# Application Security Engineer

[Genomics](https://gurify.com/jobs?q=Genomics) · London · Posted yesterday

Hybrid

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://jobs.ashbyhq.com/genomics/12b90f95-ee11-4071-8415-528dc016fffa)

## Job description

### The Mission: Why We Exist

Genomics is a science-led transatlantic TechBio combining large-scale genetic and health data with proprietary analytics to accelerate drug discovery and advance predictive, preventative healthcare. We are united by a single vision to help people live longer, healthier lives, using the power of genomics.

Genomics aims to help people live longer, healthier lives in two ways: super-charging drug discovery and development for novel treatments with our AI-enabled advanced genetic analytics platform, and by helping people understand their personal risk of common chronic diseases through polygenic risk scores - giving doctors and health systems the chance to get the right people into the right prevention, screening and treatment programmes at the right time.

### Role Purpose

Genomic data is some of the most sensitive data there is, and our customers trust us with it. As Senior Application Security Engineer on Mystra, you'll own application security end-to-end across multi-tenant, trillion-row-scale, AI-enabled data platforms.

You'll lead threat modelling and design review with product teams, build the tooling and patterns that make secure codet, and find and fix the vulnerabilities that slip through. You'll do it with security-focused AI tooling, steered by your own expert judgement and intuition, to keep Genomics secure against state-of-the-art threats.

### A Day in the Life

- Leading threat modelling and design reviews for new products and infrastructure, and defining the security invariants every team builds against: tenant isolation, authentication and authorisation, secrets, least privilege, and trust boundaries

- Building the libraries, patterns, and CI/CD guardrails that make the secure way the easy way, and deciding what is enforced versus advised

- Building and tuning AI tooling for code analysis, triage, and remediation, and deciding where its output can be trusted and where it must be verified

- Hunting for vulnerabilities through code review, testing, and proof-of-concept exploits, then running the disclosure programme and driving every finding through to a verified fix

- Securing our agentic and AI surfaces, from prompt injection and tool boundaries to delegated credentials and tenant-scoped access, and proving the controls hold under adversarial testing

- Working as an embedded, trusted partner to product teams, SRE, detection and response, the data platform team, and the MystraAI / ML team, unblocking rather than gating

### Who You Are

- Experience within application security in production. You've found and fixed exploitable bugs in software you were responsible for, through threat modelling, secure design, code review, and proof-of-concept exploitation across web services, APIs, and data-serving interfaces. Triaging scanner output doesn't count

- Production-quality software engineering in at least one mainstream language (such as Python, Go, or TypeScript), and you can read several. You've built and operated security or developer tooling in CI/CD pipelines, such as static and dependency analysis, secrets detection, or policy-as-code, and engineers actually adopted it

- Hands-on depth securing multi-tenant systems on a major cloud. We run on AWS (RDS, EC2, S3, EKS, Batch), and comparable GCP or Azure depth transfers. You know tenant isolation, IAM and least privilege, secrets management, Kubernetes and container security, and the trust boundaries between services

- Daily use of frontier AI models for code analysis, vulnerability triage, remediation drafting, and research, with sharp judgement about where they're reliable and where they mislead. You've built or tuned LLM-driven tooling rather than only used a chat interface, and you understand the attack surface it introduces

- Experience running, or being core to, a vulnerability disclosure or bug bounty programme and the remediation lifecycle behind it, covering severity, prioritisation, SLAs, root cause, and systemic fixes. You've also worked application-layer incidents alongside detection and response, using security telemetry and SIEM data as evidence

- Risk-led judgement. You know which designs need deep review, which findings matter and which are noise, and you make accepted risk explicit so leadership can decide with open eyes

- Clear communication. You explain risk and trade-offs precisely to engineers, product, and leadership, write guidance people actually use, and mentor others to grow security capability across teams

### Your Package

We are committed to providing a transparent, supportive, and rewarding work environment.

### Compensation & Growth

- Competitive Reward: Salaries are externally benchmarked annually to ensure market-aligned compensation.

- Clear Career Path: A straightforward, open progression framework means you'll always know the path to promotion and how to achieve your next career goal.

- Continuous Learning: Including external courses and a wide library of L&D materials, because your growth is our success.

### Wellbeing & Time Off

- Holiday: 25 days annual leave, plus bank holidays, plus an extra 3-day company-wide shutdown at year-end.

