# Application Security Engineer

[Rightmove](https://gurify.com/jobs?q=Rightmove) · London, United Kingdom · Posted yesterday

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://job-boards.eu.greenhouse.io/rightmovecareers/jobs/4757122101)

## Job description

Our vision is to give everyone the belief they can make their move. We aim to make moving simpler, by giving everyone the best place to turn to and return to for access to the tools, expertise, trust, and belief to make it happen.

We’re home to the UK’s largest choice of properties and are the go-to destination for millions of people planning their next move, reading the latest industry news, or just browsing what’s on the market.

### Application Security Engineer

Purpose
This is the first engineering hire into Rightmove's growing Application Security function,reporting to the Lead Application Security Engineer. You'll work closely with engineering teamsto deliver day-to-day AppSec capabilities across security tooling, vulnerability management,secure design and threat modelling, while helping shape how Application Security operates asthe function matures.

### Key Responsibilities

- Vulnerability Management & Security Tooling

- Support the rollout and operation of application security tooling across engineeringrepositories, including SAST, SCA and secrets detection.

- Triage and classify security findings across repos, driving remediation of the secrets backlog

- Manage the day-to-day operation of vulnerability management, including findings triage,monitoring and engineering engagement.

- Maintain engineer-facing guidance for resolving vulnerabilities and requesting exceptions

### Cloud Security

- Support cloud security posture management through Prisma Cloud, including findings triage,monitoring and engagement with relevant engineering/platform teams.

### Engineering Team Engagement

- Run a risk-tiered engagement cadence with engineering teams based on SLA compliance

### Security Reviews & Triage

- Triage inbound security requests per the AppSec triage SLA

- Conduct secure design and API security reviews for new services, integrations, and RFCs

- Review and respond to penetration test requests and third-party integration reviews

### Threat Modelling

- Facilitate threat modelling sessions using the team's runbook/guide

- Work with engineering teams to establish and improve threat modelling practices acrosssquads

### Process & Documentation

- Maintain runbooks and process documentation as the function matures

- Support recurring review cadences (e.g. access reviews, vulnerability audits)

Requirements
Must have:

- Practical experience in application security, security engineering or a related hands-onsecurity role

- Able to assess security findings in context, distinguish meaningful risk from tooling noise, andmake pragmatic recommendations to engineering teams.

- Working proficiency in Python (able to read, modify, and write scripts used for internal tooling)

- Practical experience with DAST/SAST/SCA/secrets scanning tools (Aikido, Snyk, Semgrep,Checkmarx, or similar)

- Experience with Prisma Cloud or a comparable cloud-native security platform

- Comfortable reading code and understanding CI/CD pipelines (GitLab CI or equivalent)

- Experience running or contributing to threat modelling exercises

- Comfortable running recurring stakeholder syncs with engineering teams

- Strong written communication

- Able to triage and prioritise a high volume of inbound requests independently

### Nice to have:

- Exposure to GCP security controls

- Familiarity with supply-chain security (npm/PyPI dependency risks)

- Prior experience in a scaling/greenfield security function

### Success in first 6 months

- Fully ramped on Aikido, independently supporting rollout, triage and day-to-day operations

- Cloud Security handover complete: backlog triaged, monitoring cadence running

- Risk-tiered engagement cadence live and running its first full cycle

- Independently triaging and closing security review requests within SLA

- Independently facilitating threat modelling sessions with engineering teams

- Identified and delivered improvements to at least one AppSec process or workflow

### Life at Rightmove

Despite our growth, we’ve remained a friendly, supportive place to work, with employee #1 still working here! We’ve done this by placing the Rightmove Hows at the heart of everything we do. These are the essential values that reflect our culture, and include:

- We create value…by delivering results and building trust with partners and consumers.

- We think bigger…by acting with curiosity and setting bold aspirations.

- We care deeply…by being real, having fun, and valuing diversity.

- We move together…by being one team - internally collaborative, externally competitive.

- We make a difference…by focusing on delivering measurable impact.

We believe in careers that open doors and help our team develop by providing an open and inclusive work environment, offering ongoing training opportunities, and supporting charity fundraising events. And with 89% of Rightmovers saying we’re a great place to work, we’re clearly doing something right!

### What we offer

- Cash plan for dental, optical and physio treatments.

- Private Medical Insurance, Pension and Life Insurance, Employee Assistance Plan.

- 27 days holiday plus two (paid) volunteering days a year to give back, and holiday buy schemes.

- Contributory stakeholder pension.

- Life assurance at 4x your basic salary to a spouse, family member or other nominated person in your life.

