Skip to content

Nobody tells you why you were rejected. We will. Free, in 30 seconds.

Score my CV against live jobs

Application Security Engineer

Cytix · Manchester

On-siteMidGBP 45k–55k / yrPosted 27 Aug 2026

What this role requires

2 requirements, read out of the advert rather than guessed from the job title:

Also mentioned, not required: APIs, mobile applications, English. Worth having, but their absence is not what gets a CV filtered out.

See how often each of these is required across open security roles in Europe.

Check my CV against these 2 requirements

Free, no card. Tells you which of them your CV evidences and which it only implies.

Job description

We're looking for a Application Security Engineer to join our Manchester-based application security business as a member of the AppSec Engineering team (Open to people who can make it to our office twice a month or remote) Cytix is a platform that threat models development tickets and creates security testing plans that include both manual and automated testing.

In this role, you won't be confined to traditional 4+1 web applications. We're breaking away from the constraints of CHECK or CE+ standards, and we're not interested in producing lengthy PDF reports. Instead, our focus is on seamlessly integrating continuous penetration testing into our customers' Software Development Life Cycle (SDLC).

Collaborating closely with both our in-house development team and clients, you'll play a pivotal role in shaping the evolution of our products and services, helping to deliver the next generation of continuous penetration testing.

Having recently secured Series A funding this opportunity is genuinely one-of-a-kind for the right individual!

What you'll do

Operating as a Security Consultant specialising in Application Security (AppSec) Testing.

Read the full description (26 more sections)

Penetration Testing web applications, APIs, mobile applications, etc for our clients across a range of industries.

Working with stakeholders of both a technical and non-technical nature to assist in vulnerability identification and remediations.

Performing risk reviews of application changes as part of our continuous security testing process.

You will collaborate closely with developers and other teams to strengthen application security, drive continuous improvement, and enhance organisational resilience to cybersecurity threats

What you'll bring

2+ years in Penetration Testing, Application Security Engineering, or a similar offensive security role.

What you'll get

Unlimited Holidays!

Share options - If Cytix wins, you should too.

Enhanced maternity pay.

Pension - 8% (3% employer, 5% employee)

Private Healthcare (inc. dental, optical and hearing)

Octopus car scheme - Drive electric through salary sacrifice

Dog-friendly office .

Inclusivity as standard - A team where you can do your best work as yourself, no asterisks. About Cytix

Software never stops changing. Teams ship new code every day, through tickets, pull requests, releases, and increasingly with AI in the mix, but the way security keeps up with all that change hasn't really moved on. That's the problem we're solving. Cytix helps organisations understand which software changes actually matter, what should happen next, and how to prove the right call was made. Security understood, in other words.

We're a small team with big plans, so every person we hire genuinely shapes what Cytix becomes. That's why we're upfront about our five values: we interview for all of them, and they matter to us more than a perfect CV. They're things you do, not things you are, so have a read and see if they sound like you.

Make the first move. When the goal is clear but the path isn't, you get moving rather than waiting for perfect instructions. If you're blocked, you make a sensible call, say what you're assuming, and explain how you'd course-correct. We'd rather you act and be slightly wrong than sit still.

Find the smarter path. You ask why before how. You dig into what the real problem is instead of just building what the spec says, and you're happy to question 'that's how it's always been done' when the reason behind it has gone stale.

See it through. When something's yours, it lands. No loose ends, no surprises for whoever picks it up next. You keep people posted when things change, and if something falls between roles, you catch it.

Raise the bar. You do the best job possible in the time you've got, whether that's a day or a month. Sometimes that means deep craft; sometimes the smartest move is quick and scrappy. It's about good judgement, and we hold each other to it without blame or politics.

Play to win. You care about the mission but don't take yourself too seriously. You say 'I' when things go wrong and 'we' when they go right, trust teammates to do things their own way, and bring a bit of humour when the pressure's on.

Sound like you on a normal working day? We'd love to meet you.

Compensation: £45K – £55K • + Equity

• £45K – £55K • + Equity

Find Jobs in United Kingdom on Arbeitnow

You will apply. Then you will hear nothing.

And no one will tell you what was wrong. See it before you send: your ATS score, every weak line, and the fix for each.

  1. 1

    Drop in your CV

    One PDF, thirty seconds. No card.

  2. 2

    See what is wrong with it

    Every weak passage, quoted from your own CV, with the line to replace it.

  3. 3

    Apply where you fit

    Every European role ranked against what your CV actually says.

  • Free, no card
  • Your CV file is deleted after parsing
  • Or skip the upload — build your profile by hand
  • Refreshed every 6 hours