- Company Name
- RealVNC
- Job Title
- Applications Security Engineer
- Job Description
-
**Job Title**
Applications Security Engineer
**Role Summary**
Assume a core role in the Cyber Security team to embed security throughout the Software Development Lifecycle (SDLC) for VNC Connect and related products. Conduct threat modelling, secure design reviews, code reviews, and dynamic/ static application security testing (DAST, IAST, SAST, SCA). Work cross‑functionally with development, QA, DevOps, and incident response to remediate vulnerabilities and promote a robust security posture.
**Expectations**
- Deliver secure coding guidance and training to developers and non‑technical stakeholders.
- Execute automated and manual security testing of desktop, web, and mobile applications.
- Advise on secure deployment configurations and hardening in production.
- Keep up to date with vulnerability feeds, industry frameworks (CIS, NIST, SOC2, GDPR, ISO‑27001) and emerging security tools.
- Produce clear vulnerability reports, recommendations, and playbooks.
**Key Responsibilities**
- Conduct threat modelling and risk assessments during design phases; provide security requirements for new features.
- Perform secure code reviews; guide developers on CIS Controls, OWASP Top 10, and secure coding of Java, Python, or C++.
- Execute DAST (XSS, SQL Injection, Broken Access Control), IAST (Burp Suite, OWASP ZAP, Frida), SAST, and Software Composition Analysis (Blackduck, Mend, Snyk).
- Test desktop, web, and mobile applications for security gaps.
- Collaborate with DevOps to recommend secure configurations and hardening.
- Support incident response and remediate application‑level vulnerabilities.
- Deliver security training and promote security awareness across the organization.
- Maintain knowledge of vulnerability announcements, risk assessments, and security frameworks.
**Required Skills**
- Hands‑on experience with DAST, IAST, penetration testing tools (Burp Suite, OWASP ZAP, Frida).
- Proficiency with SAST and SCA tools (e.g., Blackduck, Mend/WhiteSource, Snyk).
- Deep understanding of SDLC security, DevSecOps, OWASP Top 10, and common application vulnerabilities (XSS, SQL injection, broken access).
- Secure coding experience in Java, Python, or C++ (or equivalent).
- Ability to explain complex security concepts to non‑technical stakeholders and produce clear reports.
- Familiarity with Windows, Linux, macOS, Android, and iOS environments.
- Strong cross‑functional collaboration skills with developers, QA, DevOps, system administrators, and compliance teams.
**Preferred Additional Knowledge**
- Buffer overflow exploitation, shellcode writing, or patch analysis.
- Cybersecurity frameworks (CIS Controls v8, NIST CSF).
- Regulatory compliance (GDPR, ISO‑27001, SOC2).
- Encryption best practices.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Cyber Security, or related field (or equivalent practical experience).
- Security certifications such as CISSP, CEH, OSCP, or equivalent (preferred).
Cambridge, United kingdom
Hybrid
Senior
04-03-2026