# Lead Application Security Engineer

[Brunswickgroup](https://gurify.com/jobs?q=Brunswickgroup) · London, United Kingdom · Posted 2 days ago

Lead

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://job-boards.greenhouse.io/brunswickgroup/jobs/8867735002)

## Job description

### Opportunity

The Lead Application Security Engineer will join Brunswick's Information Security team and play a key role in shaping how the firm embeds security into application design, development, deployment, and technology change.

This is a senior individual contributor role initially, with scope to help establish and mature Brunswick's application security capability over time. The role will focus on providing risk-based security advice and assurance across internally developed applications, enterprise platforms, integrations, cloud services, SaaS solutions, and selected AI-enabled workstreams.

Working closely with ICT, AI Engineering, application owners, and business stakeholders, the Lead Application Security Engineer will help define practical security standards, guardrails, review processes, and secure design patterns that enable delivery teams to move at pace while managing risk appropriately.

### About the Role

In this role, you will provide senior application security and DevSecOps expertise across technology projects, design reviews, cloud-based applications, APIs, integrations, delivery pipelines, and selected AI-enabled solutions.

You will act as a senior security advisor to technical and business teams, helping establish a repeatable application security model that can scale as demand grows, including the potential introduction of additional team members in the future.

### Key responsibilities include:

- Lead the development of Brunswick's application security capability, including standards, secure design patterns, review processes, and practical guardrails.

- Act as a senior security advisor to ICT, AI Engineering, application owners, and business stakeholders.

- Review and assess application designs, architecture decisions, APIs, integrations, cloud services, and deployment patterns to identify security risks early in the delivery lifecycle.

- Mature repeatable approaches for application security reviews, threat modelling, and risk-based assurance across new and changed solutions.

- Provide guidance and oversight on secure development lifecycle practices, including security requirements, design review, code and security review considerations, dependency management, secrets management, testing, and release assurance.

- Conduct threat modelling for internally developed applications, AI-enabled workflows, integrations, automation use cases, and higher-risk technology changes, using STRIDE or similar methodologies.

- Advise on secure design principles, including identity and access management, API security, data protection, encryption, logging, monitoring, resilience, secure configuration, and least privilege.

- Support security review of CI/CD pipelines, infrastructure as code, containerised workloads, and cloud infrastructure, identifying practical controls for engineering and platform teams.

- Review and assess third-party platforms, SaaS solutions, and new technology features, including AI-enabled tools where there are material application, integration, or data security considerations.

- Support the development and application of secure patterns and guardrails for emerging technology adoption, including AI-enabled solutions, agents, and automation where relevant.

- Support security assurance activities, including penetration testing, application security testing, remediation tracking, and ensuring appropriate logging, monitoring, and response considerations are built into new solutions.

- Define and document security requirements, architecture decisions, design recommendations, and risk-based remediation actions.

- Support the future growth of the application security function, including helping define ways of working, capability needs, and technical guidance for future team members as the function matures.

### What We're Looking For

We're looking for an experienced, technically capable security professional who can lead and mature an application security capability while remaining pragmatic, hands-on, and delivery-focused.

### The ideal candidate will demonstrate:

- 7+ years' experience in cyber security, application security, DevSecOps, cloud security, security architecture, security engineering, or a related technical security role.

- Strong understanding of risk management and compensative controls.

- Experience operating as a senior technical advisor or lead within application security, DevSecOps, cloud security, secure engineering, or a related discipline.

- Proven experience working alongside software engineering, DevOps, platform, cloud, or ICT teams to secure applications and infrastructure throughout the delivery lifecycle.

- Strong understanding of secure development lifecycle and application security practices, including threat modelling, secure design, API security, authentication and authorisation, secrets management, dependency management, security testing, and remediation planning.

- Practical experience reviewing application architectures, APIs, integrations, cloud services, CI/CD pipelines, containerised workloads, or infrastructure as code.

- Practical understanding of Microsoft 365, Azure, SaaS platforms, and Azure application security controls such as Entra ID, managed identities, Key Vault, API Management, container security, logging, monitoring, and secure configuration.

- Experience conducting STRIDE-based threat modelling, technical risk assessments, application security reviews, or security design reviews.

- Experience developing security standards, secure design patterns, review processes, or guardrails that can be adopted by engineering and delivery teams.

- Ability to translate technical security risks into clear, business-focused recommendations and influence delivery teams without directly owning implementation.

- Familiarity with AI-related technologies, large language models, AI-enabled applications, and associated risks such as data exposure, prompt injection, insecure integrations, and excessive agent permissions would be beneficial.

- Strong written and verbal communication skills, sound judgement, attention to detail, and the ability to balance security requirements with business needs.

- Experience working in an ISO27001-aligned or regulated environment would be beneficial.

- Preferred, but not essential, certifications:

- ISC2: CISSP, CCSP, SSCP, CSSLP

- ISACA: CISM, CISA, CRISC

- CompTIA: Security+, CySA+, CASP+

- GIAC, Microsoft Azure, or other relevant application security, cloud security, architecture, or DevSecOps certifications

### Why Join Us

Joining Brunswick unlocks a range of employee benefits to support your financial future, health and wellness, family and community, and continuous professional development.

