F
FlagstoneNew

Senior Application Security Engineer

onsiteFull timeLondon, GBYesterday

Job Overview & Requirements

What is Flagstone?Flagstone is many things. An online savings platform, reinventing how individuals, businesses, and charities manage, protect, and grow their cash. A diverse group of people, bound by a collaborative spirit, and shared purpose. And lastly, a thriving, profitable business – where smart people do their best work.Each definition shares a common thread: our unique culture. It’s our pride and joy. And our competitive advantage.A feel for our culture:To revolutionise the savings market, we need to be at our best. But high performance takes more than talent – it takes a culture of kindness, respect, and growth.That’s why we’re building a diverse, inclusive community, where your voice is heard and valued. Where, with close support and room to develop, you can surpass even your own expectations. And be rewarded for it.We may not change the world, but we can change the world of financial technology. And all it takes is a winning mix of drive, talent, and empathy. Our culture celebrates all three.But enough about us. Let’s talk about you.About the TeamThis is a new AppSec-focused addition to Security Engineering, working closely with product engineering teams across the SDLC. The role sits alongside, not inside, GRC/Compliance — customer security questionnaires and RFP responses are owned by GRC, with this role providing technical input as needed rather than end-to-end ownership.Does this sound like you:We're currently hiring a Senior Application Security Engineer to own AppSec end-to-end across our development lifecycle: from design-stage threat modelling through to code review, tooling, and remediation of findings. This is a hands-on engineering role, not a compliance or customer-facing one — you'll work directly with product engineering teams to build security in rather than bolt it on afterwards.What you’ll do:Own the AppSec programme for Flagstone and report back on its success to relevant stakeholders including leadershipFormalise a secure development lifecycle which includes owning threat modelling and secure design review for new features and systems, working directly with engineering teams during design rather than after the fact, introducing security gates and guardrails and ensuring applications are secure even post deploymentRun and continuously improve secure code review practices, including SAST/DAST/SCA tooling integrated into CI/CD pipelines and code review (manual and/or AI assisted)Coordinate external and execute internal penetration test engagements — scope, logistics, findings triage — and drive remediation to closure with engineering teamsMaintain and evolve secure coding standards, and run a security champions programme to scale AppSec practice across engineeringTrack and report on vulnerability management across the application estate, prioritising by exploitability and business impactContribute AppSec expertise to incident response where application-layer issues are involvedRun and own a security champions programmeManage application cyber risk according to the internal Flagstone Risk FrameworkWhat we’re looking for5+ years in application security or a security engineering role with a strong AppSec componentPractical experience embedding security in the SDLC: threat modelling frameworks (e.g. STRIDE), secure design review, and working directly with engineering teamsHands-on experience with SAST/DAST/SCA tooling and CI/CD pipeline integrationStrong grasp of OWASP Top 10 and secure coding practices across at least one major language/framework used in a production environmentExperience coordinating and running penetration testing programmes, including remediation trackingComfortable communicating security risk clearly to engineering and product audiences and influencing senior leadershipDemonstrable experience with adversarial security testingDemonstrated experience in reviewing, threat modelling and securing agentic and AI systemsGreat communication skills and stakeholder management, which includes influencing stakeholders and creating relationshipsStrong critical thinking skills and a curiosity for learning new technologies and frameworksGreat at troubleshooting and thinking out of the boxNice to HaveA strong link to the AppSec community and industry which includes conferences, OWASP or other Open-Source contributions, public speaking and engagement in thought leadershipOSCP, CSSLP, or equivalent hands-on offensive/AppSec certificationExperience in a regulated financial services environmentPrior experience running or scaling a security champions programmeExposure to cloud-native application security (containers, serverless, API security)How we reward you:At Flagstone, the benefits extend beyond false gifts like “fruit and snacks”. Instead, we invest in your health, wealth, and professional development. Here’s a selection of our benefits:Competitive bonus scheme - designed to reward and recognise high performanceFlexible benefits budget - a pot to fund meaningful benefits for you, whether it's hormone or fertility testing, cancer screening, neuro-diversity coaching or something that matters for you.A range of salary sacrifice options to help you make tax efficient savings on electric cars, nursery schemes, home and tech goods.Around the World scheme - 3 months work from anywhere scheme (some exclusions do apply)Mental wellbeing support – Access therapy and mental health sessions through SpillLearning and development – 1,000 personal development budget to help you grow in your role.Private health care - Enjoy all the benefits AXA has to offer, including reduced gym memberships and medical history disregardedMedical cash plan - To help you with the costs of dental and optical expensesLife insurance and Income Protection- four times your annual salary for peace of mindMatched pension contributions up to 5%25 days holiday - plus

Job Snapshot

Employer:Flagstone
Location:London, GB
Work Mode:onsite
Employment Type:Full time
Compensation:Competitive
Date Posted:Yesterday
Verified Creator Feed

This job posting is officially syndicated with tracking preserved to ensure prioritized creator-referred application review.

Similar Open Positions

remotefull time💼5-9 yrsSan Francisco, California, US4h ago

About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to a...

$165k - $225k / yr
ReactTypeScriptNext.js+3
remotefull time💼5-9 yrsSan Francisco, California, US4h ago

About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to a...

$165k - $225k / yr
ReactTypeScriptNext.js+3
remotefull time💼6-12 yrsUS12h ago

About Anthropic Anthropic is an AI safety and research company that builds reliable, beneficial AI systems. We are dedicated to creating state-of-the-art AI while conducting founda...

$240k - $360k / yr
PythonPyTorchRust+3
F

Senior Application Security Engineer

Competitive

Apply Now