Now hiring

Senior Application Security Engineer @ Cloudsmith

Donegall Square West 7, BelfastOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

Salary: £41,000 - 41,000 per year

Requirements: Around 5+ years of hands-on application security experience, or equivalent experience across software engineering and security, with security as our recent focus.Deep software engineering craft, with a focus on Python; familiarity with TypeScript, Go, or Rust is an advantage.Deep web and API security knowledge, including OWASP Top 10, business logic flaws, authentication and authorization design, token handling, REST, GraphQL, and multi-tenant access control.Practical threat modeling and vulnerability research experience against real applications, APIs, cloud-native systems, and distributed services.Strong cloud-native security experience across AWS, IAM, KMS, S3, containers, Terraform, CI/CD, secrets handling, logging, and multi-tenant isolation.Sound judgment on vulnerability priority, with attention to exploitability, reachability, tenant impact, and production reality.Ability to reason through production systems, including APIs, queues, caches, databases, workers, CDNs, object storage, edge delivery, telemetry, and failure modes.Clear communication in a remote-first environment, with threat models, risk write-ups, incident notes, and feedback that are useful to engineers and credible to leadership.You should understand, or be excited to go deep on, software supply chain ecosystems such as npm, PyPI, Docker/OCI, Maven, Helm, and Hugging Face.You should understand, or be excited to go deep on, software supply chain threats such as dependency confusion, typosquatting, malicious packages, maintainer compromise, metadata poisoning, and build-system injection.You should understand, or be excited to go deep on, artifact and registry concepts such as immutable blobs, mutable metadata, package identity, checksums, upstream proxying, private repos, access control, caching, and promotion.You should understand, or be excited to go deep on, provenance and trust mechanisms such as SBOMs, signing, attestations, SLSA, Sigstore, in-toto, trusted publishing, and zero-trust software delivery.Experience securing artifact management, package registry, container registry, CI/CD, DevOps, developer tooling, or supply chain security platforms is a bonus.Experience with secure runtime environments, sandboxing, workload isolation, policy engines, OPA/Rego, eBPF, or similar control points is a bonus.Contributions to open-source security tooling or supply chain security projects are a bonus.Familiarity with Datadog, AWS Security Hub, Okta, GitHub Advanced Security, Snyk, Semgrep, Trivy, Wiz, or similar tooling is a bonus.Useful, but not required: certifications such as OSCP, CSSLP, GPEN, GWAPT, GCSA, or CISSP. Responsibilities: Embed inside an engineering tribe and participate in planning, design review, code review, incident learning, and delivery conversations.Collaborate across security, platform, and engineering guilds so security work routes to the right team, at the right time, with the right priority.Threat-model product and platform changes across APIs, workers, data stores, queues, object storage, CDNs, identity, policy, and tenant boundaries.Review production code and architecture for authentication, authorization, data access, secrets handling, artifact integrity, signing, auditability, and abuse cases.Build and improve security tooling, paved roads, checks, libraries, and automation that make securing our platform easier for engineers.Tune and operate security controls across SAST, DAST, SCA, secrets scanning, container scanning, IaC scanning, dependency analysis, and runtime signals.Investigate, triage, and remediate vulnerabilities identified through internal testing, third-party testing, responsible disclosure, customer reports, and security tooling.Support security incidents, red/blue exercises, detection work, and post-incident actions, improvements, and other investigatory or preventative follow-ups.Support technical control work for SOC 2, ISO 27001, EU CRA, and related frameworks, working with GRC where security engineering input is needed.Raise the tribes security capability by helping engineers understand risks, threat-model their own work, and recognize what good secure design looks like. Technologies: AIAPIAWSCI/CDCloudDatadogDevOpsDockerGitHubGraphQLHelmIAMSupportMavenNPMOWASPPythonRESTRustSecurityTerraformTypeScriptWebSlack More:

We are Cloudsmith, building the operating system for the modern software supply chain. We run a global, fully managed, multi-tenant SaaS platform that helps organizations from startups to the Fortune 500 secure, govern, and distribute software artifacts at scale. Our customers rely on us as a critical infrastructure control plane for CI/CD, developer workflows, security controls, compliance, and software distribution across 30+ formats and ecosystems. We recently raised our Series C to accelerate Cloudsmith 2.0, with deeper artifact intelligence, stronger policy and provenance, faster package-aware delivery, and infrastructure built for engineering teams and the modern AI-driven software factory. This Senior Application Security Engineer role reports to our Head of Security and embeds directly into one of our engineering tribes, working closely with Engineering Managers, Product Managers, Principal Engineers, and product engineers. We are headquartered in Belfast, Northern Ireland, with fully equipped office space for working sessions, planning, meetups, and team activities. We offer a competitive compensation package including equity, comprehensive health, dental, and vision insurance, generous annual leave, flexible working policies, professional development support, and a dynamic, innovative, trust-centric, and supportive work environment. The role is based in Ireland or the United Kingdom, with regular travel possibly required for team meetings, planning, customers, and events.

last updated 36 week of 2026

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores