Davy Rogers

Application Security, AI Security & Secure Engineering

Practical application security for software teams.

I help engineering teams build secure applications through secure code review, threat modelling, vulnerability management, AI security, penetration testing, and CI/CD security automation.

I lead application security work across engineering teams, combining hands-on technical testing with clear remediation guidance, secure design support, and application security maturity improvement across enterprise environments. My credentials include Certified Information Systems Security Professional (CISSP) and Offensive Security Certified Professional (OSCP).

Focus

The work I care about most sits where technical security testing, engineering delivery, and clear risk decisions meet.

Application security leadership

Helping teams make security decisions earlier, remediate issues effectively, and improve AppSec maturity without slowing delivery.

Secure software delivery

Embedding secure design, code review, threat modelling, vulnerability management, and automated checks into everyday engineering workflows.

AI security

Reviewing AI-enabled systems, assessing AI-generated code, and applying modern models and tooling to practical AppSec workflows.

Experience

Lead Security Engineer - Applications

Holland & Barrett

May 2026 - Present

Providing practical application security guidance, hands-on remediation support, and technical leadership for engineering teams. My work covers secure code review, reviews of AI-enabled systems, threat modelling, vulnerability remediation, CI/CD security automation, and secure design support, with a focus on making AppSec effective, repeatable, and easy for development teams to adopt.

Senior Security Engineer - Applications

Holland & Barrett

Oct 2025 - May 2026

Supported engineering teams with hands-on application security testing, secure code review, practical remediation guidance, threat modelling, AI-assisted vulnerability analysis, and automated security checks across the software development lifecycle.

Senior Application Security Engineer

JustAppSec

Jul 2025 - Present

Delivering focused application security health checks for software teams. Each engagement uses AI-assisted secure code review to target the high-risk areas where serious issues usually live, then produces a clear, actionable written report and a one-to-one debrief that gives teams either reassurance or a concrete remediation plan.

Application Security Manager

Unily

Mar 2023 - Oct 2025

Led application security improvement across an enterprise SaaS environment, including technical testing, security review, generative AI security review, AI-generated code assessment, AI safety guardrails, and risk guidance for engineering teams.

Independent Security Researcher

Synack Red Team

Nov 2021 - Oct 2025

Participated in private security testing engagements across web applications, mobile applications, and infrastructure alongside full-time employment, reporting vulnerabilities through structured responsible disclosure processes.

Senior Security Engineer - Applications

A.P. Moller - Maersk

Mar 2022 - Mar 2023

Helped improve application security across a large global engineering environment, supporting teams with secure design decisions, practical AppSec guidance, threat modelling, and DevSecOps-focused ways of working.

Application Security Specialist

Atradius

Mar 2020 - Mar 2022

Supported application security improvement across a global financial services environment, covering secure code review, web application penetration testing, vulnerability scanning, platform assurance, security reporting, and AppSec tooling evaluation.

Business Systems Manager and earlier operations roles

Freeman

Oct 2006 - Mar 2020

Progressed through operational, analytical, and systems-focused roles before moving into Business Systems Management in 2015. Led support, improvement, and integration of internal business systems across finance, operations, and wider enterprise processes.

Credentials

CISSP

Certified Information Systems Security Professional

ISC2

Issued Jun 2025

Verify

OSCP

Offensive Security Certified Professional

OffSec

Issued Feb 2019

Verify

GDPR Practitioner

EU General Data Protection Regulation Practitioner

IBITGQ

Issued Aug 2017

Verify

Selected Work

Public projects where I publish, maintain, and review practical application security guidance, tooling, and training material.

JustAppSec

Creator, maintainer, and engineer

An application security practice I created and maintain, offering focused security health checks and AI-assisted secure code review for software teams. Alongside running it, I stay hands-on in the engineering work, from secure code review and vulnerability analysis to threat modelling and DevSecOps guidance.

Visit JustAppSec

The CyberSec Lounge

Creator and content reviewer

An independent cyber security learning and resource site created to share practical guidance, training material, and industry-focused content.

Visit The CyberSec Lounge