Jobiglo

No results.

Senior Application Security Consultant (SAST/DAST/OWASP)

Salt Search · London

Contract Hybrid Senior 🇬🇧 English
Application Security Secure SDLC OWASP Top 10 Secure Coding Threat Modelling STRIDE MITRE ATT&CK Security Architecture DevSecOps CI/CD GitHub Actions GitLab Jenkins Azure DevOps SAST DAST SCA Checkmarx Fortify SonarQube Veracode Semgrep Burp Suite OWASP ZAP Snyk Trivy Prisma Cloud Aqua Wiz AWS Azure GCP Kubernetes Docker Container Security API Security REST APIs Microservices Security

Job description

About the role

We are seeking a Senior Application Security Consultant / DevSecOps Security Architect to join a high‑performing cyber‑security function within a large banking technology environment in London. You will work closely with software engineering, cloud, architecture and DevOps teams to embed security throughout the Secure SDLC and ensure applications are built and deployed securely.

Key responsibilities

  • Lead application security reviews for business‑critical applications and cloud platforms.
  • Conduct security architecture and secure design reviews.
  • Perform risk assessments, define security requirements and lead threat‑modelling workshops (STRIDE, MITRE ATT&CK).
  • Integrate SAST, DAST and SCA tooling into CI/CD pipelines and support remediation.
  • Provide guidance on secure coding, API security and micro‑services protection.
  • Produce security standards, technical guidance and best‑practice documentation.
  • Act as the Application Security SME across multiple technology programmes.

Required profile

  • 8+ years of experience in cyber security, with a strong focus on application security or DevSecOps.
  • Proven experience working directly with software engineering teams in a large‑scale cloud environment.
  • Hands‑on experience with secure SDLC, threat modelling and vulnerability management.

Required skills

  • Application Security, Secure SDLC, OWASP Top 10, Secure Coding.
  • Threat Modelling (STRIDE, MITRE ATT&CK), Security Architecture.
  • DevSecOps, CI/CD, GitHub Actions, GitLab, Jenkins, Azure DevOps.
  • SAST, DAST, SCA tools: Checkmarx, Fortify, SonarQube, Veracode, Semgrep, Burp Suite, OWASP ZAP, Snyk, Trivy, Prisma Cloud, Aqua, Wiz.
  • Cloud Security (AWS, Azure, GCP), Kubernetes, Docker, Container Security.
  • API Security, REST APIs, Microservices Security.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec Salt Search.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.
Le contrat proposé est un Contract basé à London.

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in the United Kingdom.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

A question about this job?

Ask it here: you will get the full job summary by e-mail, right away.

💬 Chat with us on Telegram

Published 1 month ago

Expires 1 week from now

21 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

Salt Search

London