Company Overview
RealVNC is the remote access platform for engineers seeking the most reliable and secure solution, built by the creators of VNC technology. With 25 years of experience as inventors of VNC, we enable a global workforce to work from anywhere and have created the remote access market. Our software is used by hundreds of millions of users worldwide, including IT professionals from global companies such as Intel, IBM, NASA, Shell, DreamWorks, and Philips.
Our lead product, VNC Connect, allows users to connect securely to a remote device anywhere in the world, see its screen in real‑time, and take control as though sitting in front of it. The product has been deployed across a myriad of use cases, from remote support to deploying the software onto connected devices such as medical ventilators, set‑top boxes, heavy industrial machinery and more.
Backed by leading mid‑market private equity firm Livingbridge since 2021, we are investing in our people to support ambitious growth plans. We are looking to add new team members that are integral to the success of the business, committed to delivering high quality results, collaboration and innovation to help accelerate company growth.
Position
We are seeking a highly skilled Applications Security Engineer to join our Cyber Security team, helping to ensure security is embedded throughout the Software Development Lifecycle (SDLC). This hands‑on technical role involves identifying, analysing and mitigating vulnerabilities in our applications throughout the development lifecycle. The role protects our customers and reputation by ensuring security is tested into our products before they ship. You will work closely with Security, Development and QA teams to embed robust, evidence‑based security practices throughout our software delivery process.
Key Responsibilities
- Conduct manual penetration testing and vulnerability assessments across various environments including web, API, desktop and mobile applications.
- Execute Dynamic Application Security Testing (DAST) on running applications, focusing on XSS, SQL Injection, Broken Access Control, etc., manually confirming exploitability beyond what scanners or AI analysis reports.
- Use Interactive Application Security Testing (IAST) tools for runtime analysis, such as Burp Suite, OWASP ZAP, Frida, applying hands‑on techniques to validate and extend automated results.
- Conduct Static Application Security Testing (SAST) and Software Composition Analysis (SCA) on source code and binaries, manually triaging findings to separate real risk from noise, using AI tools to accelerate initial triage where helpful.
- Ensure a secure foundation from the start by conducting threat modelling and risk assessments during design phases.
- Provide security requirements for new features and architecture reviews.
- Perform secure code reviews and advise developers on ensuring security best practices are followed.
- Make use of AI‑assisted code review tools to speed up initial passes, while personally validating any flagged issue against actual code behaviour.
- Collaborate with engineering teams to integrate security into development workflows.
- Partner with DevOps to advise on secure configurations and hardening in production environments.
- Support incident response and remediation of application‑level vulnerabilities.
- Keep up to date with industry news, vulnerability announcements and guidelines.
- Deliver secure coding training and promote a positive security posture.
Requirements
- Hands‑on experience with DAST, IAST and penetration testing tools (e.g., Burp Suite, OWASP ZAP, Frida), and the ability to manually identify and exploit vulnerabilities beyond what these tools surface automatically.
- Independent, hands‑on technical ability demonstrated through CTF experience, bug bounty history, HackTheBox/TryHackMe rankings, or a technical portfolio.
- 3–5 years’ experience in an application security, penetration testing, or software engineering role with a strong security focus.
- Strong understanding of secure SDLC and DevSecOps principles.
- Strong knowledge of application security principles and common vulnerabilities (e.g., XSS, SQL Injection, Broken Access Control).
- Experience with Static Application Security Testing (SAST).
- Practical experience using software composition analysis (SCA) tools such as Blackduck, Mend/Whitesource, Snyk or similar.
- Ability to explain complex security concepts to non‑technical stakeholders and write clear security reports.
- Excellent collaboration skills with cross‑functional teams—including system administrators, developers, network engineers and information security compliance.
- Proficiency in secure coding practices (Java, Python, C++ or similar).
- Familiarity with common operating systems—Windows, Linux, macOS, Android and iOS.
Desired Experience (Optional)
- Leveraging AI to drive efficiency in day‑to‑day workflows.
- Exploit development activities, such as exploiting buffer overflows, crafting shellcode, or analysing patches.
- Knowledge of Cyber Security frameworks such as NIST Cybersecurity Framework.
- Regulatory compliance knowledge—GDPR, ISO‑27001 and SOC2.
- Details of any security‑based qualifications.
Benefits
This role offers an opportunity to join our Cyber Security team within a successful, growing company with a recognised global brand and substantial potential. We are committed to creating a culture that recognises contributions, supports career growth, and promotes well‑being.
Benefits include a contributory pension, EV car leasing scheme, private dental and medical cover, and a hybrid work environment that allows a combination of remote and office work. The role requires the ability to commute to Cambridge and/or London.
RealVNC is an equal opportunities employer, committed to staff welfare and professional development. All staff are eligible to work in the United Kingdom and must provide proof of eligibility during the interview process.
#J-18808-Ljbffr…
