding of the incident response process and Zero Trust architecture principles
  • Experience managing penetration testing engagements and working with engineering on remediation
  • Comfortable reading and writing code (Python, Go, TypeScript, or similar)
  • Experience with SAST/DAST, vulnerability management tooling
  • Strong written and verbal communication — able to explain technical risk to non-technical stakeholders
  • Comfortable evangelising and coaching security practices with teams that don't have security as their day job
  • Practical understanding of integrating security into the SDLC

Desirable:

  • Cloud security experience (AWS/GCP)
  • Experience with SOC 2, ISO 27001, or similar compliance frameworks
  • Exposure to AI/ML security or agentic AI frameworks
  • Experience building automation or tooling to scale a security function
  • Relevant security certifications (e.g. CISSP, CCSP, CISM, AWS/GCP security specialty) are a plus, not a requirement

Working Conditions

  • Hybrid - Full time 
  • Travel required

Adjustments will be considered to accommodate individual needs in line with applicable equality and disability legislation.


Equal Opportunity Statement


CloudBees is committed to providing equal opportunities in employment. We value diversity and inclusion and make decisions based on skills, qualifications, and experience. We do not discriminate on the basis of age, disability, gender identity, marital or civil status, pregnancy, maternity, race, religion or belief, sex, or sexual orientation, in accordance with applicable laws.


Data Protection Statement


All personal data collected during the recruitment process will be processed in line with CloudBees’s Privacy Policy and applicable data protection legislation, including the EU General Data Protection Regulation (GDPR).


Disclaimer


This job description provides an overview of the role and key responsibilities. It is not an exhaustive list, and responsibilities may evolve in line with business needs.