dunnhumby
Tech / AI / Software
Engineer(ApplicationSecurity)
Neural analysis suggests this role is
optimal for Mid+ candidates.
“Engineer (Application Security) at dunnhumby. Skills: Application Security, SDLC, CI/CD pipelines, Git workflows, modern software engineering practices, Cloud Security, Kubernetes Security, Vulnerability Management. drive application vulnerability management. embed security into development pipelines”
Industry & Context.
engineering mindset; understands how products are developed end‑to‑end; propose fixes; identifying and communicating risk clearly
What They're Looking For.
Must Have
deeply familiar with the SDLC, deeply familiar with CI/CD pipelines, deeply familiar with Git workflows, deeply familiar with modern software engineering practices
Nice to Have
security background, product background
What You'll Do.
drive application vulnerability management
embed security into development pipelines
guide engineering teams in building secure-by-design applications
Integrate security best practices into the SDLC
and maintain AppSec tooling
Provide secure design guidance
perform secure code reviews
validate remediations with developers
Embed security checks in CI/CD for container images
contribute to runtime protections such as admission controls
Promote secure infrastructure configurations and Kubernetes defaults
Ensure CI/CD pipelines have robust
effective security coverage
manage exceptions & risk workflows
Maintain a consolidated vulnerability backlog with clear ownership and SLA tracking
build automated reporting using tools like Power BI or Excel/Pandas
Develop secure coding standards and practical developer guidance
Run secure development forums
build and maintain relationship with engineering teams
drive application vulnerability management through engagements and reporting
Act as a trusted advisor to both engineers and leadership
identifying and communicating risk clearly and persuasively
How You'll Work.
Team & Collaboration
cross‑team collaboration; guide engineering teams; build and maintain relationship with engineering teams; Act as a trusted advisor to both engineers and leadership
Communication Scope
communication skills; ability to build trusted relationships; communicating risk clearly and persuasively
Process & Methodology
manage exceptions & risk workflows, Maintain a consolidated vulnerability backlog with clear ownership and SLA tracking
Full Job Description
dunnhumby is the global leader in Customer Data Science, partnering with the world’s most ambitious retailers and brands to put the customer at the heart of every decision. We combine deep insight, advanced technology, and close collaboration to help our clients grow, innovate, and deliver measurable value for their customers. dunnhumby employs nearly 2,500 experts in offices throughout Europe, Asia, Africa, and the Americas working for transformative, iconic brands such as Tesco, Coca-Cola, Nestlé, Unilever and Metro. Overview We are looking for an Application Security Engineer with a strong engineering mindset—someone who has built and maintained technical systems and understands how products are developed end‑to‑end. The ideal candidate may come from a security or product background, but must be deeply familiar with the SDLC, CI/CD pipelines, Git workflows, and modern software engineering practices. This role combines hands‑on security engineering with enablement, governance, and cross‑team collaboration. The Security Engineer will drive application vulnerability management, embed security into development pipelines, and guide engineering teams in building secure-by-design applications. Strong communication skills and the ability to build trusted relationships across both technical and non‑technical stakeholders is essential. Key Responsibilities Application Security Integrate security best practices into the SDLC and operate, tune, and maintain AppSec tooling (SAST, DAST, SCA). Provide secure design guidance, perform secure code reviews, reproduce issues, propose fixes, and validate remediations with developers. Cloud & Kubernetes Security Embed security checks in CI/CD for container images, IaC, and Helm charts & contribute to runtime protections such as admission controls, policy-as-code, scanning, and drift detection. Promote secure infrastructure configurations and Kubernetes defaults (RBAC, network policies, PodSecurity, secrets handling, image provenance).
Applying for this Engineer (Application Security) role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Greenhouse
- Create a Greenhouse profile before applying — it saves time across multiple applications.
- Upload your resume as a PDF; the parser handles it better than Word.
- Answer all knockout questions carefully — wrong answers auto-reject before a human sees you.
- Enable email notifications to track application status in real time.
ANONYMOUS · UNFILTERED
What do employees actually say about dunnhumby?
Real rants from real employees. Read before you apply.