JobRaahGet matched free

Jobs

Lead Application Security Engineer

Brunswick Group · London, England, United Kingdom · On-site

Posted Oct 5, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

Opportunity The Lead Application Security Engineer will join Brunswick's Information Security team and play a key role in shaping how the firm embeds security into application design, development, deployment, and technology change. This is a senior individual contributor role initially, with scope to help establish and mature Brunswick's application security capability over time. The role will focus on providing risk-based security advice and assurance across internally developed applications, enterprise platforms, integrations, cloud services, SaaS solutions, and selected AI-enabled workstreams. Working closely with ICT, AI Engineering, application owners, and business stakeholders, the Lead Application Security Engineer will help define practical security standards, guardrails, review processes, and secure design patterns that enable delivery teams to move at pace while managing risk appropriately. About the Role In this role, you will provide senior application security and DevSecOps expertise across technology projects, design reviews, cloud-based applications, APIs, integrations, delivery pipelines, and selected AI-enabled solutions. You will act as a senior security advisor to technical and business teams, helping establish a repeatable application security model that can scale as demand grows, including the potential introduction of additional team members in the future. Key responsibilities include: Lead the development of Brunswick's application security capability, including standards, secure design patterns, review processes, and practical guardrails. Act as a senior security advisor to ICT, AI Engineering, application owners, and business stakeholders. Review and assess application designs, architecture decisions, APIs, integrations, cloud services, and deployment patterns to identify security risks early in the delivery lifecycle. Mature repeatable approaches for application security reviews, threat modelling, and risk-based assurance across new and changed solutions. Provide guidance and oversight on secure development lifecycle practices, including security requirements, design review, code and security review considerations, dependency management, secrets management, testing, and release assurance. Conduct threat modelling for internally developed applications, AI-enabled workflows, integrations, automation use cases, and higher-risk technology changes, using STRIDE or similar methodologies. Advise on secure design principles, including identity and access management, API security, data protection, encryption, logging, monitoring, resilience, secure configuration, and least privilege. Support security review of CI/CD pipelines, infrastructure as code, containerised workloads, and cloud infrastructure, identifying practical controls for engineering and platform teams. Review and assess third-party platforms, SaaS solutions, and new technology features, including AI-enabled tools where there are…