The Opportunity ✨
As the Loyalty division evolves into a Platform as a Service business, we're looking for a talented and passionate Senior Application Security Engineer to join our security engineering team. You'll have a background in software engineering, a deep interest in application and API security, and a passion for helping organisations safely adopt emerging technologies, including AI and Agentic AI.
You thrive on collaboration, enjoy helping others grow, and see security as an enabler — not a blocker. You'll be an AppSec advocate who supports our engineers in identifying and addressing security risks across the software development lifecycle, while helping shape how security supports our growing use of AI-powered capabilities, intelligent automation and next-generation digital experiences.
As we continue to invest in AI and Agentic AI capabilities to power more intelligent customer experiences, autonomous and semi-autonomous workflows, and new opportunities for commercial growth, security plays a critical role in ensuring these technologies are adopted responsibly, securely and at scale. This is a unique opportunity to help define and embed secure-by-design principles for the next generation of products, platforms and AI-powered services across IAG Loyalty.
What you'll be doing
As a Senior Application Security Engineer, you'll lead the application security practice within the Loyalty division security team, taking responsibility for key security KPIs in this area.
You'll champion secure software development by working closely with engineers, architects and product teams, embedding security practices into our engineering culture. You'll provide training, offer expert advice, and drive awareness of security from the earliest stages of design through to deployment.
You'll help integrate automated security tooling and checks into our CI/CD pipelines, facilitate threat modelling sessions, and review security-sensitive design decisions around authentication, cryptography, API security, data protection and logging. You'll also ensure that tools such as SAST, DAST and SCA are effective and efficient, and that testing programmes — including penetration testing, vulnerability scanning and bug bounty initiatives — are delivering value.
As our adoption of AI accelerates, you'll partner with engineering and platform teams to identify and address emerging security risks associated with AI-powered products, large language models and Agentic AI architectures. You'll help establish security guardrails, patterns and best practices that enable teams to innovate confidently while maintaining appropriate controls around data, access, model usage, agent orchestration and third-party integrations.
You'll play a key role in helping the business safely leverage AI to automate and optimise complex workflows, enhance customer experiences and unlock new growth opportunities, ensuring security is embedded from experimentation through to production scale.
You'll triage vulnerabilities, support engineering teams with practical mitigations, contribute to documentation that strengthens our internal standards and processes, and help shape the future of secure AI adoption across the organisation. Maintaining a strong security culture will be a key focus, and you'll also support internal and external audits where needed.
What we need from you
Experience in software engineering, with a strong security mindset.
Deep understanding of web, application and API vulnerabilities, including the OWASP Top 10.
Proficient in coding, scripting (e.g. Python, Bash) and automating security controls within CI/CD pipelines.
Hands-on experience with security tools such as SAST, DAST and SCA.
Familiar with cloud-native environments (especially AWS), containers, Kubernetes and microservices architectures.
Comfortable reviewing technical designs, performing threat modelling and advising on secure architecture patterns.
Strong understanding of emerging AI security considerations, including large language models, AI-enabled applications and Agentic AI architectures, with a passion for helping shape and secure our adoption journey in this space.
Strong communicator who collaborates effectively with engineers and promotes secure-by-default and secure-by-design practices.