- Competitive compensation package.

- Paid leave for maternity, paternity, adoption & fertility.

- Travel Loans, Bike to Work scheme, Rental Deposit Loan.

- Charitable contributions through Payroll Giving and donation matching.

- Access deals and discounts on things like travel, electronics, fashion, gym memberships, cinema discounts and more.

- We offer hybrid working with a minimum of 2 days in the office. For our roles, such as Field or Home-based positions, different working arrangements apply - full details will be shared during the recruitment process.

### As an Equal Opportunity Employer, Rightmove will never discriminate based on age, disability, sex, race, religion or belief, gender reassignment, marriage / civil partnership, pregnancy/maternity or sexual orientation.

At Rightmove, we believe that a diverse and inclusive workforce leads to better innovation, productivity, and overall success. We are committed to creating a welcoming and inclusive environment for all employees, regardless of their background or identity, to develop and promote a diverse culture that reflects the communities we serve.

### By applying, you confirm that you are aged at least 18 or over and that you’ve read and understood our Privacy Policy, which explains how we handle and protect your personal information during the recruitment process.

**Live in Rightmove’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- WR [Security engineer, application security (UK)](https://gurify.com/job/security-engineer-application-security-uk-at-writer-5099130c9e15) Writer · London, United Kingdom · last week
- WR [Security engineer, detection and response (UK)](https://gurify.com/job/security-engineer-detection-and-response-uk-at-writer-9cb21b626cf6) Writer · London, United Kingdom · last week
- TR [Senior Product Security Engineer](https://gurify.com/job/senior-product-security-engineer-at-trainline-40f1783e34dd) Trainline · London · yesterday
- DO [Cyber Security Engineer - dojo.careers](https://gurify.com/job/cyber-security-engineer-dojo-careers-0961a5dd9c92) Dojo · London · last week
- EN [Lead Security Engineer](https://gurify.com/job/lead-security-engineer-at-encord-691754c23bc3) Encord · London · yesterday
- MA [Security Engineer](https://gurify.com/job/security-engineer-at-marex-a383676e7e6e) Marex · London, United Kingdom · last week

