All roles with salary

Application Security Engineer

Legal Counsel - 12 month FTC at Rightmove Greenhouse LondonEst. Est. GBP 65,000–95,000 / yearSenior

Estimated range based on role, country and industry — not published by the company.

Key requirements

  • Python
  • Gcp
  • Ci/Cd
  • Cloud Security
Our vision is to give everyone the belief they can make their move. We aim to make moving simpler, by giving everyone the best place to turn to and return to for access to the tools, expertise, trust, and belief to make it happen. We’re home to the UK’s largest choice of properties and are the go-to destination for millions of people planning their next move, reading the latest industry news, or just browsing what’s on the market. Application Security Engineer Purpose This is the first engineering hire into Rightmove's growing Application Security function,reporting to the Lead Application Security Engineer. You'll work closely with engineering teamsto deliver day-to-day AppSec capabilities across security tooling, vulnerability management,secure design and threat modelling, while helping shape how Application Security operates asthe function matures. Key Responsibilities Vulnerability Management & Security Tooling Support the rollout and operation of application security tooling across engineeringrepositories, including SAST, SCA and secrets detection. Triage and classify security findings across repos, driving remediation of the secrets backlog Manage the day-to-day operation of vulnerability management, including findings triage,monitoring and engineering engagement. Maintain engineer-facing guidance for resolving vulnerabilities and requesting exceptions Cloud Security Support cloud security posture management through Prisma Cloud, including findings triage,monitoring and engagement with relevant engineering/platform teams. Engineering Team Engagement Run a risk-tiered engagement cadence with engineering teams based on SLA compliance Security Reviews & Triage Triage inbound security requests per the AppSec triage SLA Conduct secure design and API security reviews for new services, integrations, and RFCs Review and respond to penetration test requests and third-party integration reviews Threat Modelling Facilitate threat modelling sessions using the team's runbook/guide Work with engineering teams to establish and improve threat modelling practices acrosssquads Process & Documentation Maintain runbooks and process documentation as the function matures Support recurring review cadences (e.g. access reviews, vulnerability audits) Requirements Must have: Practical experience in application security, security engineering or a related hands-onsecurity role Able to assess security findings in context, distinguish meaningful risk from tooling noise, andmake pragmatic recommendations to engineering teams. Working proficiency in Python (able to read, modify, and write scripts used for internal tooling) Practical experience with DAST/SAST/SCA/secrets scanning tools (Aikido, Snyk, Semgrep,Checkmarx, or similar) Experience with Prisma Cloud or a comparable cloud-native security platform Comfortable reading code and understanding CI/CD pipelines (GitLab CI or equivalent) Experience running or contributing to threat modelling exercises Comfortable running recurring stakeholder syncs with engineering teams Strong written communication Able to triage and prioritise a high volume of inbound requests independently Nice to have: Exposure to GCP security controls Familiarity with supply-chain security (npm/PyPI dependency risks) Prior experience in a scaling/greenfield security function Success in first 6 months Fully ramped on Aikido, independently supporting rollout, triage and day-to-day operations Cloud Security handover complete: backlog triaged, monitoring cadence running Risk-tiered engagement cadence live and running its first full cycle Independently triaging and closing security review requests within SLA Independently facilitating threat modelling sessions with engineering teams Identified and delivered improvements to at least one AppSec process or workflow Life at Rightmove Despite o

See your match score for this role.

Xecodai maps the interview stages and shows what is preventing a 95% match.

Analyse this role