- Financial & Health Security: Robust benefits including a market-leading pension scheme, comprehensive private health insurance for you and your family with NO excess, critical illness, and life assurance.

- Enhanced Leave: Enhanced paid family leave to support all new parents.

### Work Environment & Culture

- Hybrid Working

- Truly Inclusive Time Off: Our 'Bank Your Bank Holiday' program allows you to exchange public holidays for dates that hold personal or cultural significance to you.

- Vibrant Social Culture: From regular Town Halls and team picnics to organised sports events, our social committee ensures frequent opportunities to connect and celebrate.

- Green Commute: Cycle-to-Work scheme and convenient office locations near major transport hubs.

Ready to Build the Future?

If this opportunity excites you, apply now!

We are dedicated to creating a diverse environment and are proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.

Genomics politely requests no contact from recruitment agencies. We do not accept speculative CVs from recruitment agencies nor accept the fees associated with them.

**Live in Genomics’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- BR [Lead Application Security Engineer](https://gurify.com/job/lead-application-security-engineer-at-brunswickgroup-5849dbce754f) Brunswickgroup · London, United Kingdom · 2 days ago
- RI [Application Security Engineer](https://gurify.com/job/application-security-engineer-at-rightmove-53294a38228f) Rightmove · London, United Kingdom · 5 days ago
- WR [Security engineer, application security (UK)](https://gurify.com/job/security-engineer-application-security-uk-at-writer-5099130c9e15) Writer · London, United Kingdom · 2 weeks ago
- EN [Lead Security Engineer](https://gurify.com/job/lead-security-engineer-at-encord-691754c23bc3) Encord · London · 5 days ago
- OM [Platform Security Engineer](https://gurify.com/job/platform-security-engineer-at-omnea-79e993c63a72) Omnea · London · yesterday
- XA [Infrastructure Security Engineer](https://gurify.com/job/infrastructure-security-engineer-at-xai-5df6888fa213) Xai · Dublin, United Kingdom · last week

