Senior Application Security Consultant (SAST/DAST/OWASP )
other jobs Salt Search
Added before 4 Days
- England,London,City of London
- Full Time, Contract
- Salary negotiable
Job Description:
Full job descriptionSenior Application Security Consultant (SAST/DAST/OWASP )/ DevSecOps Security - Banking - London
Secure SDLC | SAST | DAST | Threat Modelling | Cloud Security | CI/CD
Location: London (Hybrid - 8 days onsite per month)
Contract: 12 Months + extension
Rate:£500-£550 per day (Umbrella)
The Opportunity
We’re looking for an experienced Senior Application Security Consultant / DevSecOps Security Architect to join a high-performing Cyber Security function within a large enterprise technology environment.
Working alongside software engineering, cloud, architecture and DevOps teams, you’ll play a key role in embedding security throughout the Software Development Lifecycle, ensuring applications are designed, developed and deployed securely.
This is an excellent opportunity for someone passionate about Secure-by-Design, DevSecOps and modern Application Security within a large-scale cloud environment.
Key Responsibilities
*Lead application security reviews across business-critical applications and cloud platforms.
*Conduct security architecture and secure design reviews.
*Perform application security risk assessments and define security requirements.
*Lead Threat Modelling workshops using STRIDE, MITRE ATT&CK or similar methodologies.
*Embed Secure SDLC principles into engineering teams.
*Integrate security tooling into CI/CD pipelines and DevSecOps processes.
*Review and analyse SAST, DAST and Software Composition Analysis (SCA) findings.
*Work closely with development teams to prioritise vulnerability remediation.
*Define security testing requirements and support penetration testing activities.
*Produce security standards, technical guidance and best practice documentation.
*Act as the Application Security SME across multiple technology programmes.
Essential Skills
Application Security
*Secure Software Development Lifecycle (SSDLC)
*OWASP Top 10
*Secure Coding
*Secure Design Reviews
*API Security
*REST APIs
*Microservices Security
*Application Security Risk Assessments
Threat Modelling
*STRIDE
*MITRE ATT&CK
*Security Architecture
*Risk Assessments
DevSecOps
*CI/CD Security
*GitHub Actions
*GitLab
*Jenkins
*Azure DevOps
*Security Automation
*Shift Left Security
Security Testing
*SAST
*DAST
*SCA
*Vulnerability Management
*Penetration Testing
Cloud Security
*AWS, Azure or GCP
*Kubernetes
*Docker
*Container Security
*Cloud Security Best Practices
Security Tooling
Experience with one or more of:
*Checkmarx
*Fortify
*SonarQube
*Veracode
*Semgrep
*Burp Suite
*OWASP ZAP
*Snyk
*Trivy
*Prisma Cloud
*Aqua
*Wiz
Ideal Background
You’ll ideally have:
*8+ years in Cyber Security
*Strong Application Security or DevSecOps experience
*Experience working directly with software engineering teams
*Experience embedding security into CI/CD pipelines
*Strong knowledge of Secure SDLC
*Experience conducting Threat Modelling sessions
*Excellent stakeholder management and communication skills
*Previous experience within Banking, Financial Services, Insurance or another highly regulated enterprise environment
Contract Details
*12-month contract
*£500-£600 per day (Umbrella)
*Hybrid working - 8 days onsite per month in London
*Immediate interview availability preferred
*Rates depend on experience and client requirements
Secure SDLC | SAST | DAST | Threat Modelling | Cloud Security | CI/CD
Location: London (Hybrid - 8 days onsite per month)
Contract: 12 Months + extension
Rate:£500-£550 per day (Umbrella)
The Opportunity
We’re looking for an experienced Senior Application Security Consultant / DevSecOps Security Architect to join a high-performing Cyber Security function within a large enterprise technology environment.
Working alongside software engineering, cloud, architecture and DevOps teams, you’ll play a key role in embedding security throughout the Software Development Lifecycle, ensuring applications are designed, developed and deployed securely.
This is an excellent opportunity for someone passionate about Secure-by-Design, DevSecOps and modern Application Security within a large-scale cloud environment.
Key Responsibilities
*Lead application security reviews across business-critical applications and cloud platforms.
*Conduct security architecture and secure design reviews.
*Perform application security risk assessments and define security requirements.
*Lead Threat Modelling workshops using STRIDE, MITRE ATT&CK or similar methodologies.
*Embed Secure SDLC principles into engineering teams.
*Integrate security tooling into CI/CD pipelines and DevSecOps processes.
*Review and analyse SAST, DAST and Software Composition Analysis (SCA) findings.
*Work closely with development teams to prioritise vulnerability remediation.
*Define security testing requirements and support penetration testing activities.
*Produce security standards, technical guidance and best practice documentation.
*Act as the Application Security SME across multiple technology programmes.
Essential Skills
Application Security
*Secure Software Development Lifecycle (SSDLC)
*OWASP Top 10
*Secure Coding
*Secure Design Reviews
*API Security
*REST APIs
*Microservices Security
*Application Security Risk Assessments
Threat Modelling
*STRIDE
*MITRE ATT&CK
*Security Architecture
*Risk Assessments
DevSecOps
*CI/CD Security
*GitHub Actions
*GitLab
*Jenkins
*Azure DevOps
*Security Automation
*Shift Left Security
Security Testing
*SAST
*DAST
*SCA
*Vulnerability Management
*Penetration Testing
Cloud Security
*AWS, Azure or GCP
*Kubernetes
*Docker
*Container Security
*Cloud Security Best Practices
Security Tooling
Experience with one or more of:
*Checkmarx
*Fortify
*SonarQube
*Veracode
*Semgrep
*Burp Suite
*OWASP ZAP
*Snyk
*Trivy
*Prisma Cloud
*Aqua
*Wiz
Ideal Background
You’ll ideally have:
*8+ years in Cyber Security
*Strong Application Security or DevSecOps experience
*Experience working directly with software engineering teams
*Experience embedding security into CI/CD pipelines
*Strong knowledge of Secure SDLC
*Experience conducting Threat Modelling sessions
*Excellent stakeholder management and communication skills
*Previous experience within Banking, Financial Services, Insurance or another highly regulated enterprise environment
Contract Details
*12-month contract
*£500-£600 per day (Umbrella)
*Hybrid working - 8 days onsite per month in London
*Immediate interview availability preferred
*Rates depend on experience and client requirements
Job number 3991861
Increase your exposure to recruiters with ProJobs
Thousands of recruiters are looking for you in the Job Master profile database, increase your exposure 4 times with a ProJob subscription
You can cancel your subscription at any time.