### About Brunswick

Brunswick is a global advisory firm. We help companies tackle high-stakes issues, navigate complex stakeholder relationships, and deliver high-impact outcomes.

Our clients value our ability to anticipate, shape, and respond to the key players and forces in the financial and investment arena, regulatory and geopolitical universe, NGO community, workforce and beyond. They rely on us for deep experience, fresh perspectives and original thinking. So, in Brunswick you will find an exceptional range of experience and talent with a rich mix of backgrounds. From the beginning, we have prioritized attracting, developing, and retaining the best professionals in the industry, united by a culture of inclusivity, excellence, and intellectual curiosity.

Founded in 1987 in London, the firm has organically grown to 27 offices in 18 countries across the Americas, Europe, Middle East, Africa, Asia and Australia. We operate as a “one-firm firm” with no individual profit centers. This allows us to assemble fully integrated, bespoke teams for each client, able to draw on the full resources of Brunswick anywhere in the world.

Brunswick is an equal opportunity employer. All qualified applicants will be considered without regard to race, religion, color, national origin, gender, sexual orientation, age, disability, pregnancy, genetic information, or any other status protected by applicable law. Please read our Global Privacy Notice to understand how your data is managed.

**Live in Brunswickgroup’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- RI [Application Security Engineer](https://gurify.com/job/application-security-engineer-at-rightmove-53294a38228f) Rightmove · London, United Kingdom · 5 days ago
- GE [Application Security Engineer](https://gurify.com/job/application-security-engineer-at-genomics-7b8e06290558) Genomics · London · yesterday
- WR [Security engineer, application security (UK)](https://gurify.com/job/security-engineer-application-security-uk-at-writer-5099130c9e15) Writer · London, United Kingdom · 2 weeks ago
- XA [Infrastructure Security Engineer](https://gurify.com/job/infrastructure-security-engineer-at-xai-5df6888fa213) Xai · Dublin, United Kingdom · last week
- OM [Platform Security Engineer](https://gurify.com/job/platform-security-engineer-at-omnea-79e993c63a72) Omnea · London · yesterday
- EN [Lead Security Engineer](https://gurify.com/job/lead-security-engineer-at-encord-691754c23bc3) Encord · London · 5 days ago

