Senior Application Security Engineer
You'll embed security practices into development workflows across Elsevier's engineering teams, focusing on CI/CD pipeline security, automated tooling integration, threat modeling, and secure-by-default delivery patterns. The role involves partnering with development teams to reduce application security risks, supporting remediation efforts, and designing reusable security templates and reference implementations. You'll need 5+ years in application security or software engineering with expertise in secure coding practices, CI/CD security controls, secrets management, and compliance automation.
Free Tailor for ATS: 10/10 runs left
Are you a software engineer who is passionate about building secure applications with an interest in moving into application security?
Do you enjoy collaborating with engineering teams to drive practical, secure-by-design solutions that reduce risk and improve delivery outcomes?
About the Role
As a Senior Application Security Engineer, you will contribute to strengthening secure software delivery across engineering teams by embedding security practices, tools, and automation into development workflows. This role focuses on enabling teams to build secure applications and CI/CD pipelines through practical guidance, reusable solutions, and improved processes. You will work across teams to reduce risk, improve reliability, and support secure-by-default delivery at scale.
Responsibilities
Partner with development teams to improve secure software delivery practices across applications and CI/CD pipelines
Support triage and remediation of application security findings through practical guidance and secure refactoring recommendations
Facilitate threat modelling activities and translate outcomes into actionable improvements and risk reduction measures
Design and maintain secure-by-default delivery patterns, reusable templates, and reference implementations
Support adoption of centrally managed tooling and automated security controls
Develop integrations and automation to enable security validation, audit evidence generation, and operational metrics
Collaborate with platform, architecture, and security teams to improve processes, tooling, and delivery capabilities
Communicate security guidance, standards, and best practices to stakeholders
Requirements
Experience in application security, software engineering, or product security
Knowledge of application security principles, common vulnerabilities, and secure coding practices across multiple technology stacks
5+ years of application security, software engineering, or product security experience.
BS Engineering/Computer Science or equivalent experience required.
Understanding of CI/CD security, including pipeline controls, identity and access management, and secrets handling
Experience integrating automated security tooling into software delivery workflows
Experience developing reusable templates, standards, and reference implementations
Familiarity with security automation, compliance support, and audit evidence generation
Awareness of industry security standards and best practices
Strong collaboration, communication, analytical, troubleshooting, and problem-solving skills
Work in a way that works for you
We promote a healthy work/life balance across the organization. We offer an appealing working prospect for our people. With numerous wellbeing initiatives, shared parental leave, study assistance and sabbaticals, we will help you meet your immediate responsibilities and your long-term goals.
Working flexible hours - flexing the times when you work in the day to help you fit everything in and work when you are the most productive
About the Business
A global leader in information and analytics, we help researchers and healthcare professionals advance science and improve health outcomes for the benefit of society. Building on our publishing heritage, we combine quality information and vast data sets with analytics to support visionary science and research, health education and interactive learning, as well as exceptional healthcare and clinical practice. At Elsevier, your work contributes to the world’s grand challenges and a more sustainable future. We harness innovative technologies to support science and healthcare to partner for a better world.
We know your well-being and happiness are key to a long and successful career. We are delighted to offer country specific benefits. Click here to access benefits specific to your location.
We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Form or please contact 1-855-833-5120.
Criminals may pose as recruiters asking for money or personal information. We never request money or banking details from job applicants. Learn more about spotting and avoiding scams here.
Please read our Candidate Privacy Policy.
We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law.
USA Job Seekers:
EEO Know Your Rights.