Jobiglo

No results.

Lead Application Security/DevSecOps Engineer

faria · Loughborough

New
Contract Senior 🇬🇧 English
Application security AppSec tooling SAST DAST SCA Secrets scanning DevSecOps CI/CD integration Secrets management Vault integration Threat modeling Vulnerability management AWS Azure Ruby on Rails PHP/Laravel .NET/C# Python GitHub Advanced Security

Job description

About the role

Faria, a global leader in education SaaS solutions, is seeking a Lead Application Security/DevSecOps Engineer to own and mature its application security program across five products. Reporting to the VP of Engineering, the role works closely with the vCISO, DevOps, and engineering teams to embed security throughout the software development lifecycle.

Key responsibilities

  • Define and run a greenfield application security program, establishing a secure SDLC with security requirements, design reviews, guardrails, and coding standards.
  • Select, deploy, and integrate AppSec tooling (SAST, DAST, SCA, secrets scanning) into CI/CD pipelines.
  • Implement secrets management, detection, rotation, and vault integration across pipelines.
  • Lead risk‑based vulnerability management, triage, prioritise, and drive remediation across multiple tech stacks.
  • Conduct threat modelling and security reviews for new architectures and major features.
  • Improve cloud security posture on AWS and Azure, partnering with platform and infrastructure teams.
  • Lead technical incident response for application‑layer incidents and coordinate with SOC and vCISO.
  • Build a security‑champions network and deliver security awareness training.

Required profile

  • 7+ years of experience in application/product security, including building or significantly maturing an AppSec program.
  • Strong knowledge of AI concepts and a proactive approach to protecting AI‑driven features.
  • Hands‑on experience across Ruby on Rails, PHP/Laravel.NET/C#, and Python (deep in at least one).
  • Extensive cloud security experience on AWS (primary) and Azure.
  • Proven ability to lead vulnerability remediation and manage large vulnerability backlogs.

Required skills

  • Application security (AppSec) tooling: SAST, DAST, SCA, secrets scanning.
  • DevSecOps integration with CI/CD pipelines.
  • Secrets management and vault solutions.
  • Threat modelling.
  • Vulnerability management and remediation.
  • Cloud security on AWS and Azure.
  • Programming languages: Ruby on Rails, PHP/Laravel.NET/C#, Python.
  • GitHub Advanced Security (nice‑to‑have).

What we offer

  • Competitive compensation and career development opportunities.
  • Learning resources: online platform, unlimited book purchases, internal and external training.
  • Friendly team atmosphere with group activities and corporate events.
  • Equipment provision including MacBook Pro or laptop of choice, peripherals, and displays.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec faria.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.
Le contrat proposé est un Contract basé à Loughborough.
Source : ats:bamboohr

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in the United Kingdom.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

💬 Chat with us on Telegram Chat on WhatsApp

Published 5 hours ago

Expires 1 month from now

1 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

faria

Loughborough