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Application Security Engineer","description":"\u003Cp\u003EOur vision is to give everyone the belief they can make their move. We aim to make moving simpler, by giving everyone the best place to turn to and return to for access to the tools, expertise, trust, and belief to make it happen.\u003C/p\u003E\u003Cp\u003EWe\u2019re home to the UK\u2019s largest choice of properties and are the go-to destination for millions of people planning their next move, reading the latest industry news, or just browsing what\u2019s on the market.\u003C/p\u003E\u003Ch3\u003EApplication Security Engineer\u003C/h3\u003E\u003Cp\u003EPurpose\u003Cbr /\u003EThis is the first engineering hire into Rightmove\u0026#39;s growing Application Security function,reporting to the Lead Application Security Engineer. You\u0026#39;ll work closely with engineering teamsto deliver day-to-day AppSec capabilities across security tooling, vulnerability management,secure design and threat modelling, while helping shape how Application Security operates asthe function matures.\u003C/p\u003E\u003Ch3\u003EKey Responsibilities\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EVulnerability Management \u0026amp; Security Tooling\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESupport the rollout and operation of application security tooling across engineeringrepositories, including SAST, SCA and secrets detection.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ETriage and classify security findings across repos, driving remediation of the secrets backlog\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EManage the day-to-day operation of vulnerability management, including findings triage,monitoring and engineering engagement.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EMaintain engineer-facing guidance for resolving vulnerabilities and requesting exceptions\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ECloud Security\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003ESupport cloud security posture management through Prisma Cloud, including findings triage,monitoring and engagement with relevant engineering/platform teams.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EEngineering Team Engagement\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003ERun a risk-tiered engagement cadence with engineering teams based on SLA compliance\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ESecurity Reviews \u0026amp; Triage\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003ETriage inbound security requests per the AppSec triage SLA\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EConduct secure design and API security reviews for new services, integrations, and RFCs\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EReview and respond to penetration test requests and third-party integration reviews\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EThreat Modelling\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EFacilitate threat modelling sessions using the team\u0026#39;s runbook/guide\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWork with engineering teams to establish and improve threat modelling practices acrosssquads\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EProcess \u0026amp; Documentation\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EMaintain runbooks and process documentation as the function matures\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESupport recurring review cadences (e.g. access reviews, vulnerability audits)\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003ERequirements\u003Cbr /\u003EMust have:\u003C/p\u003E\u003Cul\u003E\u003Cli\u003EPractical experience in application security, security engineering or a related hands-onsecurity role\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAble to assess security findings in context, distinguish meaningful risk from tooling noise, andmake pragmatic recommendations to engineering teams.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWorking proficiency in Python (able to read, modify, and write scripts used for internal tooling)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPractical experience with DAST/SAST/SCA/secrets scanning tools (Aikido, Snyk, Semgrep,Checkmarx, or similar)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience with Prisma Cloud or a comparable cloud-native security platform\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EComfortable reading code and understanding CI/CD pipelines (GitLab CI or equivalent)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience running or contributing to threat modelling exercises\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EComfortable running recurring stakeholder syncs with engineering teams\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong written communication\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAble to triage and prioritise a high volume of inbound requests independently\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ENice to have:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EExposure to GCP security controls\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFamiliarity with supply-chain security (npm/PyPI dependency risks)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPrior experience in a scaling/greenfield security function\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ESuccess in first 6 months\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EFully ramped on Aikido, independently supporting rollout, triage and day-to-day operations\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECloud Security handover complete: backlog triaged, monitoring cadence running\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ERisk-tiered engagement cadence live and running its first full cycle\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EIndependently triaging and closing security review requests within SLA\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EIndependently facilitating threat modelling sessions with engineering teams\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EIdentified and delivered improvements to at least one AppSec process or workflow\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ELife at Rightmove\u003C/h3\u003E\u003Cp\u003EDespite our growth, we\u2019ve remained a friendly, supportive place to work, with employee #1 still working here! We\u2019ve done this by placing the Rightmove Hows at the heart of everything we do. These are the essential values that reflect our culture, and include:\u003C/p\u003E\u003Cul\u003E\u003Cli\u003EWe create value\u2026by delivering results and building trust with partners and consumers.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWe think bigger\u2026by acting with curiosity and setting bold aspirations.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWe care deeply\u2026by being real, having fun, and valuing diversity.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWe move together\u2026by being one team - internally collaborative, externally competitive.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWe make a difference\u2026by focusing on delivering measurable impact.\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003EWe believe in careers that open doors and help our team develop by providing an open and inclusive work environment, offering ongoing training opportunities, and supporting charity fundraising events. And with 89% of Rightmovers saying we\u2019re a great place to work, we\u2019re clearly doing something right!\u003C/p\u003E\u003Ch3\u003EWhat we offer\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003ECash plan for dental, optical and physio treatments.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPrivate Medical Insurance, Pension and Life Insurance, Employee Assistance Plan.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003E27 days holiday plus two (paid) volunteering days a year to give back, and holiday buy schemes.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EContributory stakeholder pension.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ELife assurance at 4x your basic salary to a spouse, family member or other nominated person in your life.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECompetitive compensation package.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPaid leave for maternity, paternity, adoption \u0026amp; fertility.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ETravel Loans, Bike to Work scheme, Rental Deposit Loan.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECharitable contributions through Payroll Giving and donation matching.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAccess deals and discounts on things like travel, electronics, fashion, gym memberships, cinema discounts and more.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWe offer hybrid working with a minimum of 2 days in the office. For our roles, such as Field or Home-based positions, different working arrangements apply - full details will be shared during the recruitment process.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EAs an Equal Opportunity Employer, Rightmove will never discriminate based on age, disability, sex, race, religion or belief, gender reassignment, marriage / civil partnership, pregnancy/maternity or sexual orientation.\u003C/h3\u003E\u003Cp\u003EAt Rightmove, we believe that a diverse and inclusive workforce leads to better innovation, productivity, and overall success. We are committed to creating a welcoming and inclusive environment for all employees, regardless of their background or identity, to develop and promote a diverse culture that reflects the communities we serve.\u003C/p\u003E\u003Ch3\u003EBy applying, you confirm that you are aged at least 18 or over and that you\u2019ve read and understood our Privacy Policy, which explains how we handle and protect your personal information during the recruitment process.\u003C/h3\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"application-security-engineer-at-rightmove-53294a38228f"},"url":"https://gurify.com/job/application-security-engineer-at-rightmove-53294a38228f","datePosted":"2026-10-02","validThrough":"2026-11-17T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Rightmove","sameAs":"https://job-boards.eu.greenhouse.io/rightmovecareers"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"GB","addressLocality":"London"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"United Kingdom","item":"https://gurify.com/jobs/united-kingdom"},{"@type":"ListItem","position":3,"name":"Application Security Engineer","item":"https://gurify.com/job/application-security-engineer-at-rightmove-53294a38228f"}]}
```
