Senior Application Security Engineer

Manchester hybrid Until 9/25/2026 First posted July 27, 2026 Last posted July 27, 2026
Job description

Are you ready to shape the future of data?

Matillion is the company behind Maia, the AI Data Automation platform. 

In the AI economy, demand for data is exploding. Manual data engineering can’t keep up. Maia fixes that by combining 15 years of data expertise with agentic AI to eliminate the manual work that slows data teams down. Organisations like Cisco, DocuSign, and Slack are already using it to deliver real business impact, faster.

We started in Manchester and now we’re global - with teams across the UK, US and India.

We are driven, curious, energetic people who move fast, think big and hold ourselves to a high standard. We’re here to make a dent in the universe bigger than ourselves. And we’re looking for people who want to be part of it.


Role Purpose
 
Matillion is built around small development teams utilising a modern, cloud-based technology stack to deliver products. The AppSec Engineer will work in an engineering capacity to product and engineering teams to ensure security is baked into the product from the design phase creating a SecDevOps workflow.

What you will be doing

    Design
    Establish and lead security champions programme across the development squads
    Build functional and nonfunctional requirements for the application in conjunction with the product team
    Input abuse case stories into the product backlog
    Evangelise security across the product team, ensuring security stories are prioritised against feature goals
    Assess SDLC security gap risks and propose remedies
     
    Consult
    Instruct and guide developers on how to conduct Threat Modelling during application Design
    Act as the single point of contact for security concerns arising from the development team providing advice on how to solve technical software issues
    Lead the pentesting cadence around the core application set by conducting hacking exercises
    Provide application code reviews against known development frameworks such as OWASP ASVS
    Provide input into the design of functional and non-functional security controls such as customer authentication workflows
    Run Security Champion sessions to keep developers aware of security developments
     
    Engineer
    Establish security into the CICD pipeline such as SAST/IAST/DAST
    Automate and build nifty security tools to test Matillion applications 
    Integrate testing, build failures and outputs to the development team to ensure passage to production is secure
    Create security tests for code and assist developers in building security unit testing
     
    Support
    Responsive support to the development teams
    Analysis of logs to identify issues and provide solutions
     
    Innovation
    Research projects, including prototyping, to explore future opportunities
    Investigate new technologies
    Optimise the infrastructure deployment process through use of automation, in-house and open source solutions
     
    Self-Development and Growth
    Develop new skills by working with other members of the team
    Work with the Team Lead to identify training goals
    Lead and partake in technical discussions within the team
    Actively identify and complete opportunities for self-training and external training
    Drive the team’s process of continual improvement

What we are looking for

    Technical / Role Specific 
     
    Essential
    A passion and drive to succeed in Application Security
    Understanding of Software Development Life Cycle
     
    Desirable
    Security professional at heart borne from a software engineering background
    Experience of working with the OWASP ASVS framework
    Experience in Agile delivery environments
    Greenfield experience setting up security technologies from scratch
    Outgoing and able to build relationships with key stakeholders
     
    Personal Capabilities Required, e.g. skills, attitude, strengths
    Can do attitude, willing to take on a wide range of security issues
    Keeps up to date with security developments
    Keen to engage with the security community on a range of topics
    Fast learner

More about Matillion

We operate a flexible working culture that promotes work-life balance, with benefits including:

  • Company Equity

  • 30 days holiday + bank holiday

  • 5 days paid volunteering leave

  • Private Health Insurance

  • Life Insurance

  • Pension

  • Access to mental health support

Your Safety

Matillion recruiters will only contact you from @matillion.com email addresses. We occasionally work with trusted recruiting partners; they will always tell you they are working on our behalf. We will never ask for money, fees, or bank details at any point in the hiring process. If something feels off, trust that instinct. Don't click any links. Go straight to matillion.com/careers to verify open roles or reach us at [email protected].

Want to know more?

Don't tick every box? Apply anyway. We hire for potential, not just experience. A member of our Talent Acquisition team will be in touch.

Cannot find anything suitable role right now? We still want to hear from you. Drop us a line at [email protected].

Find out more about life on #TeamGreen here

Matillion is an equal opportunity employer. We celebrate diversity and we are committed to creating an inclusive environment for all of our team. Matillion prohibits discrimination and harassment of any type. Matillion does not discriminate on the basis of race, colour, religion, age, sex, national origin, disability status, genetics, sexual orientation, gender identity or expression, or any other characteristic protected by law. 

Compensation (from employer):
71440–107160 GBP per year

About this role

Summary

Ensure security in application development, perform threat modeling, pentesting, automate security testing

Job title

Senior Application Security Engineer

Experience level

professional

Industry

software

Location requirements

Manchester, remote work not specified

Salary

£71k–£107k

Management role

No

Skills & keywords

Required skills

understanding of SDLCknowledge of OWASP ASVSsecurity testingcode review

Preferred skills

security frameworksagile experiencesecurity automation

Specializations

application securityDevSecOpsthreat modelingpentestingOWASP
Locations

Structured locations inferred from the posting.

Manchester, UK

Hybrid City