Application Security Consultant
Location:
UK Remote
Salary:
up to £55k
Contract Type:
UK Remote
Application Security Engineer / Researcher
Location: Remote-first, with occasional UK office attendance for onboarding, collaboration and team days
Salary: Up to £55,000, reviewed regularly
Type: Permanent, full-time
Package: Share options, pension, private healthcare and unlimited holidays
About the company
Our client is a well-funded cybersecurity technology business building a modern platform for continuous application security testing and application-change risk management.
The platform helps analyse development tickets and software changes, threat model risk, and create targeted security testing plans using a mix of manual security expertise, automation and agentic testing capability.
This is not a traditional point-in-time penetration testing business focused on long PDF reports. The company is working to embed application security directly into the software development lifecycle and help engineering teams understand where application changes introduce real security risk.
The role
We are looking for an Application Security Engineer / Researcher to help improve the technology, research and security capability behind the platform.
This role would suit someone with strong application security fundamentals who wants to apply that knowledge to broader engineering, research, product and platform problems.
Application-led penetration testing may be required in the short term, particularly across web applications, APIs, desktop applications and related environments. Longer term, the main focus is expected to be application security engineering, security research, application-change risk management, agentic testing and platform capability.
This is a strong opportunity for someone who enjoys AppSec or application-focused pentesting, but does not want to stay confined to repetitive consultancy testing and reporting.
Key responsibilities
•Research and help engineer solutions to complex application security problems.
•Support and improve the company’s application-change risk management platform and related security testing workflows.
•Contribute to the development, evaluation and benchmarking of agentic / automated testing capabilities.
•Apply AppSec and pentesting knowledge to help identify security risk introduced by application changes.
•Work closely with internal development teams, providing application security expertise where useful and relevant.
•Perform application security reviews and risk assessments of software changes.
•Support application-focused penetration testing where required across web apps, APIs, desktop apps and related technologies.
•Work with clients, developers and stakeholders to explain vulnerabilities, impact and remediation clearly.
•Contribute ideas around methodology, research direction, product capability and continuous security testing.
Ideal candidate profile
The ideal candidate will understand application security vulnerabilities, including how they are identified, exploited and remediated.
They may come from a penetration testing, AppSec / Security Engineering, or security research background, but should be motivated to move beyond traditional testing delivery into a broader AppSec engineering and research-focused role.
You should have:
•2+ years’ experience in application security, penetration testing, security engineering or security research.
•Strong understanding of web application and API security.
•Ability to identify, validate, exploit and explain application security vulnerabilities.
•Good communication skills and confidence working with clients, developers and technical stakeholders.
•Interest in application-change risk management, continuous testing and SDLC-integrated security.
•Curiosity around automation, AI / agentic testing and product-led security.
•A practical problem-solving mindset.
•Desire to contribute to research, product capability and technical direction.
Useful background / experience
•Application-focused penetration testing.
•Application Security Engineering / Security Engineering.
•Security research or tool-building.
•Secure code review.
•Threat modelling.
•AppSec automation.
•CI/CD or SDLC tooling exposure.
•Conference talks, research write-ups or open-source projects.
•CREST CRT, CPSA, OSCP, OSWA or OSWE.
•UK right to work.
Less suitable backgrounds
This is unlikely to suit someone who is heavily infrastructure-focused, uncomfortable speaking with clients or stakeholders, or only wants to continue delivering traditional penetration tests without moving into broader AppSec engineering, research or product capability work.
Package / working setup
•Salary up to £55,000, reviewed regularly.
•Share options.
•Pension contribution.
•Private healthcare, including dental, optical and hearing.
•Unlimited holidays.
•Permanent, full-time role.
•Remote-first working, with occasional UK office attendance for onboarding, collaboration and team days where possible.
Why this role?
This is a strong move for someone with AppSec or application pentesting knowledge who wants to work on modern application security problems, agentic testing, automation and change-led security, rather than staying confined to repetitive consultancy testing and reporting.

