Application Security Engineer

Rightmove — United Kingdom · Posted ~7 hours ago

Mid

Skills

Application security Security tooling Vulnerability management Secure design Threat modeling Security engineering

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

An application security engineering role supporting the development of security capabilities across a large digital platform. You will operate security tooling, manage vulnerabilities, contribute to secure design and threat modeling, and help establish mature application security practices.

Highlights

Opportunity to become an early engineering contributor in a growing application security function, with broad ownership across security tooling, vulnerability management, secure design, and threat modeling.

Description

Our vision is to give everyone the belief they can make their move. We aim to make moving simpler, by giving everyone the best place to turn to and return to for access to the tools, expertise, trust, and belief to make it happen. We’re home to the UK’s largest choice of properties and are the go-to destination for millions of people planning their next move, reading the latest industry news, or just browsing what’s on the market. Application Security Engineer Purpose This is the first engineering hire into Rightmove's growing Application Security function,reporting to the Lead Application Security Engineer. You'll work closely with engineering teamsto deliver day-to-day AppSec capabilities across security tooling, vulnerability management,secure design and threat modelling, while helping shape how Application Security operates asthe function matures. Key Responsibilities Vulnerability Management & Security ToolingSupport the rollout and operation of application security tooling across engineeringrepositories, including SAST, SCA and secrets detection.Triage and classify security findings across repos, driving remediation of the secrets backlogManage the day-to-day operation of vulnerability management, including findings triage,monitoring and engineering engagement.Maintain engineer-facing guidance for resolving vulnerabilities and requesting exceptions Cloud Security Support cloud security posture management through Prisma Cloud, including findings triage,monitoring and engagement with relevant engineering/platform teams. Engineering Team Engagement Run a risk-tiered engagement cadence with engineering teams based on SLA compliance Security Reviews & Triage Triage inbound security requests per the AppSec triage SLAConduct secure design and API security reviews for new services, integrations, and RFCsReview and respond to penetration test requests and third-party integration reviews Threat Modelling Facilitate threat modelling sessions using the team's runbook/guideWork with engineering teams to establish and improve threat modelling practices acrosssquads Process & Documentation Maintain runbooks and process documentation as the function maturesSupport recurring review cadences (e.g. access reviews, vulnerability audits) Requirements Must have: Practical experience in application security, security engineering or a related hands-onsecurity roleAble to assess security findings in context, distinguish meaningful risk from tooling noise, andmake pragmatic recommendations to engineering teams.Working proficiency in Python (able to read, modify, and write scripts used for internal tooling)Practical experience with DAST/SAST/SCA/secrets scanning tools (Aikido, Snyk, Semgrep,Checkmarx, or similar)Experience with Prisma Cloud or a comparable cloud-native security platformComfortable reading code and understanding CI/CD pipelines (GitLab CI or equivalent)Experience running or contributing to threat modelling exercisesComfortable running recurring stakeholder syncs with engineering teamsStrong written communicationAble to triage and prioritise a high volume of inbound requests independently Nice To Have Exposure to GCP security controlsFamiliarity with supply-chain security (npm/PyPI dependency risks)Prior experience in a scaling/greenfield security function Success in first 6 months Fully ramped on Aikido, independently supporting rollout, triage and day-to-day operationsCloud Security handover complete: backlog triaged, monitoring cadence runningRisk-tiered engagement cadence live and running its first full cycleIndependently triaging and closing security review requests within SLAIndependently facilitating threat modelling sessions with engineering teamsIdentified and delivered improvements to at least one AppSec process or workflow Life at Rightmove Despite Our Growth, We’ve Remained a Friendly, Supportive Place To Work, With Employee #1 Still Working Here! We’ve Done This By Placing The Rightmove Hows At The Heart Of Everything We Do. These Are The Essential Values That Reflect Our Culture, And Include We create value…by delivering results and building trust with partners and consumers.We think bigger…by acting with curiosity and setting bold aspirations.We care deeply…by being real, having fun, and valuing diversity.We move together…by being one team - internally collaborative, externally competitive.We make a difference…by focusing on delivering measurable impact. We believe in careers that open doors and help our team develop by providing an open and inclusive work environment, offering ongoing training opportunities, and supporting charity fundraising events. And with 89% of Rightmovers saying we’re a great place to work, we’re clearly doing something right! Cash plan for dental, optical and physio treatments.Private Medical Insurance, Pension and Life Insurance, Employee Assistance Plan.27 days holiday plus two (paid) volunteering days a year to give back, and holiday buy schemes.Contributory stakeholder pension.Life assurance at 4x your basic salary to a spouse, family member or other nominated person in your life.Competitive compensation package.Paid leave for maternity, paternity, adoption & fertility.Travel Loans, Bike to Work scheme, Rental Deposit Loan.Charitable contributions through Payroll Giving and donation matching.Access deals and discounts on things like travel, electronics, fashion, gym memberships, cinema discounts and more.We offer hybrid working with a minimum of 2 days in the office. For our roles, such as Field or Home-based positions, different working arrangements apply - full details will be shared during the recruitment process. As an Equal Opportunity Employer, Rightmove will never discriminate based on age, disability, sex, race, religion or belief, gender reassignment, marriage / civil partnership, pregnancy/maternity or sexual orientation. At Rightmove, we believe that a diverse and inclusive workforce leads to better innovation, productivity, and overall success. We are committed to creating a welcoming and inclusive environment for all employees, regardless of their background or identity, to develop and promote a diverse culture that reflects the communities we serve. By applying, you confirm that you are aged at least 18 or over and that you’ve read and understood our Privacy Policy, which explains how we handle and protect your personal information during the recruitment process.