Application Security Engineer
Legal Counsel - 12 month FTC at Rightmove Greenhouse LondonEst. Est. GBP 65,000–95,000 / yearSenior
Estimated range based on role, country and industry — not published by the company.
Key requirements
- Python
- Gcp
- Ci/Cd
- Cloud Security
Our vision is to give everyone the belief they can make their move. We aim to make moving simpler, by giving everyone the best place to turn to and return to for access to the tools, expertise, trust, and belief to make it happen.
We’re home to the UK’s largest choice of properties and are the go-to destination for millions of people planning their next move, reading the latest industry news, or just browsing what’s on the market.
Application Security Engineer
Purpose
This is the first engineering hire into Rightmove's growing Application Security function,reporting to the Lead Application Security Engineer. You'll work closely with engineering teamsto deliver day-to-day AppSec capabilities across security tooling, vulnerability management,secure design and threat modelling, while helping shape how Application Security operates asthe function matures.
Key Responsibilities
Vulnerability Management & Security Tooling
Support the rollout and operation of application security tooling across engineeringrepositories, including SAST, SCA and secrets detection.
Triage and classify security findings across repos, driving remediation of the secrets backlog
Manage the day-to-day operation of vulnerability management, including findings triage,monitoring and engineering engagement.
Maintain engineer-facing guidance for resolving vulnerabilities and requesting exceptions
Cloud Security
Support cloud security posture management through Prisma Cloud, including findings triage,monitoring and engagement with relevant engineering/platform teams.
Engineering Team Engagement
Run a risk-tiered engagement cadence with engineering teams based on SLA compliance
Security Reviews & Triage
Triage inbound security requests per the AppSec triage SLA
Conduct secure design and API security reviews for new services, integrations, and RFCs
Review and respond to penetration test requests and third-party integration reviews
Threat Modelling
Facilitate threat modelling sessions using the team's runbook/guide
Work with engineering teams to establish and improve threat modelling practices acrosssquads
Process & Documentation
Maintain runbooks and process documentation as the function matures
Support recurring review cadences (e.g. access reviews, vulnerability audits)
Requirements
Must have:
Practical experience in application security, security engineering or a related hands-onsecurity role
Able to assess security findings in context, distinguish meaningful risk from tooling noise, andmake pragmatic recommendations to engineering teams.
Working proficiency in Python (able to read, modify, and write scripts used for internal tooling)
Practical experience with DAST/SAST/SCA/secrets scanning tools (Aikido, Snyk, Semgrep,Checkmarx, or similar)
Experience with Prisma Cloud or a comparable cloud-native security platform
Comfortable reading code and understanding CI/CD pipelines (GitLab CI or equivalent)
Experience running or contributing to threat modelling exercises
Comfortable running recurring stakeholder syncs with engineering teams
Strong written communication
Able to triage and prioritise a high volume of inbound requests independently
Nice to have:
Exposure to GCP security controls
Familiarity with supply-chain security (npm/PyPI dependency risks)
Prior experience in a scaling/greenfield security function
Success in first 6 months
Fully ramped on Aikido, independently supporting rollout, triage and day-to-day operations
Cloud Security handover complete: backlog triaged, monitoring cadence running
Risk-tiered engagement cadence live and running its first full cycle
Independently triaging and closing security review requests within SLA
Independently facilitating threat modelling sessions with engineering teams
Identified and delivered improvements to at least one AppSec process or workflow
Life at Rightmove
Despite o
See your match score for this role.
Xecodai maps the interview stages and shows what is preventing a 95% match.
