Application Security Engineer - Enterprise
Appcast · London, England ·
London, GBR • Cybersecurity DescriptionJob Title: Application Security Engineer - Enterprise (AI & Enterprise Security)Working Time: Full timeLocation: UK, London - HybridAbout CloudBeesCloudBees helps organizations build, run, and govern software factories, giving enterprises the confidence to ship software better, faster, and safer.
Writing code is no longer the bottleneck. Governing what reaches production and validating its impact is. As enterprises adopt agentic coding, software is created faster than most teams can review, secure, and validate. Without consistent governance, organizations risk shipping code they cannot explain, audit, or trust.
CloudBees addresses this challenge without asking teams to replace the tools they already use. Across every toolchain a customer runs, CloudBees makes each change, human or AI, visible, auditable, and accountable before it reaches production.
CloudBees Unify is the product behind this: a governance layer, with context and control-plane capabilities, that enforces consistent policy and evidence across every tool, team, and workflow. Founded in 2010, CloudBees is backed by Goldman Sachs, Morgan Stanley, Bridgepoint Capital, HSBC, Golub Capital, Delta-v Capital, Matrix Partners, and Lightspeed Venture Partners.
Visit us at .About the RoleWe're looking for a motivated engineer to help secure the most critical AI initiatives across the business. Most application security engineers spend their careers on the product side. This role puts you on the other side: AI-era security for the business itself, not the product customers use.
You'll work alongside the CISO on problems most companies don't have a playbook for yet. The work is product security with an enterprise scope. Internal apps, AI tools, and agents are products that need the same threat modeling, secure design, and engineering rigour as anything customer-facing.
Alongside enterprise security work, you'll build tooling, automation, and agents that help the broader security team scale with AI.You're curious, proactive, and hands-on. We'll back you with the resources and exposure to do your best work.
This is a hands-on role. Bring initiative. We'll give you the problems worth solving. What You'll DoSecure Development StandardsDevelop secure SDLC standards for internal apps and AI workflowsBuild patterns, reference architectures, and the documentation teams need to self-serveWork with business teams to raise the profile of security and adopt secure practices, especially for AI and low-codeThreat modeling and risk assessmentConduct threat modeling, risk assessments, and technical security reviews for enterprise systems, internal apps, and AI and agentic deploymentsIdentify and prioritize security risks; advise risk, compliance, audit, and business teams on mitigationsTranslate findings into actionable enterprise controls and detection requirementsAI and agentic securityDesign safeguards for enterprise AI tooling, including agents and non-human identitiesEvaluate and integrate emerging AI/ML security toolsStay current with the AI security landscapeBuilding and automationEngineer and automate AI-first security workflows that scale the wider Security teamBuild for the enterprise domain in a way that benefits Product Security, SOC, and GRCWhat You BringSecurity expertise: Hands-on experience in software and enterprise securityDesirable: working knowledge in any of SaaS, cloud, IAM, or endpoint securitySecure SDLC:Proficiency in secure SDLC fundamentals, including threat modelling, secure design, vulnerability management, and CI/CD securityEngineering and tooling: Comfortable writing and reviewing code (Python, Go, TypeScript, or similar)Experience building integrations and automating security workflowsExperience with security tools at scale — SAST, DAST, SIEM, endpoint, cloud, identity, AI/ML, vulnerability management platformsAI and agentic security knowledge: Understanding of AI/ML security risks, attack vectors, and vulnerabilitiesFamiliarity with agentic AI frameworks and generative AI toolsCommunication and interpersonal
skills
Exceptional written and verbal communication; able to translate complex security concepts for any audienceStrong interpersonal skills; build trust and credibility quickly across technical and non-technical teamsDrive outcomes through collaborationMindset: Self-starter with initiative and ownershipHacker mindset — figures out the problem, then solves itThrives in ambiguityWorking ConditionsHybrid - Full time Travel requiredAdjustments will be considered to accommodate individual needs in line with applicable equality and disability legislation.
Equal Opportunity StatementCloudBees is committed to providing equal opportunities in employment. We value diversity and inclusion and make decisions based on skills, qualifications, and experience. We do not discriminate on the basis of age, disability, gender identity, marital or civil status, pregnancy, maternity, race, religion or belief, sex, or sexual orientation, in accordance with applicable laws.
Data Protection StatementAll personal data collected during the recruitment process will be processed in line with CloudBees's Privacy Policy and applicable data protection legislation, including the EU General Data Protection Regulation (GDPR).DisclaimerThis job description provides an overview of the role and key responsibilities.
It is not an exhaustive list, and responsibilities may evolve in line with business needs.