Application Secruity Engineer - London
Technology. Award-winning customer service. Bleeding-edge data ability.
Simply Business is a new type of insurance company, using all of the above to create the best possible insurance experience for small businesses and self-employed people.
We love working here, and have even taken the number one spot in the Sunday Times Best Company To Work For 2015 and 16 lists; we’ve stopped entering now to focus on a few bigger projects, but you get the idea. It’s a great place to work.
There are currently over 425,000 active Simply Business insurance policies in the UK alone. And we have offices in London, Northampton and Boston, USA.
Talking of offices, ours are bright, airy and geared up for really smart working. We’re flexible, with plenty of remote workers coming in and out, and we believe work and life should be hand in hand, rather than a juggling act. So no need to worry about school pick-ups, or a horrible commute.
Our people are our most important asset, so we focus on building a working life that helps us thrive, not stick. Join us and you’ll be part of our journey to creating something even better, for our customers and ourselves.
Reporting to the Lead Application Security Engineer, you will play an important role in driving the security mind-set into the teams who are responsible for the applications they create, maintain and run. The successful candidate will help build a network of champions, define standards/guidelines, evaluate security products and technologies, and strengthen our defences through the SDLC.
As a Application Security Engineer you will:
- collaborate on source code with developers
- create threat models for new and existing features
- mentor team members and security champions
- advise on the security architecture of projects
- setup and tune the security technology (SAST, DAST, WAF, HIDS, Container Security)
- triage vulnerabilities
- testing automation (fuzzing, vulnerability reproduction)
- creating documentation (policies, procedures, guidelines, training)
- mentoring team members
- running application security focused sessions (presentations, workshops and CTF)
What we are looking for:
- sociable & Communicative
- passionate about security
- experience with threat modelling
- experience as a software developer
- experience reviewing vulnerabilities
What are the benefits?
There’s all the serious (but important) stuff we call ‘core benefits’. On top of that, you can pick and choose from the more exciting options we offer – whether it’s a full gym membership or gym subsidy, comprehensive private health cover, extra holiday, or a National Trust pass.
The ‘core’ stuff
Some of these will kick in once you’re confirmed in post, but here’s the summary:
- a salary that reflects your experience, our pay policy and the market we’re in from your first day, generous annual leave
- life cover (financial cover for your family, should the worst happen)
- a cash plan to reimburse your everyday medical expenses
- an extra day off if you get married or move house
- a stakeholder pension (employer-matched at 5%)
The fun stuff
Passed probation? Time to pick and mix from things like:
- a full gym membership
- private medical insurance
- cinema passes
- up to 5 extra days annual leave
- shopping vouchers
- dental and/or travel insurance
But there’s so much more to Simply Business than insurance and memberships. We also commit to flexible working options, smart working (our offices are kitted out for you to work when and how you choose), cycle to work, childcare vouchers, and season ticket loan schemes, and we have a handy online form to put in any training or conference requests.
Best of all, though, are the groups, clubs, and adventures that come with the Simply Business territory. Forget a simple Give As You Earn scheme (although we’ve got that too) – we trek the Sahara for charity, take you on weekends away, throw epic summer parties, and meet up for book groups, public speaking coaching, yoga, cheeky manicures, beer brewing, and lots, lots more.
The Simply Business culture is truly unique. And you sort of have to come and spend time with us to appreciate it. So get that application in and we’ll take it from there.
How to Apply
If you are interested in working for us, then please email your application to firstname.lastname@example.org, or email@example.com for roles based in the US, quoting the specific job role in the subject line.
Note for recruitment agencies We have an internal team in place for our recruitment needs, so we tend not to use recruitment agencies. If we do not have signed terms of agreement with your company, then we advise against you sending us any speculative candidate profiles. They will not be subject to any terms and conditions, regardless of whether we progress with the candidate.