Cytix Logo

Cytix

Application Security Engineer

Posted 15 Days Ago
Be an Early Applicant
Hybrid
Manchester, Greater Manchester, England, GBR
Junior
Hybrid
Manchester, Greater Manchester, England, GBR
Junior
Perform penetration testing across web applications, APIs, and mobile applications for clients. Identify vulnerabilities, support remediation with technical and non-technical stakeholders, conduct risk reviews of application changes, and collaborate with developers to strengthen application security and continuous security testing processes.
The summary above was generated by AI

We're looking for a Application Security Engineer to join our Manchester-based application security business as a member of the AppSec Engineering team
Cytix is a platform that threat models development tickets and creates security testing plans that include both manual and automated testing.

In this role, you won't be confined to traditional 4+1 web applications. We're breaking away from the constraints of CHECK or CE+ standards, and we're not interested in producing lengthy PDF reports. Instead, our focus is on seamlessly integrating continuous penetration testing into our customers' Software Development Life Cycle (SDLC).

Collaborating closely with both our in-house development team and clients, you'll play in pivotal role in driving penetration testing.


Having recently secured Series A funding this opportunity is genuinely one-of-a-kind for the right individual!

 

What you'll do

Operating as a Security Consultant specialising in Application Security (AppSec) Testing.

 
  • Penetration Testing web applications, APIs, mobile applications, etc for our clients across a range of industries.

  • Working with stakeholders of both a technical and non-technical nature to assist in vulnerability identification and remediations.

  • Performing risk reviews of application changes as part of our continuous security testing process.

  • You are comfortable collaborating with developers and external customers.

What you'll bring

  • 2+ years in Penetration Testing, Application Security Engineering, or a similar offensive security role.

What you'll get

  • Unlimited Holidays!

  • Share options - If Cytix wins, you should too.

  • Enhanced maternity pay.

  • Pension - 8% (3% employer, 5% employee)

  • Private Healthcare (inc. dental, optical and hearing)

  • Octopus car scheme - Drive electric through salary sacrifice

  • Dog-friendly office.

Inclusivity as standard - A team where you can do your best work as yourself, no asterisks.

About Cytix

  • Software never stops changing. Teams ship new code every day, through tickets, pull requests, releases, and increasingly with AI in the mix, but the way security keeps up with all that change hasn't really moved on. That's the problem we're solving. Cytix helps organisations understand which software changes actually matter, what should happen next, and how to prove the right call was made. Security understood, in other words.

    We're a small team with big plans, so every person we hire genuinely shapes what Cytix becomes. That's why we're upfront about our five values: we interview for all of them, and they matter to us more than a perfect CV. They're things you do, not things you are, so have a read and see if they sound like you.

    Make the first move. When the goal is clear but the path isn't, you get moving rather than waiting for perfect instructions. If you're blocked, you make a sensible call, say what you're assuming, and explain how you'd course-correct. We'd rather you act and be slightly wrong than sit still.

    Find the smarter path. You ask why before how. You dig into what the real problem is instead of just building what the spec says, and you're happy to question 'that's how it's always been done' when the reason behind it has gone stale.

    See it through. When something's yours, it lands. No loose ends, no surprises for whoever picks it up next. You keep people posted when things change, and if something falls between roles, you catch it.

    Raise the bar. You do the best job possible in the time you've got, whether that's a day or a month. Sometimes that means deep craft; sometimes the smartest move is quick and scrappy. It's about good judgement, and we hold each other to it without blame or politics.

    Play to win. You care about the mission but don't take yourself too seriously. You say 'I' when things go wrong and 'we' when they go right, trust teammates to do things their own way, and bring a bit of humour when the pressure's on.

    Sound like you on a normal working day? We'd love to meet you.

Cytix Manchester, England Office

Manchester, United Kingdom, M2 5LN,

Similar Jobs

6 Days Ago
Easy Apply
Remote or Hybrid
UK
Easy Apply
Expert/Leader
Expert/Leader
Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Lead Samsara’s vulnerability management and application security programs across cloud, firmware, IoT, and corporate systems. Define technical strategy, automate vulnerability detection and response, reduce remediation time, guide engineering teams, mentor security engineers, investigate critical vulnerabilities, and support incident response. The role requires strong AWS, programming, vulnerability management, application security testing, AI/LLM, and security automation expertise.
Top Skills: Ai/LlmAWSAws LambdaCC++Ci/CdCvssDastEpssFedrampFirmwareGoIotJavaScriptPythonSastScaSemgrepTinesWiz
22 Days Ago
Hybrid
Senior level
Senior level
Fintech • Information Technology • Insurance • Software
The Application Security Engineer embeds security throughout the software development lifecycle by advising on secure coding, threat modeling, OWASP Top 10 mitigation, code reviews, penetration testing, and SAST, DAST, and IAST tooling. The role partners with engineering teams, improves DevSecOps practices, researches AI and LLM threats, supports incident investigations, delivers security training, and mentors developers.
Top Skills: AIAWSAzureDastDevsecopsGCPIastLlm Threat ModelingOwasp Top 10Penetration TestingSast
23 Days Ago
Hybrid
Senior level
Senior level
Fintech • Software • Financial Services
Lead application security for the platform by embedding automated controls into the SDLC, conducting security architecture and code reviews, driving threat modeling, triaging vulnerabilities, coordinating remediations, partnering with engineering/product teams, and scaling tooling and AI-assisted workflows to raise security across cloud-native and containerized environments.
Top Skills: AIAWSCi/CdContainer Security ScanningContainersDastDependency ScanningEksJavaJavaScriptKotlinPenetration TestingReactSastTypescriptVulnerability Scanning

What you need to know about the Manchester Tech Scene

Home to a £5 billion digital ecosystem, including MediaCity, which consists of major players like the BBC, ITV and Ericsson, Manchester is one of the U.K.'s top digital tech hubs, at the forefront of advancements in film, television and emerging sectors like as e-sports, while also fostering a community of professionals dedicated to pushing creative and technological boundaries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account