Keyloop bridges the gap between dealers, manufacturers, technology suppliers and car buyers.
We empower car dealers and manufacturers to fully embrace digital transformation. How? By creating innovative technology that makes selling cars better for our customers, and buying and owning cars better for theirs.
Β
We use cutting-edge technology to link our clientsβ systems, departments and sites. We provide an open technology platform thatβs shaping the industry for the future. We use data to help clients become more efficient, increase profitability and give more customers an amazing experience.Β Want to be part of it?
Β
Role Summary
The Application Security Engineer is responsible for embedding security into Keyloopβs application development lifecycle to ensure that products and services are designed, built, and operated securely. This role partners closely with engineering and product teams to identify, prioritise, and mitigate application-level risks while enabling secure, scalable delivery.
The role requires strong hands-on application security expertise, a deep understanding of modern software development practices, and the ability to influence engineering teams through collaboration and pragmatism rather than control.
Key Responsibilities:
β’ Secure SDLC & Engineering Enablement
β’ Define, implement, and continuously improve secure software development lifecycle (SSDLC) practices aligned with Keyloopβs delivery model.
β’ Embed security requirements into application design, development, testing, and deployment activities.
β’ Work closely with engineering teams to address security early in the development lifecycle.
β’ Provide hands-on guidance and coaching to developers on secure coding practices and design patterns.
β’ Application Security Testing & Tooling
β’ Design, operate, and improve application security testing capabilities, including:
β’ Static Application Security Testing (SAST)
β’ Dynamic Application Security Testing (DAST)
β’ Software Composition Analysis (SCA)
β’ Interactive Application Security Testing (IAST), where applicable
β’ Integrate security testing tools into CI/CD pipelines and developer workflows.
β’ Triage, validate, and prioritise findings to reduce false positives and focus on material risk.
β’ Ensure findings are risk-ranked, actionable, and aligned to business impact.
β’ Vulnerability Management (Application-Focused)
β’ Own the application vulnerability management lifecycle from discovery through remediation and verification.
β’ Define remediation SLAs in collaboration with engineering teams based on severity, exploitability, and business context.
β’ Track remediation progress and provide clear reporting on application security risk and trends.
β’ Secure Architecture, Design & API Security
β’ Conduct application architecture and design reviews for new and existing services.
β’ Provide guidance on authentication, authorisation, session management, cryptography, and secure data handling.
β’ Assess and improve API security, including authentication, authorisation, rate limiting, and abuse prevention.
β’ Support secure adoption of cloud-native, microservices, and event-driven architectures.
β’ Threat Modelling & Risk Assessment
β’ Facilitate threat modelling exercises to identify abuse cases, attack paths, and design weaknesses.
β’ Apply attacker-centric thinking using frameworks such as OWASP and MITRE ATT&CK.
β’ Ensure identified risks are documented, prioritised, and addressed appropriately.
β’ Incident Support & Assurance
β’ Provide application security expertise during security incidents and investigations.
β’ Support root cause analysis and remediation for application-related vulnerabilities or breaches.
β’ Contribute to post-incident reviews and preventative control improvements.
β’ Standards, Assurance & Continuous Improvement
β’ Define and maintain application security standards, secure coding guidelines, and reusable security patterns.
β’ Support compliance and assurance activities related to application security, including NIST, ISO/IEC 27001, and SOC 2 requirements.
β’ Stay current with emerging application security threats, vulnerabilities, and best practices.
β’ Continuously improve tooling, processes, and developer enablement based on lessons learned.
Essential skillsets
β’ 5+ years of experience in application security, secure software development, or related engineering roles.
β’ Strong understanding of modern application architectures, including web applications, APIs, and microservices.
β’ Hands-on experience with application security testing tools (SAST, DAST, SCA, etc.).
β’ Experience integrating security tooling into CI/CD pipelines.
β’ Solid understanding of common vulnerabilities (e.g., OWASP Top 10) and secure coding practices.
β’ Experience working in Agile and DevOps environments.
Why join us?
Weβre on a journey to become market leaders in our space β and with that comes some incredible opportunities. Collaborate and learn from industry experts from all over the globe. Work with game-changing products and services. Get the training and support you need to try new things, adapt to quick changes and explore different paths. Join Keyloop and progress your career, your way.
Β
An inclusive environment to thrive
Weβre committed to fostering an inclusive work environment. One that respects all dimensions of diversity.Β We promote an inclusive culture within our business, and we celebrate different employees and lifestyles β not just on key days, but every day.
Β
Be rewarded for your efforts
We believe people should be paid based on their performance so our pay and benefits reflect this and are designed to attract the very best talent. We encourage everyone in our organisation to explore opportunities which enable them to grow their career through investment in their development but equally by working in a culture which fosters support and unbridled collaboration.
Keyloop doesnβt require academic qualifications for this position. We select based on experience and potential, not credentials.
We are also an equal opportunity employer committed to building a diverse and inclusive workforce.Β We value diversity and encourage candidates of all backgrounds to apply.