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Lead Application Security Engineer","description":"\u003Ch3\u003EOpportunity\u003C/h3\u003E\u003Cp\u003EThe Lead Application Security Engineer will join Brunswick\u0026#39;s Information Security team and play a key role in shaping how the firm embeds security into application design, development, deployment, and technology change.\u003C/p\u003E\u003Cp\u003EThis is a senior individual contributor role initially, with scope to help establish and mature Brunswick\u0026#39;s application security capability over time. The role will focus on providing risk-based security advice and assurance across internally developed applications, enterprise platforms, integrations, cloud services, SaaS solutions, and selected AI-enabled workstreams.\u003C/p\u003E\u003Cp\u003EWorking closely with ICT, AI Engineering, application owners, and business stakeholders, the Lead Application Security Engineer will help define practical security standards, guardrails, review processes, and secure design patterns that enable delivery teams to move at pace while managing risk appropriately.\u003C/p\u003E\u003Ch3\u003EAbout the Role\u003C/h3\u003E\u003Cp\u003EIn this role, you will provide senior application security and DevSecOps expertise across technology projects, design reviews, cloud-based applications, APIs, integrations, delivery pipelines, and selected AI-enabled solutions.\u003C/p\u003E\u003Cp\u003EYou will act as a senior security advisor to technical and business teams, helping establish a repeatable application security model that can scale as demand grows, including the potential introduction of additional team members in the future.\u003C/p\u003E\u003Ch3\u003EKey responsibilities include:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003ELead the development of Brunswick\u0026#39;s application security capability, including standards, secure design patterns, review processes, and practical guardrails.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAct as a senior security advisor to ICT, AI Engineering, application owners, and business stakeholders.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EReview and assess application designs, architecture decisions, APIs, integrations, cloud services, and deployment patterns to identify security risks early in the delivery lifecycle.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EMature repeatable approaches for application security reviews, threat modelling, and risk-based assurance across new and changed solutions.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EProvide guidance and oversight on secure development lifecycle practices, including security requirements, design review, code and security review considerations, dependency management, secrets management, testing, and release assurance.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EConduct threat modelling for internally developed applications, AI-enabled workflows, integrations, automation use cases, and higher-risk technology changes, using STRIDE or similar methodologies.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAdvise on secure design principles, including identity and access management, API security, data protection, encryption, logging, monitoring, resilience, secure configuration, and least privilege.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESupport security review of CI/CD pipelines, infrastructure as code, containerised workloads, and cloud infrastructure, identifying practical controls for engineering and platform teams.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EReview and assess third-party platforms, SaaS solutions, and new technology features, including AI-enabled tools where there are material application, integration, or data security considerations.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESupport the development and application of secure patterns and guardrails for emerging technology adoption, including AI-enabled solutions, agents, and automation where relevant.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESupport security assurance activities, including penetration testing, application security testing, remediation tracking, and ensuring appropriate logging, monitoring, and response considerations are built into new solutions.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDefine and document security requirements, architecture decisions, design recommendations, and risk-based remediation actions.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESupport the future growth of the application security function, including helping define ways of working, capability needs, and technical guidance for future team members as the function matures.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EWhat We\u0026#39;re Looking For\u003C/h3\u003E\u003Cp\u003EWe\u0026#39;re looking for an experienced, technically capable security professional who can lead and mature an application security capability while remaining pragmatic, hands-on, and delivery-focused.\u003C/p\u003E\u003Ch3\u003EThe ideal candidate will demonstrate:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003E7\u002B years\u0026#39; experience in cyber security, application security, DevSecOps, cloud security, security architecture, security engineering, or a related technical security role.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong understanding of risk management and compensative controls.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience operating as a senior technical advisor or lead within application security, DevSecOps, cloud security, secure engineering, or a related discipline.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EProven experience working alongside software engineering, DevOps, platform, cloud, or ICT teams to secure applications and infrastructure throughout the delivery lifecycle.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong understanding of secure development lifecycle and application security practices, including threat modelling, secure design, API security, authentication and authorisation, secrets management, dependency management, security testing, and remediation planning.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPractical experience reviewing application architectures, APIs, integrations, cloud services, CI/CD pipelines, containerised workloads, or infrastructure as code.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPractical understanding of Microsoft 365, Azure, SaaS platforms, and Azure application security controls such as Entra ID, managed identities, Key Vault, API Management, container security, logging, monitoring, and secure configuration.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience conducting STRIDE-based threat modelling, technical risk assessments, application security reviews, or security design reviews.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience developing security standards, secure design patterns, review processes, or guardrails that can be adopted by engineering and delivery teams.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAbility to translate technical security risks into clear, business-focused recommendations and influence delivery teams without directly owning implementation.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFamiliarity with AI-related technologies, large language models, AI-enabled applications, and associated risks such as data exposure, prompt injection, insecure integrations, and excessive agent permissions would be beneficial.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong written and verbal communication skills, sound judgement, attention to detail, and the ability to balance security requirements with business needs.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience working in an ISO27001-aligned or regulated environment would be beneficial.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPreferred, but not essential, certifications:\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EISC2: CISSP, CCSP, SSCP, CSSLP\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EISACA: CISM, CISA, CRISC\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECompTIA: Security\u002B, CySA\u002B, CASP\u002B\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EGIAC, Microsoft Azure, or other relevant application security, cloud security, architecture, or DevSecOps certifications\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EWhy Join Us\u003C/h3\u003E\u003Cp\u003EJoining Brunswick unlocks a range of employee benefits to support your financial future, health and wellness, family and community, and continuous professional development.\u003C/p\u003E\u003Ch3\u003EAbout Brunswick\u003C/h3\u003E\u003Cp\u003EBrunswick is a global advisory firm. We help companies tackle high-stakes issues, navigate complex stakeholder relationships, and deliver high-impact outcomes.\u003C/p\u003E\u003Cp\u003EOur clients value our ability to anticipate, shape, and respond to the key players and forces in the financial and investment arena, regulatory and geopolitical universe, NGO community, workforce and beyond. They rely on us for deep experience, fresh perspectives and original thinking. So, in Brunswick you will find an exceptional range of experience and talent with a rich mix of backgrounds. From the beginning, we have prioritized attracting, developing, and retaining the best professionals in the industry, united by a culture of inclusivity, excellence, and intellectual curiosity.\u003C/p\u003E\u003Cp\u003EFounded in 1987 in London, the firm has organically grown to 27 offices in 18 countries across the Americas, Europe, Middle East, Africa, Asia and Australia. We operate as a \u201Cone-firm firm\u201D with no individual profit centers. This allows us to assemble fully integrated, bespoke teams for each client, able to draw on the full resources of Brunswick anywhere in the world.\u003C/p\u003E\u003Cp\u003EBrunswick is an equal opportunity employer. All qualified applicants will be considered without regard to race, religion, color, national origin, gender, sexual orientation, age, disability, pregnancy, genetic information, or any other status protected by applicable law. Please read our Global Privacy Notice to understand how your data is managed.\u003C/p\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"lead-application-security-engineer-at-brunswickgroup-5849dbce754f"},"url":"https://gurify.com/job/lead-application-security-engineer-at-brunswickgroup-5849dbce754f","datePosted":"2026-10-05","validThrough":"2026-11-21T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Brunswickgroup","sameAs":"https://job-boards.greenhouse.io/brunswickgroup"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"GB","addressLocality":"London"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"United Kingdom","item":"https://gurify.com/jobs/united-kingdom"},{"@type":"ListItem","position":3,"name":"Lead Application Security Engineer","item":"https://gurify.com/job/lead-application-security-engineer-at-brunswickgroup-5849dbce754f"}]}
```
