Social network you want to login/join with:
Senior Application Security Engineer, Chelmsford
Client: Cloudsmith
Location: Chelmsford, UK (Remote work within the UK or Ireland)
Job Category: Other
EU work permit required: Yes
Job Views:
4
Posted:
31.05.2025
Expiry Date:
15.07.2025
Job Description:
Some people like building things. Others like breaking them. You? You love both and more importantly, you love stopping bad actors from breaking the things you helped build. If that sounds like your vibe, we’ve got a job you’ll want to see.
This job is with the software supply chain company - securing and powering how software gets delivered everywhere.
What you'll do:
* Embed security across the platform, from source to production.
* Architect security controls across distributed, cloud-native systems.
* Lead threat modeling and security reviews (and make them engaging).
* Perform ethical pen-testing on services and infrastructure.
* Extend security automation and monitoring with tools like CircleCI, GitHub Actions, DataDog, AWS Security Hub, etc.
* Harden systems from container runtimes to APIs to artifact pipelines.
* Write secure code, review others’ code, and help elevate the team’s secure coding skills.
* Build tools, automate routine tasks, and occasionally create proof of concepts for fun.
You need:
* A background in software development, especially in Python and TypeScript.
* Deep application security knowledge.
* Hands-on experience with SAST, DAST, RASP, and securing cloud environments (preferably AWS).
* Strong understanding of container security, API security, Infrastructure as Code (IaC), and CI/CD pipelines.
* Experience with pen testing, threat modeling, and developing security tools.
* Bonus: experience securing artifact systems or supply chains.
* Bonus: familiarity with Firecracker, gVisor, SCA, and data enclaves.
* You believe security should enable engineering, not hinder it.
* You are diplomatic and can collaborate effectively with engineering teams to secure the SDLC.
This role is remote within Ireland or the UK. Applicants must be physically located in these regions; remote work from outside these areas is not permitted. Work permit sponsorship is not available.
#J-18808-Ljbffr