
Application Security Engineer
Job Description
Join us, be part of more.
We’re so much more than an energy company. We’re a family of brands revolutionising how we power the planet. We're energisers. One team of 21,000 colleagues that's energising a greener, fairer future by creating an energy system that doesn’t rely on fossil fuels, whilst living our powerful commitment to igniting positive change in our communities. Here, you can find more purpose, more passion, and more potential. That’s why working here is #MoreThanACareer. We do energy differently - we do it all. We make it, store it, move it, sell it, and mend it.
An opportunity to play your part - Are you passionate about building security into the heart of modern software delivery? We’re looking for an experienced Application Security Engineer to help strengthen secure development practices across Centrica’s multi-cloud environment, with a key focus on AWS, Azure DevOps and modern DevSecOps tooling. This is a brilliant opportunity to work closely with engineering, platform and security teams to reduce risk, improve our security posture and make secure, automated and scalable delivery feel like second nature. You’ll help define and embed application standards, champion developer enablement and play an important role in shaping Centrica’s wider security capability. If you love the idea of helping teams move fast without leaving security behind, this role gives you the chance to bring your expertise, curiosity and practical problem-solving to work that really matters.
Location: UK-based hybrid role, Occasional travel to site.
Day to day –
- Collaborate with DevOps and engineering teams to weave security best practice into the software development lifecycle, helping teams deliver at pace without compromising on protection.
- Provide practical guidance on secure design, implementation and architecture, including API security, microservices patterns and cloud-native application security.
- Carry out ongoing manual security assessments, coordinate third-party engagements where needed, and turn findings into clear, prioritised actions.
- Review SAST, DAST and SCA outputs, driving remediation through to closure and keeping tracking, ownership and prioritisation firmly on course.
- Provide on-demand application security support while driving continuous improvement across processes, tooling and ways of working, making security simpler, smarter and more scalable.
- Lead or contribute to the Security Champions programme and work closely with GSOC and CSIRT teams on application-layer security incidents, helping build a strong, distributed security culture across engineering.
What you would bring –
- Strong hands-on experience in application security, with a solid understanding of secure software development, OWASP Top 10, common application vulnerabilities and secure SDLC practices.
- Proficiency in one or more programming languages, such as Python or JavaScript, with experience using code to support security automation, tooling, custom rule development or other clever ways to make security scale.
- Experience working across cloud platforms such as AWS, Azure or SAP, alongside a good understanding of modern application architectures, container security, API security, network protocols and identity frameworks such as OAuth 2.0, OIDC and SAML.
- A strong working knowledge of DevOps pipelines, repositories and CI/CD security integration, including platforms such as Azure DevOps and GitHub Actions, with the confidence to bring security into delivery without slowing everyone down.
- Practical experience with security tooling and practices including SAST, DAST, SCA, container scanning, vulnerability management, SBOM tooling such as CycloneDX, IaC security across Terraform, Bicep, Ansible and tools such as Trivy, plus Policy as Code and threat modelling.
- A proactive, curious and collaborative approach, with the ability to guide engineering teams, support third-party supply chain security and make complex topics feel practical; desirable extras include certifications such as GWAPT, GWEB, OSCP or AWS Security Specialty, Security Champions or developer training experience, and exposure to SOC or Incident Response environments.
What's in it for you?
- Enjoy a generous market salary, along with fantastic growth opportunities and a vibrant work environment!
- Power up your pay with a 15% Employee Energy Allowance, surpassing the government's price cap!
- Secure your future with our comprehensive pension plan, designed for peace of mind.
- Elevate your health with our fully-funded company healthcare plan, prioritizing your well-being.
- Recharge with a generous 25-day holiday allowance, plus public holidays, and even purchase up to 5 extra days for extended relaxation!
- Experience unparalleled work-life balance with an exceptional selection of flexible benefits, from tech treats and eco-friendly car leases to travel insurance for your adventures!
Why should you apply?
We’re not a perfect place – but we’re a people place. Our priority is supporting all of the different realities our people face. Life is about so much more than work. We get it. That’s why we’ve designed our total rewards to give you the flexibility to choose what you need, when you need it, making sure that you and your family are supported not only financially, but physically and emotionally too. Visit the link below to discover why we’re a great place to work and what being part of more means for you.
https://www.morethanacareer.energy/centrica
If you're full of energy, fired up about sustainability, and ready to craft not only a better tomorrow, but a better you, then come and find your purpose in a team where your voice matters, your growth is non-negotiable, and your ambitions are our priority.
Help us, help you. We would love for you to share any information about yourself throughout our recruitment process so that we can better understand you and help shape your journey.
Other jobs you might like
Senior Application Security Engineer
£60,000 – £75,000 per annum
Cambridge, UK
Working at Centrica

Hybrid

A little flex time

