Security Engineer, Application Security (uk)

Writer · AI Frontier · London, United Kingdom · Engineering, product & design

Security engineer focused on securing enterprise AI platforms, including LLM architectures, AI agents, training data pipelines, and customer-facing AI agents. Responsibilities include threat modeling, SAST/DAST scanning, security code reviews, secure coding standards, penetration testing, and designing security controls for AI infrastructure. The role emphasizes integrating AI agents to improve security team velocity and staying ahead of emerging AI/ML security threats.

What you'd actually do

  1. Build security into the DNA of our AI platform by conducting threat modeling sessions with product teams, designing secure architectures for new features, and ensuring security considerations shape product decisions from day one—not after the fact
  2. Own and evolve our application security program including establish and maintain SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production
  3. Partner with engineering teams to establish and champion secure coding standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default
  4. Design and recommend security features and products that help secure customer environments. You are the advocate and the vision for how we protect and secure customers..
  5. Integrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products

Skills

Required

  • 4+ years of hands-on experience in application security engineering
  • Understanding of developer experience and developer workflows for shipping features and products
  • Technical expertise in at least two programming languages (Python, Java, Go, JavaScript/TypeScript)
  • Knowledge of security tools and methodologies including SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practices
  • Excellent communication skills

Nice to have

  • proven track record of securing large-scale production systems—bonus points if you've worked in fast-growing startups or high-growth environments
  • you know which tools to use and when automation beats manual review
  • you can explain why something matters and motivate teams to action
  • you understand that security enables the business, not blocks it

What the JD emphasized

  • securing AI agents
  • protecting training data pipelines
  • designing controls for systems that didn't exist a few years ago
  • threat modeling our LLM architectures
  • building automated security controls that scale across our growing platform
  • securing AI agents
  • protecting training data pipelines
  • design and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents
  • researching attack vectors specific to LLMs and generative AI

Other signals

  • Securing AI systems
  • Protecting training data pipelines
  • Designing controls for AI agents