The Pokémon Company International Logo

The Pokémon Company International

Application Security Engineer

Posted 6 Days Ago
Be an Early Applicant
In-Office
London, Greater London, England, GBR
Senior level
In-Office
London, Greater London, England, GBR
Senior level
Design, implement, and operate application and cloud security controls; perform penetration tests and vulnerability assessments; lead threat modeling and security design reviews; respond to and investigate incidents; integrate security into the SDLC; reduce cloud risks (primarily AWS); collaborate with partners and report business impact to leadership.
The summary above was generated by AI

Get to know The Pokémon Company International

The Pokémon Company International manages the Pokémon property outside of Asia and is responsible for brand management, licensing and marketing, the Pokémon Trading Card Game, the animated TV series, home entertainment, and the official Pokémon website. Pokémon was launched in Japan in 1996 and today is one of the most popular children’s entertainment properties in the world. 

Learn more online at corporate.pokemon.com and pokemon.com.

Get to know the role

  • Job Title: Application Security Engineer
  • Job Summary: Designs, implements, and operates security controls to prevent and detect attacks against company systems, applications, and data. Conducts penetration testing and vulnerability assessments across applications, operating systems, and networks. Responds to cybersecurity incidents by identifying, isolating, and removing unauthorized access. Researches emerging threats, performs root cause analysis, and supports the development of security solutions. Communicates business impact related to data loss, system disruption, or unauthorized access. 
  • People Manager: No

What you’ll do

  • Administer and enforce security policies governing system and application access.
  • Perform application security testing and reviews to ensure secure configurations and compliance with standards.
  • Conduct penetration tests and vulnerability assessments across applications, OS, and network layers.
  • Lead threat modeling and security design reviews for new technologies and system changes.
  • Respond to security incidents, isolating threats and removing unauthorized access.
  • Research emerging cybersecurity threats and conduct root cause analysis on issues.
  • Implement technical controls to reduce cloud-based risks, including drift, private-cloud gaps, and web-facing vulnerabilities.
  • Collaborate with Information Security partners to advance roadmaps and shared initiatives.
  • Integrate security testing and controls into development lifecycle phases.
  • Provide management with insights on business impact related to data compromise or system unavailability.
  • Work within an agile framework to deliver iterative improvements toward team and organizational goals.
  • Respond and investigate cybersecurity incidents, which may be off-hours and on a scheduled rotation.               

What you’ll bring

  • 5–7 years of relevant experience securing cloud environments, primarily AWS, or equivalent expertise.
  • Bachelor’s degree in a related field or equivalent practical experience.
  • Strong time management, organizational skills, and attention to detail.
  • Solid background in application security engineering and architecture, including MWAF and software development.
  • Demonstrated ability to build partnerships and collaborate with cross‑functional teams.
  • Strong communication skills, with the ability to clearly present security risks to senior leadership.
  • Experience managing security vendors and managed service providers.
  • Proven background in incident management and response.
  • Security certifications (CISSP, GIAC, CISA, etc.) are a plus.

Base Salary Range: For this role, new hires generally start between £59,829.00 - £79,604.00 per year. The full range is £59,829.00 - £107,759.00 per year. This range is applicable for the labor market where the role is intended to be hired. The final base salary is directly related to the candidate’s qualifications and professional experience uniquely.

#LI-PS  #LI-Hybrid

How you’ll be successful

  • Passion for Pokémon: Develops an understanding of the Pokémon brand, the impact it has on our people, culture, business, fans, and communities, and applying that knowledge and passion to everything you do.
  • Challenging the Expected: Approaches challenges with curiosity and creativity, embracing the possibility of failure as an opportunity to learn something new, develop innovative ideas, solve complex problems and identify unique opportunities.  
  • Integrity and Respect: Demonstrates integrity and respect by leading with empathy, listening to others, seeking out different perspectives, and taking personal responsibility for decisions, actions, and results.
  • Dedicated to Quality: Takes ownership to maintain and promote high standards, looks for new ways to learn and improve, and embraces a growth mindset to seek and apply feedback from others in an effort to continuously improve. 
  • Building Relationships: Develops and strengthens relationships, adopting a “team first” mentality and working collaboratively to solve problems and meet shared goals.  
  • Delighting Customers: Listens and understands the interests and needs of our customers and stakeholders, making them feel heard and important, and embracing these learnings to continue delivering a unique Pokémon experience.

