Social network you want to login/join with:
Senior Application Security Engineer, Stockport
Client: Cloudsmith
Location: Stockport, United Kingdom
Job Category: Other
EU work permit required: Yes
Job Views: 4
Posted: 31.05.2025
Expiry Date: 15.07.2025
Job Description:
Some people like building things. Others like breaking them. You? You love both and more importantly, you love stopping bad actors from breaking the things you helped build. If that sounds like your vibe, we’ve got a job you’ll want to see.
This job is with the software supply chain company - securing and powering how software gets delivered everywhere.
What you'll do:
* Embed security across the platform, from source to production.
* Architect security controls across distributed, cloud-native systems.
* Lead threat modeling and security reviews (and get people to enjoy them).
* Perform penetration testing services and infrastructure security assessments (ethically, please).
* Extend security automation and monitoring with tools like CircleCI, GitHub Actions, DataDog, AWS Security Hub, etc.
* Harden everything from container runtimes to APIs to artifact pipelines.
* Write secure code, review others’ code, and help everyone level up their secure coding game.
* Build tools, automate boring tasks, and occasionally create a ‘sploity’ proof of concept for fun.
You need:
* A background in software development. At your core, you’re a software engineer. Python for sure and a bit of TypeScript never hurt anyone.
* Deep application security knowledge.
* Hands-on experience with SAST, DAST, RASP, and securing cloud environments (preferably AWS).
* Strong grasp of container security, API security, Infrastructure as Code (IaC), and CI/CD pipelines.
* Experience with pen testing, threat modeling, and building security tools.
* Big bonus if you’ve secured artifact systems or supply chains before.
* Bigger bonus if you’ve worked with Firecracker, gVisor, or security solutions like SCA and data enclaves.
* You believe security should enable, not block, engineering.
* You’re a diplomat — you can work with engineering teams to secure the SDLC without spooking them.
This job is remote within the Island of Ireland or in the UK. You need to be physically located here — remote work from another country is not available.
Work permit sponsorship is not available.
#J-18808-Ljbffr