[Hiring] Application Security Lead @Prolific
Application Security Lead @Prolific
Software Development
Salary unspecified
Remote Location
remote UK
Employment Type full-time
Posted 2d ago

[Hiring] Application Security Lead @Prolific

2d ago - Prolific is hiring a remote Application Security Lead. 💸 Salary: unspecified 📍Location: UK

Role Description

Security at Prolific isn't an afterthought, it's foundational to how we build. As a company trusted by world-leading research institutions and AI labs to handle sensitive data at scale, the security of our platform and the code that powers it is critical. We handle participant data, researcher credentials, payment flows, and API integrations, and we need someone to own how we protect all of it at the application layer.

As Application Security Lead, you'll own Prolific's application security strategy and be the most senior security engineering voice in the organisation. You'll define and drive our Secure Software Development Lifecycle (SSDLC), set the standard for how security is embedded into engineering, and get hands-on with code review, threat modelling, and security testing when it matters. You'll also manage our Senior Application Security Engineer and continue to own our compliance programme alongside these responsibilities.

This is a player-coach role. You won't just set strategy, you'll be in the code, leading by example, and building the security culture that scales with Prolific. You'll need deep engineering experience to earn the trust of our engineering teams, and deep application security experience to know where the real risks are.

You'll report to the Head of Engineering/Platform and work cross-functionally with product engineering, platform, data, TechOps, and legal teams. As we scale, there's a clear path for this role to grow into leading a broader security function.

Qualifications

  • Several years of experience in software engineering, you’ve built and shipped production systems at scale
  • Several years in application security (testing, code review, threat modelling, vuln management)
  • Expert knowledge of OWASP Top 10 (Web & API) and modern attack paths (e.g. auth flaws, SSRF, injection, business logic, supply chain)
  • Strong understanding of modern architectures (microservices, APIs, event-driven systems)
  • Python for security tooling and automation (Django a strong plus)
  • Hands-on testing experience (e.g. Burp Suite) and manual assessment of apps/APIs
  • Experience building and scaling SSDLCs, including CI/CD tooling (SAST, SCA, DAST, secrets)
  • Experience leading threat modelling and security design reviews
  • Strong engineering partnership skills, you influence through trust
  • Experience with ISO 27001 / SOC 2 and translating controls into real engineering practices
  • Clear communicator across technical and non-technical audiences

Requirements

  • Experience mentoring or managing security engineers
  • Experience with Django, Vue.js, MongoDB, GCP
  • Security champions or bug bounty programmes
  • Supply chain or infrastructure security (e.g. Terraform, Kubernetes)
  • Hands-on certifications (OSCP, GWAPT, BSCP, CISSP)
  • Experience building AppSec in a scaling company

What you’ll be doing in the role

You’ll own and evolve Prolific’s application security strategy end-to-end, from hands-on testing and threat modelling to scaling secure development practices across engineering. You’ll act as the go-to expert for application security, partnering with engineering leadership to balance risk and velocity, while building the tooling, processes, and culture needed to embed security into how we ship. This includes mentoring an AppSec engineer, leading high-impact security reviews, owning vulnerability management, and ensuring our platform stays ahead of modern threats.

Benefits

  • Competitive salary
  • Benefits
  • Remote working
  • Impactful, mission-driven culture
Before You Apply
remote Be aware of the location restriction for this remote position: UK
Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Application Security Lead @Prolific
Software Development
Salary unspecified
Remote Location
remote UK
Employment Type full-time
Posted 2d ago
Apply for this position
Did not apply
Applied
Sent Follow-Up
Interview Scheduled
Interview Completed
Offer Accepted
Offer Declined
Unlock 145,286 Remote Jobs
remote Be aware of the location restriction for this remote position: UK
Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply
Applied
Sent Follow-Up
Interview Scheduled
Interview Completed
Offer Accepted
Offer Declined
Unlock 145,286 Remote Jobs
×

Apply to the best remote jobs
before everyone else

Access 145,286+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews
Unlock All Jobs Now

Maybe later