What to expect

  • An innovative culture driven by impact, delivering meaningful outcomes.
  • Company events that celebrate the spirit of Pokémon.
  • Competitive cash-based compensation programs.
  • 100% employer-paid healthcare premiums for you.
  • Generous paid family leave.
  • Employer-paid life insurance.
  • Employer-paid long and short-term income protection insurance.
  • US Employees: 401k Employer Matching.
  • UK/IRE/MX Employees: Pension Employer Contributions.
  • Fitness reimbursement.
  • Commuter benefit.
  • LinkedIn learning.
  • Comprehensive relocation package for certain roles.
  • Hybrid work environment.

The above statements are intended to describe the general nature and level of work being performed by people assigned to this role. They are not to be construed as an exhaustive list of all responsibilities, duties, and skills required. Employees may be required to perform duties outside of their normal responsibilities from time to time, as needed. For roles in the United Kingdom, candidates will need the right to work. In some cases, and for some roles, the Company may be able to arrange a visa. For roles in Ireland, this role requires candidates to have the right to live and work in the Republic of Ireland. However, we welcome applications from all nationalities and may consider supporting an employment permit application, in appropriate and suitable cases.

The Pokémon Company International is committed to the inclusion of all qualified applicants for consideration in our job application process. If you require reasonable accommodation to complete a job application, pre-employment testing, or a job interview, or to otherwise participate in the hiring process, please contact the Talent Acquisition team at [email protected].

The Pokémon Company International London, England Office

566 Chiswick High Road, 3rd Floor Building 10, London, United Kingdom, W4-5X5

Similar Jobs

4 Days Ago
Hybrid
London, England, GBR
Senior level
Senior level
Fintech • Information Technology • Insurance • Software
The Application Security Engineer embeds security throughout the software development lifecycle by advising on secure coding, threat modeling, OWASP Top 10 mitigation, code reviews, penetration testing, and SAST, DAST, and IAST tooling. The role partners with engineering teams, improves DevSecOps practices, researches AI and LLM threats, supports incident investigations, delivers security training, and mentors developers.
Top Skills: AIAWSAzureDastDevsecopsGCPIastLlm Threat ModelingOwasp Top 10Penetration TestingSast
5 Days Ago
Hybrid
London, England, GBR
Senior level
Senior level
Fintech • Software • Financial Services
Lead application security for the platform by embedding automated controls into the SDLC, conducting security architecture and code reviews, driving threat modeling, triaging vulnerabilities, coordinating remediations, partnering with engineering/product teams, and scaling tooling and AI-assisted workflows to raise security across cloud-native and containerized environments.
Top Skills: AIAWSCi/CdContainer Security ScanningContainersDastDependency ScanningEksJavaJavaScriptKotlinPenetration TestingReactSastTypescriptVulnerability Scanning
6 Days Ago
In-Office
London, Greater London, England, GBR
Senior level
Senior level
AdTech
Lead application security efforts by embedding security into the SDLC: automate SAST/DAST/SCA in CI/CD, run pentests and vulnerability management, perform threat modeling and code reviews, administer GHAS, secure cloud-native workloads (AWS), and drive security training and compliance (NIST CSF) across engineering teams.
Top Skills: Ai/Llm Tools (E.G.Api SecurityAws CloudtrailAws GuarddutyAws IamAws KmsAws VpcBurp SuiteCheckmarxCi/Cd PipelinesClaude)CodeqlCweDastGithub Advanced Security (Ghas)GoJavaNist CsfOwasp Top 10Owasp ZapPenetration TestingPythonSastScaSnykTypescriptVeracode

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account