<p><strong>Purpose of Position</strong></p> <p>Your role is to establish and lead an AppSec program within the Product and Technology department, acting as an evangelist for AppSec, trusted by engineers and managers alike.
</p> <p>As a member of the core security team, you will engage in assessing application design proposals, to identify improvements to enable our engineers to create secure products.
</p> <p>You will own the existing training program, redesign it to better equip engineers with the knowledge needed to develop secure applications, and create a Security Champions program to scale and embed a DevSecOps mindset across P&T.
</p> <p> </p> <p><strong>What you'll be responsible for</strong></p> <ul> <li><strong>Secure the SDLC</strong>: Integrate security tooling (e.
SAST, DAST, dependency scanning) into CI/CD pipelines and IDEs.
Automate and optimise checks so teams can identify and fix issues early and efficiently.
</li> <li><strong>Threat modelling & secure design</strong>: Collaborate with product and engineering teams during the design phase to conduct threat modelling sessions and pre-implementation security reviews.
</li> <li><strong>Code & architecture reviews</strong>: Guide developers on secure coding practices, perform targeted code reviews, and help resolve vulnerabilities with actionable remediation support.
</li> <li><strong>Vulnerability lifecycle management</strong>: <ul> <li>Identify, triage, track and report on vulnerabilities across internal and external apps and systems.
</li> <li>Collaborate with engineers to close gaps efficiently.
</li> <li>Support the bug bounty process with finding validation.
</li> <li>Present vulnerability management reports to our heads of department.
</li> </ul> </li> <li><strong>AI/ML & LLM security</strong>: <ul> <li>Provide guidance on secure development of AI/LLM-powered features.
</li> <li>Help teams manage risks such as prompt injection, model misuse, and data leakage.
</li> <li>Lead t.