
Lead Application Security Engineer
Brunswick Group4 hours ago
London, United KingdomStaff+
Responsibilities
- Lead the development of Brunswick’s application security capability, including standards, secure design patterns, review processes, and practical guardrails.
- Provide senior application security and DevSecOps advice to ICT, AI Engineering, application owners, engineering teams, and business stakeholders.
- Review application architectures, APIs, integrations, cloud services, SaaS platforms, deployment patterns, and technology changes for security risks.
- Conduct threat modelling, including STRIDE-based assessments, for applications, AI-enabled workflows, integrations, automation use cases, and higher-risk changes.
- Guide secure development lifecycle practices covering security requirements, design reviews, code and security reviews, dependency management, secrets management, testing, and release assurance.
- Advise on identity and access management, API security, data protection, encryption, logging, monitoring, resilience, secure configuration, and least privilege.
- Review CI/CD pipelines, infrastructure as code, containerised workloads, and cloud infrastructure and recommend practical controls.
- Support application security testing, penetration testing, remediation tracking, and security assurance activities.
- Define and document security requirements, architecture decisions, design recommendations, and risk-based remediation actions.
- Help shape the future growth, ways of working, capability needs, and technical guidance of the application security function.
Requirements
- At least 7 years of experience in cyber security, application security, DevSecOps, cloud security, security architecture, security engineering, or a related technical security role.
- Experience operating as a senior technical advisor or lead in application security, DevSecOps, cloud security, secure engineering, or a related discipline.
- Strong understanding of risk management, compensating controls, secure development lifecycles, threat modelling, secure design, API security, authentication and authorisation, secrets management, dependency management, security testing, and remediation planning.
- Practical experience reviewing application architectures, APIs, integrations, cloud services, CI/CD pipelines, containerised workloads, or infrastructure as code.
- Practical understanding of Microsoft 365, Azure, SaaS platforms, and Azure application security controls including Entra ID, managed identities, Key Vault, API Management, container security, logging, monitoring, and secure configuration.
- Experience conducting STRIDE-based threat modelling, technical risk assessments, application security reviews, or security design reviews.
- Experience developing security standards, secure design patterns, review processes, or guardrails for engineering and delivery teams.
- Ability to translate technical security risks into clear business-focused recommendations and influence delivery teams without directly owning implementation.
- Familiarity with large language models, AI-enabled applications, and risks including data exposure, prompt injection, insecure integrations, and excessive agent permissions is beneficial.
- Experience in an ISO27001-aligned or regulated environment is beneficial.
- Preferred certifications include CISSP, CCSP, SSCP, CSSLP, CISM, CISA, CRISC, Security+, CySA+, CASP+, GIAC, Microsoft Azure, or other relevant application security, cloud security, architecture, or DevSecOps certifications.
- Strong written and verbal communication, sound judgement, attention to detail, and ability to balance security requirements with business needs.
Benefits
- Employee benefits support financial future, health and wellness, family and community, and continuous professional development.
About Brunswick Group
Brunswick Group is a London‑headquartered, privately held global advisory firm that counsels companies and their leaders on high‑stakes corporate, financial and crisis communications, stakeholder engagement, and issues including cybersecurity and data privacy. It operates a consultancy model serving public and private organizations, investors, and boards. Founded in 1987, the firm has grown to 27 offices across 18 countries.