Application Security Engineer
Rightmove Careers · London, UK · United Kingdom · Hybrid
Posted Oct 2, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Our vision is to give everyone the belief they can make their move. We aim to make moving simpler, by giving everyone the best place to turn to and return to for access to the tools, expertise, trust, and belief to make it happen.
We’re home to the UK’s largest choice of properties and are the go-to destination for millions of people planning their next move, reading the latest industry news, or just browsing what’s on the market.
Application Security Engineer
Purpose This is the first engineering hire into Rightmove's growing Application Security function, reporting to the Lead Application Security Engineer. You'll work closely with engineering teams to deliver day-to-day AppSec capabilities across security tooling, vulnerability management, secure design, and threat modeling, while helping shape how Application Security operates as the function matures.
Key Responsibilities
Vulnerability Management & Security Tooling
Support the rollout and operation of application security tooling across engineering repositories, including SAST, SCA, and secrets detection.
Triage and classify security findings across repos, driving remediation of the secrets backlog.
Manage the day-to-day operation of vulnerability management, including findings triage, monitoring, and engineering engagement.
Maintain engineer-facing guidance for resolving vulnerabilities and requesting exceptions.
Cloud Security
Support cloud security posture management through Prisma Cloud, including findings triage, monitoring, and engagement with relevant engineering/platform teams.
Engineering Team Engagement
Run a risk-tiered engagement cadence with engineering teams based on SLA compliance.
Security Reviews & Triage
Triage inbound security requests per the AppSec triage SLA.
Conduct secure design and API security reviews for new services, integrations, and RFCs.
Review and respond to penetration test requests and third-party integration reviews.
Threat Modeling
Facilitate threat modeling sessions using the team's runbook/guide.
Work with engineering teams to establish and improve threat modeling practices across squads.
Process & Documentation
Maintain runbooks and process documentation as the function matures.
Support recurring review cadences (e.g. access reviews, vulnerability audits).
Requirements Must have:
Practical experience in application security, security engineering, or a related hands-on security role.
Able to assess security findings in context, distinguish meaningful risk from tooling noise, and make pragmatic recommendations to engineering teams.
Working proficiency in Python (able to read, modify, and write scripts used for internal tooling).
Practical experience with DAST/SAST/SCA/secrets scanning tools (Aikido, Snyk, Semgrep, Checkmarx, or similar).
Experience with Prisma Cloud or a comparable cloud-native security platform.
Comfortable reading code and understanding CI/CD pipelines (GitLab CI or…