Level

Rightmove

Application Security Engineer

AI in this role

Application Security Engineer required to drive security tooling, vulnerability management, secure design, and threat modelling at Rightmove.

prisma-cloudsastsca
application-securityvulnerability-managementthreat-modellingcloud-securityapi-security

 



Our vision is to give everyone the belief they can make their move. We aim to make moving simpler, by giving everyone the best place to turn to and return to for access to the tools, expertise, trust, and belief to make it happen.

We’re home to the UK’s largest choice of properties and are the go-to destination for millions of people planning their next move, reading the latest industry news, or just browsing what’s on the market. 

 

Application Security Engineer

Purpose
This is the first engineering hire into Rightmove's growing Application Security function,reporting to the Lead Application Security Engineer. You'll work closely with engineering teamsto deliver day-to-day AppSec capabilities across security tooling, vulnerability management,secure design and threat modelling, while helping shape how Application Security operates asthe function matures.

Key Responsibilities

  • Vulnerability Management & Security Tooling
  • Support the rollout and operation of application security tooling across engineeringrepositories, including SAST, SCA and secrets detection.
  • Triage and classify security findings across repos, driving remediation of the secrets backlog
  • Manage the day-to-day operation of vulnerability management, including findings triage,monitoring and engineering engagement.
  • Maintain engineer-facing guidance for resolving vulnerabilities and requesting exceptions

Cloud Security

  • Support cloud security posture management through Prisma Cloud, including findings triage,monitoring and engagement with relevant engineering/platform teams.

Engineering Team Engagement

  • Run a risk-tiered engagement cadence with engineering teams based on SLA compliance

Security Reviews & Triage

  • Triage inbound security requests per the AppSec triage SLA
  • Conduct secure design and API security reviews for new services, integrations, and RFCs
  • Review and respond to penetration test requests and third-party integration reviews

Threat Modelling

  • Facilitate threat modelling sessions using the team's runbook/guide
  • Work with engineering teams to establish and improve threat modelling practices acrosssquads

Process & Documentation

  • Maintain runbooks and process documentation as the function matures
  • Support recurring review cadences (e.g. access reviews, vulnerability audits)

Requirements
Must have:

  • Practical experience in application security, security engineering or a related hands-onsecurity role
  • Able to assess security findings in context, distinguish meaningful risk from tooling noise, andmake pragmatic recommendations to engineering teams.
  • Working proficiency in Python (able to read, modify, and write scripts used for internal tooling)
  • Practical experience with DAST/SAST/SCA/secrets scanning tools (Aikido, Snyk, Semgrep,Checkmarx, or similar)
  • Experience with Prisma Cloud or a comparable cloud-native security platform
  • Comfortable reading code and understanding CI/CD pipelines (GitLab CI or equivalent)
  • Experience running or contributing to threat modelling exercises
  • Comfortable running recurring stakeholder syncs with engineering teams
  • Strong written communication
  • Able to triage and prioritise a high volume of inbound requests independently

Nice to have:

  • Exposure to GCP security controls
  • Familiarity with supply-chain security (npm/PyPI dependency risks)
  • Prior experience in a scaling/greenfield security function

Success in first 6 months

  • Fully ramped on Aikido, independently supporting rollout, triage and day-to-day operations
  • Cloud Security handover complete: backlog triaged, monitoring cadence running
  • Risk-tiered engagement cadence live and running its first full cycle
  • Independently triaging and closing security review requests within SLA
  • Independently facilitating threat modelling sessions with engineering teams
  • Identified and delivered improvements to at least one AppSec process or workflow

Life at Rightmove

Despite our growth, we’ve remained a friendly, supportive place to work, with employee #1 still working here!  We’ve done this by placing the Rightmove Hows at the heart of everything we do. These are the essential values that reflect our culture, and include:

  • We create value…by delivering results and building trust with partners and consumers.
  • We think bigger…by acting with curiosity and setting bold aspirations.
  • We care deeply…by being real, having fun, and valuing diversity.
  • We move together…by being one team - internally collaborative, externally competitive.
  • We make a difference…by focusing on delivering measurable impact.

 

 

We believe in careers that open doors and help our team develop by providing an open and inclusive work environment, offering ongoing   training opportunities, and supporting charity fundraising events. And with 89% of Rightmovers saying we’re a great place to work, we’re clearly doing something right! 


What we offer

  • Cash plan for dental, optical and physio treatments.
  • Private Medical Insurance, Pension and Life Insurance, Employee Assistance Plan.
  • 27 days holiday plus two (paid) volunteering days a year to give back, and holiday buy schemes.
  • Contributory stakeholder pension.
  • Life assurance at 4x your basic salary to a spouse, family member or other nominated person in your life.
  • Competitive compensation package.
  • Paid leave for maternity, paternity, adoption & fertility.
  • Travel Loans, Bike to Work scheme, Rental Deposit Loan.
  • Charitable contributions through Payroll Giving and donation matching.
  • Access deals and discounts on things like travel, electronics, fashion, gym memberships, cinema discounts and more.
  • We offer hybrid working with a minimum of 2 days in the office. For our roles, such as Field or Home-based positions, different working arrangements apply - full details will be shared during the recruitment process.

As an Equal Opportunity Employer, Rightmove will never discriminate based on age, disability, sex, race, religion or belief, gender reassignment, marriage / civil partnership, pregnancy/maternity or sexual orientation. 

At Rightmove, we believe that a diverse and inclusive workforce leads to better innovation, productivity, and overall success. We are committed to creating a welcoming and inclusive environment for all employees, regardless of their background or identity, to develop and promote a diverse culture that reflects the communities we serve.

By applying, you confirm that you are aged at least 18 or over and that you’ve read and understood our Privacy Policy, which explains how we handle and protect your personal information during the recruitment process.

How we rate this

Application Security Engineer at Rightmove rates 0 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.

Classification

Little AI. AI is not part of the work.

  1. ●●●● Builds AI80 to 100
  2. ●●●○ Works on AI60 to 79
  3. ●●○○ Uses AI40 to 59
  4. ●○○○ Little AI0 to 39

Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.

Prepare for this job

A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.

Skills and AI tools this role asks for

Application SecurityVulnerability ManagementThreat ModellingCloud SecurityAPI SecurityPrisma CloudSastSca

Questions you could be asked

  1. Tell me about a project where application security was part of your work. What did you do?
  2. Tell me about a project where vulnerability management was part of your work. What did you do?
  3. Tell me about a project where threat modelling was part of your work. What did you do?
  4. Tell me about a project where cloud security was part of your work. What did you do?
  5. Tell me about a project where api security was part of your work. What did you do?

Adapt your resume

  • List these exact terms on your resume: Application Security, Vulnerability Management, Threat Modelling, Cloud Security, and API Security. An applicant tracking system matches the wording, not the idea.
  • Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.

Want an expert to read your CV for this job?

Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.

Get a free CV review

Get new cybersecurity jobs by email

One email a week with the new cybersecurity jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.

Free. One email a week. Unsubscribe in one click.

Similar roles

Security roles that involve little AI, at other companies.

What kind of AI work fits you?

Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.

Find my next step

More jobs at Rightmove

More cybersecurity jobs

Related searches

Same AI level