About the role
Are you a software engineer who is passionate about building secure applications with an interest in moving into application security?
Do you enjoy collaborating with engineering teams to drive practical, secure-by-design solutions that reduce risk and improve delivery outcomes?
About the Role
As a Senior Application Security Engineer, you will contribute to strengthening secure software delivery across engineering teams by embedding security practices, tools, and automation into development workflows. This role focuses on enabling teams to build secure applications and CI/CD pipelines through practical guidance, reusable solutions, and improved processes. You will work across teams to reduce risk, improve reliability, and support secure-by-default delivery at scale.
Responsibilities
- Partner with development teams to improve secure software delivery practices across applications and CI/CD pipelines
- Support triage and remediation of application security findings through practical guidance and secure refactoring recommendations
- Facilitate threat modelling activities and translate outcomes into actionable improvements and risk reduction measures
- Design and maintain secure-by-default delivery patterns, reusable templates, and reference implementations
- Support adoption of centrally managed tooling and automated security controls
- Develop integrations and automation to enable security validation, audit evidence generation, and operational metrics
- Collaborate with platform, architecture, and security teams to improve processes, tooling, and delivery capabilities
- Communicate security guidance, standards, and best practices to stakeholders
Requirements
- Experience in application security, software engineering, or product security
- Knowledge of application security principles, common vulnerabilities, and secure coding practices across multiple technology stacks
- 5+ years of application security, software engineering, or product security experience.
- BS Engineering/Computer Science or equivalent experience required.
- Understanding of CI/CD security, including pipeline controls, identity and access management, and secrets handling
- Experience integrating automated security tooling into software delivery workflows
- Experience developing reusable templates, standards, and reference implementations
- Familiarity with security automation, compliance support, and audit evidence generation
- Awareness of industry security standards and best practices
- Strong collaboration, communication, analytical, troubleshooting, and problem-solving skills
Work in a way that works for you
We promote a healthy work/life balance across the organization. We offer an appealing working prospect for our people. With numerous wellbeing initiatives, shared parental leave, study assistance and sabbaticals, we will help you meet your immediate responsibilities and your long-term goals.
- Working flexible hours - flexing the times when you work in the day to help you fit everything in and work when you are the most productive
About the Business
A global leader in information and analytics, we help researchers and healthcare professionals advance science and improve health outcomes for the benefit of society. Building on our publishing heritage, we combine quality information and vast data sets with analytics to support visionary science and research, health education and interactive learning, as well as exceptional healthcare and clinical practice. At Elsevier, your work contributes to the world’s grand challenges and a more sustainable future. We harness innovative technologies to support science and healthcare to partner for a better world.
Millions of jobs, with real people getting hired every day
Questions, answered
Click "Apply with JobAssist" – we tailor your resume and application to this role and submit it for your approval.
Yes. This role at Elsevier was screened before publishing – we confirmed the employer before listing it.
The employer didn't disclose a salary range for this listing. JobAssist shows pay whenever it's available.
This position can be done from anywhere, with no in-office requirement.
Yes – every application is tailored from your profile and this job's requirements, and you can review and edit before it's sent.
