Application Security Lead

Company: Prolific
Apply for the Application Security Lead
Location: London
Job Description:

Application Security Lead

Prolific is seeking an experienced security professional to own its application security strategy. The role involves defining and driving a Secure Software Development Lifecycle (SSDLC), embedding security across engineering, and providing hands‑on expertise through code review, threat modeling, and security testing. You will manage the Senior Application Security Engineer, oversee compliance programs, and lead cross‑functional initiatives with product, platform, data, TechOps, and legal teams.

Responsibilities

  • Define and implement SSDLC for all product lines.
  • Set standards for security integration in engineering workflows.
  • Lead hands‑on code reviews, threat modeling, and security testing.
  • Manage the Senior Application Security Engineer and mentor the team.
  • Own and maintain the compliance program (ISO 27001, SOC 2).
  • Collaborate with engineering leadership to balance risk and delivery velocity.

Qualifications

  • Several years of software engineering experience with production systems at scale.
  • Several years in application security (testing, code review, threat modelling, vulnerability management).
  • Expert knowledge of OWASP Top 10 (Web & API) and modern attack paths (auth flaws, SSRF, injection, business logic, supply chain).
  • Strong understanding of modern architectures (microservices, APIs, event‑driven systems).
  • Programming in Python for security tooling and automation (Django a strong plus).
  • Hands‑on experience with security testing tools (e.g., Burp Suite) and manual assessment of apps/APIs.
  • Experience building and scaling SSDLCs, including CI/CD tooling (SAST, SCA, DAST, secrets).
  • Experience leading threat modelling and security design reviews.
  • Strong engineering partnership and communication skills.
  • Experience with ISO 27001 / SOC 2 and translating controls into engineering practices.

Nice to have

  • Mentoring or managing security engineers.
  • Experience with Django, Vue.js, MongoDB, GCP.
  • Security champions or bug bounty programmes.
  • Supply chain or infrastructure security (Terraform, Kubernetes).
  • Hands‑on certifications (OSCP, GWAPT, BSCP, CISSP).
  • Experience building AppSec in a scaling company.

Benefits

Competitive salary, benefits, and remote working within a mission‑driven culture.

Legal Notice

By submitting your application, you agree that Prolific may collect your personal data for recruiting and global organization planning. Prolific’s Candidate Privacy Notice explains what personal information Prolific may process, where Prolific may process your personal information, its purposes for processing your personal information, and the rights you can exercise over Prolific’s use of your personal information.

#J-18808-Ljbffr…

Posted: May 27th, 2026