IAG Loyalty

Senior Application Security Engineer

IAG Loyalty  •  London, GB (Hybrid)  •  2 days ago
Apply
AI can make mistakes so check important info. Chat history is never stored.
70
AI Success™

Job Description

Who we are 🌍

We’re IAG Loyalty - one organisation with two ambitious, growing divisions across Loyalty and Holidays. Each has its own goals, strategy and team, but together we’re united by a shared vision to create a more rewarding world of travel and experiences.

Our Loyalty division is home to Avios, the global loyalty currency, enabling millions of members to collect and spend rewards across travel, retail and financial services.

Our Holidays division including British Airways Holidays and Iberia Vacaciones,brings together trusted brands, connecting customers to thousands of destinations worldwide through seamless, end-to-end travel experiences.

We’re on an exciting journey of growth and transformation – we’re going places.

The Opportunity

As the Loyalty division evolves into a Platform as a Service business, we’re looking for a talented and passionate Senior Application Security Engineer to join our security engineering team. You’ll have a background in software engineering and a deep interest in application and API security. You thrive on collaboration, enjoy helping others grow, and see security as an enabler — not a blocker. You’ll be an AppSec advocate who supports our engineers in identifying and addressing security issues across the software development lifecycle.

You’ll be part of a small, dynamic team within the Product department that drives the Loyalty divisions digital transformation, technology strategy, and product direction. Our cloud-native platform powers the Avios currency and the digital experiences used by millions of loyalty members. This is a great opportunity to work with cutting-edge technology in a fast-paced, agile environment.

What you’llbe doing🚀

As a Senior Application Security Engineer, you’ll lead the application security practice within the Loyalty division security team, taking responsibility for key security KPIs in this area. You’ll champion secure software development by working closely with engineers and product teams, embedding security practices into our engineering culture. You’ll provide training, offer expert advice, and drive awareness of security from the earliest stages of design through to deployment.

You’ll help integrate automated security tooling and checks into our CI/CD pipelines, facilitate threat modelling sessions, and review security-sensitive design decisions around authentication, cryptography, and logging. You’ll also ensure that tools such as SAST, DAST, and SCA are effective and efficient, and that testing programmes — including pen testing, vulnerability scanning, and bug bounty — are delivering value.

You’ll triage vulnerabilities, support engineering teams with practical mitigations, and contribute to documentation that strengthens our internal standards and processes. Maintaining a strong security culture will be a key focus, and you’ll also support internal and external audits where needed.

What we need from you

  • Experience in software engineering, with a strong security mindset

  • Deep understanding of web and API vulnerabilities, including the OWASP Top 10

  • Proficient in coding, scripting (e.g. Python, Bash), and automating security in CI/CD

  • Hands-on experience with security tools like SAST, DAST, and SCA

  • Familiar with cloud environments (especially AWS), containers, and microservices

  • Comfortable reviewing technical designs, performing threat modelling, and advising on secure architecture

  • Strong communicator who collaborates well with engineers and promotes secure-by-default practices

We might not be right for you if:

  • You only want to focus on your to-do list; we’re a small, high-performing team, we help each other to succeed.

  • You value perfection over fast iteration and progress; IAG Loyalty moves fast, we learn and iterate as we go; our environment isn’t right for everyone.

  • You’re looking to create but not build; this is an end-to-end role, you need to be comfortable owning your space, from ideation through to delivery and review

If you think you have what it takes but don't meet every single point above, please do still apply. We'd love to chat and see if you could be a great fit.

The Blend 📍

This role will work as part of our Loyalty Division and is based out of our London office. We call our approach to hybrid working The Blendit’s about giving you the flexibility to choose where you do your best work, while staying connected with your team and the wider business. This means you will be required to spend at least two days per week in the office, with the rest of the time working from home. You may also be required to work from one of our other office or partner locations, based on your role and 'to do' list.

Diversity and Inclusion

Our vision is to create a more rewarding world of travel and experiences. Delivering that requires diverse thinking and inclusive leadership.

We are committed to building a workplace where people feel they belong and are valued for their perspective. Inclusion drives better decisions, stronger performance and more innovative outcomes.

We actively encourage applications from people with different experiences and backgrounds, and are committed to ensuring our recruitment process is fair, inclusive and accessible.

IAG Loyalty

About IAG Loyalty

IAG Loyalty is part of International Airlines Group (IAG). We were founded as Airmiles in 1988 and became Avios in 2011, now we’re IAGL and we have over 30 years’ experience in loyalty.

We manage the British Airways Executive Club, Iberia Plus, Vueling Club, and the Aer Lingus AerClub, and we have an impressive range of retail, travel and financial services partners of the Avios currency.

We’re loyalty pioneers creating the world’s most rewarding experiences.

That’s our vision. We help people to enjoy incredible experiences by collecting and redeeming the iconic Avios currency. We design customer loyalty programmes, build loyalty management tools, provide loyalty tech solutions, and produce invaluable data and customer insights to turn customer loyalty into a powerful tool for maximising a brand power and scale.

We’re a vision and values led business. Our vision sets our ambition, and our values represent how we’re going to get there. Together, this perfect partnership unites our people into a club of colleagues that know why and how we do things here. Our values are owned by everyone in the club, and are uniquely ours:

• We bring passion to our work

• We have the courage to reimagine

• We focus on agility

• We excel in delivery

• We keep learning and stay curious

• We take belonging seriously

Our colleagues bring our vision and values to life every day in all they do. For our business, for our customers and for each other.

Industry
IT & Software
Company Size
501-1,000 employees
Headquarters
London, GB
Year Founded
1988
Social Media