Application Security Engineer

Posted 27 Days Ago
Be an Early Applicant
Manchester, Greater Manchester, England, GBR
Hybrid
Junior
Software • Cybersecurity
The Role
Perform penetration testing across web applications, APIs, and mobile applications for clients. Identify vulnerabilities, support remediation with technical and non-technical stakeholders, conduct risk reviews of application changes, and collaborate with developers to strengthen application security and continuous security testing processes.
Summary Generated by Built In

We're looking for a Application Security Engineer to join our Manchester-based application security business as a member of the AppSec Engineering team
Cytix is a platform that threat models development tickets and creates security testing plans that include both manual and automated testing.

In this role, you won't be confined to traditional 4+1 web applications. We're breaking away from the constraints of CHECK or CE+ standards, and we're not interested in producing lengthy PDF reports. Instead, our focus is on seamlessly integrating continuous penetration testing into our customers' Software Development Life Cycle (SDLC).

Collaborating closely with both our in-house development team and clients, you'll play in pivotal role in driving penetration testing.


Having recently secured Series A funding this opportunity is genuinely one-of-a-kind for the right individual!

 

What you'll do

Operating as a Security Consultant specialising in Application Security (AppSec) Testing.

 
  • Penetration Testing web applications, APIs, mobile applications, etc for our clients across a range of industries.

  • Working with stakeholders of both a technical and non-technical nature to assist in vulnerability identification and remediations.

  • Performing risk reviews of application changes as part of our continuous security testing process.

  • You are comfortable collaborating with developers and external customers.

What you'll bring

  • 2+ years in Penetration Testing, Application Security Engineering, or a similar offensive security role.

What you'll get:

  • Share options - If Cytix wins, you should too.

  • Unlimited Holidays!

  • Enhanced maternity and paternity pay.

  • Pension - 8% (3% employer, 5% employee)

  • Private Healthcare through Vitality including dental, optical and hearing

  • Work from anywhere (WFA)

  • Celebrate your birthday with a day off work

  • Octopus car scheme - Drive an electric car through salary sacrifice

  • Inclusivity as standard - A team where you can do your best work as yourself, no asterisks.

About Cytix

  • Software never stops changing. Teams ship new code every day, through tickets, pull requests, releases, and increasingly with AI in the mix, but the way security keeps up with all that change hasn't really moved on.

  • That's the problem we're solving. Cytix helps organisations understand which software changes actually matter, what should happen next, and how to prove the right call was made. Security understood, in other words.

  • We're a small team with big plans, so every person we hire genuinely shapes what Cytix becomes. That's why we're upfront about our five values: we interview for all of them, and they matter to us more than a perfect CV. They're things you do, not things you are, so have a read and see if they sound like you.

    Make the first move. When the goal is clear but the path isn't, you get moving rather than waiting for perfect instructions. If you're blocked, you make a sensible call, say what you're assuming, and explain how you'd course-correct. We'd rather you act and be slightly wrong than sit still.

    Find the smarter path. You ask why before how. You dig into what the real problem is instead of just building what the spec says, and you're happy to question 'that's how it's always been done' when the reason behind it has gone stale.

    See it through. When something's yours, it lands. No loose ends, no surprises for whoever picks it up next. You keep people posted when things change, and if something falls between roles, you catch it.

    Raise the bar. You do the best job possible in the time you've got, whether that's a day or a month. Sometimes that means deep craft; sometimes the smartest move is quick and scrappy. It's about good judgement, and we hold each other to it without blame or politics.

    Play to win. You care about the mission but don't take yourself too seriously. You say 'I' when things go wrong and 'we' when they go right, trust teammates to do things their own way, and bring a bit of humour when the pressure's on.

    Sound like you on a normal working day? We'd love to meet you.

Skills Required

  • 2+ years of experience in penetration testing, application security engineering, or a similar offensive security role.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
Manchester
10 Employees
Year Founded: 2022

What We Do

Cytix is the first truly continuous security testing platform, focused on identifying change and using it to intelligently determine when to test. Whether it’s a developer making a pull request, threat intelligence about a new vulnerability, or a new server being deployed, we take feeds of data from across your technology stack and use this as telemetry to determine what has changed and what actions need to be taken to assess the impact that this has had on security. Simply connect us to your existing workflows through our list of pre-built integrations or leverage the suite of native tools within our platform. We bridge the gap between automation and manual testing by identifying what actions are needed at any time and carrying them out as a sequence of tasks. Through this, we are able to minimise the time between vulnerabilities being introduced and being identified, and provide the information you need in order to resolve them as efficiently as possible. We support applications, APIs, cloud-native services, and traditional infrastructure, providing you with a centralised platform from which to build a continuous security testing programme. We are CREST-accredited and our product can either be used to drive an internal security testing programme, or as a fully managed service. Watch as your entire security testing programme runs automatically.

Similar Jobs

Samsara Logo Samsara

Application Security Engineer

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
United Kingdom
4000 Employees
139K-174K Annually

Simply Business Logo Simply Business

Application Security Engineer

Fintech • Information Technology • Insurance • Software
Hybrid
London, England, GBR
1000 Employees

CAIS Logo CAIS

Application Security Engineer

Fintech • Software • Financial Services
Hybrid
London, England, GBR
341 Employees
In-Office
London, Greater London, England, GBR
335 Employees

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account