×
Register Here to Apply for Jobs or Post Jobs. X

Application Security - Vulnerability Discovery

Job in Cardiff, Cardiff City Area, CF10, Wales, UK
Listing for: Jobgether
Full Time position
Listed on 2026-07-23
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Security Management & Operations
Job Description & How to Apply Below

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Application Security - Vulnerability Discovery based in United Kingdom.

This role focuses on strengthening application security by identifying, analyzing, and reducing vulnerabilities across modern software environments. You will collaborate with engineering and product teams to improve security practices throughout the software development life cycle. The position combines vulnerability management, secure coding expertise, automation, and security research to protect critical applications. You will play a key role in validating security findings, guiding remediation efforts, and improving security processes  ideal candidate will bring strong technical skills, a proactive mindset, and the ability to partner effectively with development teams.

This is an opportunity to contribute to impactful security initiatives while helping build safer, more resilient products.

Accountabilities

The Application Security Engineer will be responsible for identifying security risks, improving vulnerability management processes, and partnering with engineering teams to implement secure development practices.

  • Triage, validate, prioritize, and manage security vulnerabilities discovered through manual reviews, automated security tools, bug bounty programs, and AI‑assisted security platforms.
  • Partner with software engineering and product teams to drive remediation efforts, provide actionable security guidance, and ensure timely resolution of findings based on risk and severity.
  • Review security‑related pull requests, source code changes, and development workflows to identify vulnerabilities and recommend secure implementation approaches.
  • Analyze findings generated by AI‑powered security tools and automation platforms, reduce false positives, and improve vulnerability detection workflows.
  • Participate in security incident response activities, investigations, and root cause analysis related to application security issues.
  • Support and enhance secure software development lifecycle (SDLC) practices across engineering organizations.
  • Develop security tooling, automation, and workflows to improve vulnerability detection, security coverage, and operational efficiency.
  • Configure, optimize, and maintain vulnerability scanning platforms, including policies, schedules, and reporting processes.
  • Track remediation progress, security metrics, and risk reduction initiatives while providing visibility to stakeholders.
  • Collaborate with security architecture and development teams to improve vulnerability discovery, prioritization, and remediation strategies.
  • Create security documentation, best practices, and educational resources to promote secure coding practices across teams.
  • Participate in an on‑call rotation to support security triage, code reviews, and application security requests.
Requirements

The ideal candidate is an experienced application security professional with strong technical expertise, excellent collaboration skills, and a proven ability to improve security outcomes across software development environments.

  • 3+ years of experience in application security engineering or a related security role.
  • Availability to work until 11:00 AM Pacific Standard Time (PST).
  • Strong understanding of application security principles, vulnerability management, and secure software development practices.
  • Experience building and scaling Secure Development Lifecycle (SDLC) programs.
  • Hands‑on experience handling vulnerability reports, bug bounty findings, and security assessments.
  • Experience partnering with engineering and product teams to drive security improvements and remediation initiatives.
  • Experience triaging and prioritizing vulnerabilities from SAST, DAST, SCA, dependency scanning, penetration testing, and similar security assessments.
  • Strong knowledge of common application security risks, including OWASP Top 10, API security, authentication, authorization, secrets management, and cryptography.
  • Experience reviewing source code and identifying vulnerabilities across modern programming languages and frameworks.
  • Familiarity with security…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary