Skip to content

Summary

Location
Uxbridge
Job Type
Full Time
Ref #
74311
This role is a 12 Month Fixed Term Contract

As a Senior Application Security Engineer at giffgaff on a 12-month fixed-term contract, you'll be responsible for embedding security into the way we design, build and operate our products. Working across a modern technology estate, you'll help ensure security is considered from the earliest stages of development through to production, enabling engineers to deliver secure software with confidence.
This role combines technical depth with collaboration and influence. You'll work alongside engineers, architects and platform teams to identify risks, improve security controls, drive vulnerability remediation and strengthen our DevSecOps capabilities. You'll also help foster a strong security culture by coaching teams and championing security best practice throughout the business.
Who we are
Do you want to join a connectivity provider that's up to good? At giffgaff, we do things differently. We call out the bad and find a better way. We're laser-focused on flexibility, value and mutual good. And we're proud to be a certified B Corp. This means we've joined a network of more than 2,000 UK companies who want to make a positive impact on people and the planet. Working at giffgaff is something you could be proud of too.
You'll get the best of both worlds, the energy and fast pace of giffgaff, plus all the benefits that come with being part of our parent company, Virgin Media O2.
Our business model is unique. We work with our members (our customers) to understand their needs in all areas of the business. We love this highly collaborative approach. We're always looking to acquire new members, and to do that we need the best people in our team.
In return for your outstanding efforts, you'll be rewarded with a competitive salary and excellent benefits that are all about making your work life a winner. Take a look at our culture and benefits - you might just be surprised.
Our bright and modern gaff is in Uxbridge, in leafy West London. But if commuting isn't for you, most of our roles can be hybrid or remote, or anywhere in between.
The must haves
In order to be considered, you must have the following experience;
• Experience assessing security impacts across codebases and APIs using languages such as Java, TypeScript and Python.
• Strong knowledge of the OWASP Top 10, secure coding practices, and common web and API vulnerabilities.
• Hands-on experience triaging, validating and remediating vulnerabilities with both technical and non-technical stakeholders.
• Experience integrating security tooling into CI/CD pipelines and embedding DevSecOps practices.
• Proven expertise in threat modelling, secure code review, architecture review, and container/Kubernetes security.
The other stuff we are looking for
We'd also love you to bring;
• Security certifications such as OSCP, GWAPT, CSSLP, CEH or Security+.
• Experience securing AWS environments and infrastructure-as-code solutions such as Terraform.
• Knowledge of AI-enabled security workflows and securing AI or LLM-powered features.
• Experience contributing to or maintaining open-source security tooling.
What's in it for you
Our goal is to celebrate our people and their lives. We aim to create a culture that empowers everyone to bring the best versions of themselves to work each and every day. We believe the most inclusive and diverse culture makes for a better business and a brighter world.
Working at giffgaff means you get a bumper reward package bursting with benefits, and loads of extras you can add if you'd like to. These are designed to support both you and your loved ones, making sure that you're covered no matter what life throws your way.
We're all about hybrid working here, so expect to have a base location where you'll have the right facilities to enable amazing collaboration and quality time with your team, alongside all the right kit to work from home too.
Next steps
If we feel like a place where you can belong, we'd love to learn more about you as a person and your experience to date. Once you've submitted an application, the next steps of the process, if successful, are likely to include a chat with our recruiter, two technical interview stages and a final culture interview.
Please note: Applications will be reviewed, and interviews conducted throughout the duration of this advert, therefore we may bring the closing date forward. We encourage all interested applicants to apply as soon as possible. If you're offered a job with us, it will be conditional, based on the passing of background checks. All roles require a criminal record check and some roles need a financial probity check. Your recruiter can provide you with more information, if needed.
Thanks for your patience and for showing an interest in joining the giffgaff family.
#LI-gg