More jobs:
Senior Application Security Engineer
Job in
London, Greater London, W1B, England, UK
Listed on 2026-09-04
Listing for:
Flagstone
Full Time
position Listed on 2026-09-04
Job specializations:
-
IT/Tech
Cybersecurity
Job Description & How to Apply Below
Flagstone is many things. An online savings platform, reinventing how individuals, businesses, and charities manage, protect, and grow their cash. A diverse group of people, bound by a collaborative spirit, and shared purpose. And lastly, a thriving, profitable business – where smart people do their best work.
Each definition shares a common thread: our unique culture. It’s our pride and joy. And our competitive advantage.
A feel for our culture:
To revolutionise the savings market, we need to be at our best. But high performance takes more than talent – it takes a culture of kindness, respect, and growth.
That’s why we’re building a diverse, inclusive community, where your voice is heard and valued. Where, with close support and room to develop, you can surpass even your own expectations. And be rewarded for it.
We may not change the world, but we can change the world of financial technology. And all it takes is a winning mix of drive, talent, and empathy. Our culture celebrates all three.
But enough about us. Let’s talk about you.
About the Team This is a new App Sec-focused addition to Security Engineering, working closely with product engineering teams across the SDLC. The role sits alongside, not inside, GRC/Compliance — customer security questionnaires and RFP responses are owned by GRC, with this role providing technical input as needed rather than end-to-end ownership.
Does this sound like you:
We're currently hiring a Senior Application Security Engineer to own App Sec end-to-end across our development lifecycle: from design-stage threat modelling through to code review, tooling, and remediation of findings. This is a hands-on engineering role, not a compliance or customer-facing one — you'll work directly with product engineering teams to build security in rather than bolt it on afterwards.
What you’ll do:
Own the App Sec programme for Flagstone and report back on its success to relevant stakeholders including leadership
Formalise a secure development lifecycle which includes owning threat modelling and secure design review for new features and systems, working directly with engineering teams during design rather than after the fact, introducing security gates and guardrails and ensuring applications are secure even post deployment
Run and continuously improve secure code review practices, including SAST/DAST/SCA tooling integrated into CI/CD pipelines and code review (manual and/or AI assisted)
Coordinate external and execute internal penetration test engagements — scope, logistics, findings triage — and drive remediation to closure with engineering teams
Maintain and evolve secure coding standards, and run a security champions programme to scale App Sec practice across engineering
Track and report on vulnerability management across the application estate, prioritising by exploitability and business impact
Contribute App Sec expertise to incident response where application-layer issues are involved
Run and own a security champions programme
Manage application cyber risk according to the internal Flagstone Risk Framework What we’re looking for5+ years in application security or a security engineering role with a strong App Sec component
Practical experience embedding security in the SDLC: threat modelling frameworks (e.g. STRIDE), secure design review, and working directly with engineering teams
Hands-on experience with SAST/DAST/SCA tooling and CI/CD pipeline integration
Strong grasp of OWASP Top 10 and secure coding practices across at least one major language/framework used in a production environment
Experience coordinating and running penetration testing programmes, including remediation tracking
Comfortable communicating security risk clearly to engineering and product audiences and influencing senior leadership
Demonstrable experience with adversarial security testing
Demonstrated experience in reviewing, threat modelling and securing agentic and AI systems
Great communication skills and stakeholder management, which includes influencing stakeholders and creating relationships
Strong critical thinking skills and a curiosity for learning new technologies and frameworks
Great at…
Position Requirements
10+ Years
work experience
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×