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Application Security Engineer","description":"\u003Ch3\u003EThe Mission: Why We Exist\u003C/h3\u003E\u003Cp\u003EGenomics is a science-led transatlantic TechBio combining large-scale genetic and health data with proprietary analytics to accelerate drug discovery and advance predictive, preventative healthcare. We are united by a single vision to help people live longer, healthier lives, using the power of genomics.\u003C/p\u003E\u003Cp\u003EGenomics aims to help people live longer, healthier lives in two ways: super-charging drug discovery and development for novel treatments with our AI-enabled advanced genetic analytics platform, and by helping people understand their personal risk of common chronic diseases through polygenic risk scores - giving doctors and health systems the chance to get the right people into the right prevention, screening and treatment programmes at the right time.\u003C/p\u003E\u003Ch3\u003ERole Purpose\u003C/h3\u003E\u003Cp\u003EGenomic data is some of the most sensitive data there is, and our customers trust us with it. As Senior Application Security Engineer on Mystra, you\u0026#39;ll own application security end-to-end across multi-tenant, trillion-row-scale, AI-enabled data platforms.\u003C/p\u003E\u003Cp\u003EYou\u0026#39;ll lead threat modelling and design review with product teams, build the tooling and patterns that make secure codet, and find and fix the vulnerabilities that slip through. You\u0026#39;ll do it with security-focused AI tooling, steered by your own expert judgement and intuition, to keep Genomics secure against state-of-the-art threats.\u003C/p\u003E\u003Ch3\u003EA Day in the Life\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003ELeading threat modelling and design reviews for new products and infrastructure, and defining the security invariants every team builds against: tenant isolation, authentication and authorisation, secrets, least privilege, and trust boundaries\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuilding the libraries, patterns, and CI/CD guardrails that make the secure way the easy way, and deciding what is enforced versus advised\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuilding and tuning AI tooling for code analysis, triage, and remediation, and deciding where its output can be trusted and where it must be verified\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHunting for vulnerabilities through code review, testing, and proof-of-concept exploits, then running the disclosure programme and driving every finding through to a verified fix\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESecuring our agentic and AI surfaces, from prompt injection and tool boundaries to delegated credentials and tenant-scoped access, and proving the controls hold under adversarial testing\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWorking as an embedded, trusted partner to product teams, SRE, detection and response, the data platform team, and the MystraAI / ML team, unblocking rather than gating\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EWho You Are\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EExperience within application security in production. You\u0026#39;ve found and fixed exploitable bugs in software you were responsible for, through threat modelling, secure design, code review, and proof-of-concept exploitation across web services, APIs, and data-serving interfaces. Triaging scanner output doesn\u0026#39;t count\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EProduction-quality software engineering in at least one mainstream language (such as Python, Go, or TypeScript), and you can read several. You\u0026#39;ve built and operated security or developer tooling in CI/CD pipelines, such as static and dependency analysis, secrets detection, or policy-as-code, and engineers actually adopted it\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHands-on depth securing multi-tenant systems on a major cloud. We run on AWS (RDS, EC2, S3, EKS, Batch), and comparable GCP or Azure depth transfers. You know tenant isolation, IAM and least privilege, secrets management, Kubernetes and container security, and the trust boundaries between services\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDaily use of frontier AI models for code analysis, vulnerability triage, remediation drafting, and research, with sharp judgement about where they\u0026#39;re reliable and where they mislead. You\u0026#39;ve built or tuned LLM-driven tooling rather than only used a chat interface, and you understand the attack surface it introduces\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience running, or being core to, a vulnerability disclosure or bug bounty programme and the remediation lifecycle behind it, covering severity, prioritisation, SLAs, root cause, and systemic fixes. You\u0026#39;ve also worked application-layer incidents alongside detection and response, using security telemetry and SIEM data as evidence\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ERisk-led judgement. You know which designs need deep review, which findings matter and which are noise, and you make accepted risk explicit so leadership can decide with open eyes\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EClear communication. You explain risk and trade-offs precisely to engineers, product, and leadership, write guidance people actually use, and mentor others to grow security capability across teams\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EYour Package\u003C/h3\u003E\u003Cp\u003EWe are committed to providing a transparent, supportive, and rewarding work environment.\u003C/p\u003E\u003Ch3\u003ECompensation \u0026amp; Growth\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003ECompetitive Reward: Salaries are externally benchmarked annually to ensure market-aligned compensation.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EClear Career Path: A straightforward, open progression framework means you\u0026#39;ll always know the path to promotion and how to achieve your next career goal.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EContinuous Learning: Including external courses and a wide library of L\u0026amp;D materials, because your growth is our success.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EWellbeing \u0026amp; Time Off\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EHoliday: 25 days annual leave, plus bank holidays, plus an extra 3-day company-wide shutdown at year-end.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFinancial \u0026amp; Health Security: Robust benefits including a market-leading pension scheme, comprehensive private health insurance for you and your family with NO excess, critical illness, and life assurance.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EEnhanced Leave: Enhanced paid family leave to support all new parents.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EWork Environment \u0026amp; Culture\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EHybrid Working\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ETruly Inclusive Time Off: Our \u0026#39;Bank Your Bank Holiday\u0026#39; program allows you to exchange public holidays for dates that hold personal or cultural significance to you.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EVibrant Social Culture: From regular Town Halls and team picnics to organised sports events, our social committee ensures frequent opportunities to connect and celebrate.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EGreen Commute: Cycle-to-Work scheme and convenient office locations near major transport hubs.\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003EReady to Build the Future?\u003C/p\u003E\u003Cp\u003EIf this opportunity excites you, apply now!\u003C/p\u003E\u003Cp\u003EWe are dedicated to creating a diverse environment and are proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.\u003C/p\u003E\u003Cp\u003EGenomics politely requests no contact from recruitment agencies. We do not accept speculative CVs from recruitment agencies nor accept the fees associated with them.\u003C/p\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"application-security-engineer-at-genomics-7b8e06290558"},"url":"https://gurify.com/job/application-security-engineer-at-genomics-7b8e06290558","datePosted":"2026-10-06","validThrough":"2026-11-21T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Genomics","sameAs":"https://jobs.ashbyhq.com/genomics"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"GB","addressLocality":"London"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"United Kingdom","item":"https://gurify.com/jobs/united-kingdom"},{"@type":"ListItem","position":3,"name":"Application Security Engineer","item":"https://gurify.com/job/application-security-engineer-at-genomics-7b8e06290558"}]}
```
