Jobs / United Kingdom / Genomics
Application Security Engineer
Genomics · 🇬🇧 London
Sponsorship verdict
No sponsorship evidence yet
No government record and no wording either way. Not a refusal — ask the recruiter.
- No government sponsor record hereThis employer posted directly and does not match a government sponsor register.
- The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
- Can’t check pay against the visa rulesNo salary stated. UK Skilled Worker visa needs at least £41,700 a year (new-entrant (under 26, recent Student/Graduate visa) or STEM PhD: £33,400). Source: https://www.gov.uk/skilled-worker-visa/when-you-can-be-paid-less, rules effective 2025-07-22.
- Confirmed live todayWhen a source last listed this job as open.
A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.
Or apply yourself on the official page →
Why not apply?
No register record and no sponsorship wording in the posting. Worth asking the employer before investing significant time.
SponsorApply flags time-wasters so your applications go where they can land. These come from the posting's own wording — read the original listing to confirm. See better-fit alternatives →
Sponsor Radar — Genomics
This employer posted directly and does not match a government sponsor register.
Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for Genomics →
About the role
Location: Oxford or London (Hybrid) The Mission: Why We Exist Genomics is a science-led transatlantic TechBio combining large-scale genetic and health data with proprietary analytics to accelerate drug discovery and advance predictive, preventative healthcare. We are united by a single vision to help people live longer, healthier lives, using the power of genomics. Genomics aims to help people live longer, healthier lives in two ways: super-charging drug discovery and development for novel treatments with our AI-enabled advanced genetic analytics platform, and by helping people understand their personal risk of common chronic diseases through polygenic risk scores - giving doctors and health systems the chance to get the right people into the right prevention, screening and treatment programmes at the right time. Role Purpose Genomic data is some of the most sensitive data there is, and our customers trust us with it. As Senior Application Security Engineer on Mystra, you'll own application security end-to-end across multi-tenant, trillion-row-scale, AI-enabled data platforms. You'll lead threat modelling and design review with product teams, build the tooling and patterns that make secure codet, and find and fix the vulnerabilities that slip through. You'll do it with security-focused AI tooling, steered by your own expert judgement and intuition, to keep Genomics secure against state-of-the-art threats. A Day in the Life • Leading threat modelling and design reviews for new products and infrastructure, and defining the security invariants every team builds against: tenant isolation, authentication and authorisation, secrets, least privilege, and trust boundaries • Building the libraries, patterns, and CI/CD guardrails that make the secure way the easy way, and deciding what is enforced versus advised • Building and tuning AI tooling for code analysis, triage, and remediation, and deciding where its output can be trusted and where it must be verified • Hunting for vulnerabilities through code review, testing, and proof-of-concept exploits, then running the disclosure programme and driving every finding through to a verified fix • Securing our agentic and AI surfaces, from prompt injection and tool boundaries to delegated credentials and tenant-scoped access, and proving the controls hold under adversarial testing • Working as an embedded, trusted partner to product teams, SRE, detection and response, the data platform team, and the MystraAI / ML team, unblocking rather than gating Who You Are • Experience within application security in production. You've found and fixed exploitable bugs in software you were responsible for, through threat modelling, secure design, code review, and proof-of-concept exploitation across web services, APIs, and data-serving interfaces. Triaging scanner output doesn't count • Production-quality software engineering in at least one mainstream language (such as Python, Go, or TypeScript), and you can read several. You've built and operated security or developer tooling in CI/CD pipelines, such as static and dependency analysis, secrets detection, or policy-as-code, and engineers actually adopted it • Hands-on depth securing multi-tenant systems on a major cloud. We run on AWS (RDS, EC2, S3, EKS, Batch), and comparable GCP or Azure depth transfers. You know tenant isolation, IAM and least privilege, secrets management, Kubernetes and container security, and the trust boundaries between services • Daily use of frontier AI models for code analysis, vulnerability triage, remediation drafting, and research, with sharp judgement about where they're reliable and where they mislead. You've built or tuned LLM-driven tooling rather than only used a chat interface, and you understand the attack surfa