Application Security Engineer - Manager
Oaknorth.ai
Posted: March 18, 2026
Interested in this position?
Create a free account to apply with AI-powered matching
Quick Summary
An experienced application security engineer is needed to conduct security assessments and contribute towards threat modelling and secure design reviews in web applications, APIs, mobile applications and cloud hosted solutions.
Required Skills
Job Description
At OakNorth, we’re on a mission to empower the UK’s most ambitious businesses. Since 2015, we’ve lent over $21 billion across the UK and US, helped create more than 58,000 new homes and 36,000 new jobs, and supported hundreds of thousands of personal savers — all while fuelling the UK economy.
Team Mission 🚀
Role Overview:
We are seeking an experienced application security engineer to conduct security assessments across web applications, APIs, mobile applications and cloud hosted solutions; and contribute towards threat modelling and secure design reviews. This role is primarily hands-on offensive security focused on identifying real world vulnerabilities that could impact business. Additionally, the role will support threat modelling and secure architecture reviews to help identify potential weaknesses during system design and development.
The successful candidate will demonstrate strong adversarial thinking, deep technical expertise, and the ability to clearly articulate security risks and practical remediation guidance to both technical and non-technical stakeholders.
Job Responsibilities: :
• Conduct penetration testing of web applications, APIs, and mobile applications (iOS/Android).
• Conduct threat modelling, and secure design reviews to identify potential security risks and vulnerabilities across applications, platforms, and products.
• Partner with product and engineering teams to embed secure-by-design principles into product development, including AI systems.
• Drive the reduction of critical and high-risk vulnerabilities through root cause analysis and actionable remediation guidance.
• Work closely with engineering teams to ensure application security principles are understood and security issues are resolved without impacting delivery timelines.
• Deliver security training and awareness sessions for developers and key stakeholders to uplift secure development practices.
Desired Skills: :
• 4-5 years of experience in security assessments and penetration testing of web applications, APIs, and mobile platforms.
• Proven experience in threat modelling and secure design reviews for applications.
• Ability to review and interpret code (e.g., React, Python, JavaScript) to identify security risks and weaknesses.
• Strong understanding of common application security vulnerabilities, including OWASP Top 10 and SANS Top 25.
• Knowledge of AWS security services (e.g., IAM, KMS, Security Hub, GuardDuty, network security controls).
• Exposure to AI security, including associated risks, threat models, and governance considerations.
• Excellent written and verbal communication skills, with the ability to clearly articulate risk and influence technical and non-technical stakeholders.
• Ability to work independently while collaborating effectively across multiple teams.