Application Security Engineer - Infosum (Basingstoke, Hybrid: 2 days onsite)
InfoSum
- Basingstoke, Hampshire
- Permanent
- Full-time
- Perform application security testing across web apps, APIs, and supporting cloud infrastructure.
- Carry out penetration testing and provide clear, actionable vulnerability reports.
- Work closely with engineers (using Go and Node.js) to remediate security issues and integrate security best practices into the SDLC.
- Contribute to threat modeling and risk assessments for new and existing features.
- Develop or adapt security testing scripts and tools to improve automation and coverage.
- Keep up-to-date with emerging application and cloud security threats and share insights with the wider team.
- Evaluate and experiment with advanced security technologies such as Trusted Execution Environments (TEEs).
- Proven experience in application security testing (SAST, DAST, penetration testing).
- Strong understanding of cloud security fundamentals across major providers (AWS, Azure, GCP).
- Ability to code and review code in Go and Node.js.
- Familiarity with common vulnerabilities (OWASP Top 10, API security risks) and secure coding practices.
- Strong communication skills to clearly explain risks and collaborate effectively with developers.
- A competitive salary based on your experience and ability to perform in role
- 25 days annual leave (excluding bank holidays)
- 8% pension contribution
- Private health care via Vitality
- Fantastic corporate discounts and mental wellbeing support via Perkbox, including a top of line EAP.
- Salary sacrifice schemes
We are sorry but this recruiter does not accept applications from abroad.