Senior Lead Application Security Engineer
at
ZipRecruiter
Devon - England, Devon - England, United Kingdom
-
Full Time
Start Date
Immediate
Expiry Date
17 Nov, 26
Salary
0.0
Posted On
19 Aug, 26
Experience
0 year(s) or above
Remote Job
Yes
Telecommute
Yes
Sponsor Visa
Yes
Skills
Industry
Information Technology & Services
Description
Key Responsibilities
Embed application security into the Cloud Platform and across all CI/CD pipelines, making secure-by-default the path of least resistance for every R&D team.
Design, build, and operate AI-driven security agents that proactively scan, triage, and remediate vulnerabilities across source code, dependencies, containers, and infrastructure-as-code, turning point-in-time reviews into continuous, autonomous coverage.
Establish secure software development lifecycle (SSDLC) practices, threat modeling, and secure-coding standards, and integrate automated enforcement (SAST, SCA, DAST, secrets scanning, IaC scanning) as native pipeline gates rather than bolt-on checks.
Lead the security of our own agentic systems: defend against prompt injection, tool/MCP abuse, data exfiltration, excessive agency, and supply-chain risk in line with frameworks such as the OWASP Top 10 for LLM Applications and MITRE ATLAS.
Drive proactive vulnerability management: remediate HIGH and CRITICAL CVEs across platform infrastructure and container images in line with contractual and compliance commitments, and automate the toil out of it.
Partner with engineering teams to harden Azure Kubernetes Service (AKS) workloads, identity and access (Keycloak, Azure AD, Managed Identities, workload identity), network segmentation, and secrets management.
Contribute security evidence and controls to compliance programs (SOC 2, ISO 27001, Cyber Insurance), and automate evidence collection and continuous control monitoring with agentic tooling.
Define and maintain security runbooks, detection logic, and incident response procedures, and build the agents that execute and accelerate them.
Act as the security skill set within the platform team raising the bar through code review, pairing, and sharing pragmatic, developer-friendly guidance.
Contribute to improving the Agentic Operating Model through development of security-focused agent skills, prompts, and tooling that other teams can reuse.