Job Introduction
Application Security Engineer
BPP Education is entering a new phase of its growth and evolution, attracting thousands more students each year and expanding into new verticals and new markets globally. The BPP Product & Technology (P&T) organisation is evolving rapidly, and driving transformation of its platforms, digital products and experiences, in order to help BPP Education scale and meet the growth of the business in the coming years.
We’re looking for a talented application security engineer to help us build secure applications, systems and infrastructure alongside our products that delight and engage learners during their time studying with BPP and beyond, throughout their working lives.
What if you read the description and don't meet every single requirement? We encourage you to apply anyway - we value diverse backgrounds and are committed to inclusivity!
Why work for BPP Education Group?
It is a great time to join BPP Education Group as we have enjoyed a sustained period of growth, offering a wealth of opportunities to our staff, students and clients. There are many more great reasons to join BPP Education Group such as:
- Brilliantly, you can study any of BPP’s courses for free – be it a professional qualification or full degree.
- With hybrid working available, you’ll be able to split your time between one of our centres and wherever you choose to call home.
- We also provide a generous annual leave entitlement of 30 days, and there’s a rewards package that includes retail discounts and much more.
Other key benefits include our Group Personal Pension Plan, dedicated private healthcare and dental plans that offer additional assurance to look after you and your family
What you’ll be doing
As the Application Security Engineer, you will report to the Head of Cyber Security, providing technical leadership and expertise to identify, assess and mitigate security vulnerabilities and threats. This role is key as we transform BPP Education to become more customer centred, design and data informed, to build products that meet and exceed our users’ needs across our education ecosystem.
As such, you will be responsible for:
Key responsibilities
- Secure Coding: Conduct code reviews, threat modeling, and mentor developers on security best practices.
- Identity & Access Management (IAM): Configure RBAC, MFA, and manage privileged access in alignment with compliance standards.
- Cloud Security: Support secure AWS configurations, enforce infrastructure-as-code policies, and assist in cloud architecture design.
- Vulnerability Management: Perform scans, coordinate remediation, and prioritize risks.
- Collaboration: Share findings, contribute to internal documentation, and run security workshops with cross-functional teams.
What we’re looking for
To be successful in this role you will need to have a proven track record in the following areas:
Essential Skills
- Proven experience as an application security engineer working in an agile environment.
- Good knowledge of application security concepts, secure coding practices and common vulnerabilities (e.g. OWASP Top 10).
- Strong understanding of threat modelling methodologies and practical experience in applying them to software systems.
- Hands on experience with security testing tools such as static / dynamic analysis and penetration testing tools.
- Proficient in development languages and frameworks such as Python, JavaScript, React, Node.
- Knowledge of security standards and frameworks (e.g. ISO27001).
- Excellent verbal and written communication skills.
Please note that the successful candidate will be required to undergo a basic DBS check.
BPP Education Group are proud to be a Disability Confident employer so if you need any reasonable adjustments for the interview process, please just let us know!
BPP Education Group actively promotes equality of opportunity for all with the right mix of talent, skills and potential, and welcomes applications from a wide range of candidates. BPP will select candidates for interview based on their skills, qualifications and experience. Please note that for those posts that are exempt from the Rehabilitation of Offenders Act 1974, the successful candidate will be required to undertake a DBS check in addition to BPP undertaking any necessary online searches. This is deemed appropriate and necessary from a safeguarding perspective, and in line with BPP’s safer recruitment practices
BPP Education Group reserves the right to amend or withdraw this advertisement at any time prior to the closing date, should we receive a high volume of applications or if business needs change.