The Role Embed security best practices within the SDLC, collaborating with developers to ensure secure coding. Conduct security assessments, identify potential threats, and mitigate risks in web and mobile applications. Perform applicationsecurity testing (SAST, DAST) and manual security code reviews. Implement and manage security tools such as SAST, DAST, SCA, and CI/… CD security integrations. Investigate security incidents, prioritise remediation and guide teams on secure development practices. Ensure applications meet industry standards (OWASP Top 10, NIST, ISO 27001) and regulatory requirements (GDPR, PCI-DSS, etc.) Educate engineers and stakeholders on security threats, vulnerabilities and secure coding practices. Skills 5+ years of experience in applicationsecurity, penetration testing … or software security engineering. Strong knowledge of secure coding principles in one or more languages (e.g., Python, Java, JavaScript, Go, .NET). Hands-on experience with SAST, DAST, SCA and security automation in CI/CD pipelines. Familiarity with cloud security (AWS, Azure, GCP) and container security (Docker, Kubernetes). Knowledge of OWASP Top 10, CWE More ❯
Are you passionate about Cyber Security and Enterprise Architecture? Do you have senior-level experience as a Cyber Security Professional? Join us to shape the security technology and tooling strategy for HMRC and influence the UK Public Sector. Enjoy a healthy work/life balance while making a significant impact. HMRC are now one of the most … IT Landscape across Multi-Hybrid Cloud Platform. Working in one of the most complex infrastructures across Europe with significant investment and over 1000 changes monthly impacting over 600 services. Security Modernisation is critical to this initiative and our collective success. Now is a great time to join us as we establish a team of outstanding people in the fields … of Security Architecture, Risk Assessment and Testing who will create and run these new and improved technology services. This is a chance to work on services that matter and affect the lives of millions of citizens as well as delivering Government Security services directly across circa 400 Government Departments and Arms-Length Bodies (ALBs). Job description HMRC More ❯
A great client of mine is hiring a Security-Focused Technical Consultant/Security Architect to join a highly regulated healthcare tech environment. You’ll work cross-functionally with engineering, architecture, and business teams to design secure solutions, manage risks, and ensure compliance across a portfolio of applications. Length: Initial 7 months with chance to extend or go … perm. IR35: Inside Work structure: Remote Key Responsibilities: Partner with engineering and architecture to define secure technical solutions Manage end-to-end project security across multiple applications Perform vulnerability testing, threat modelling, and risk assessments Maintain up-to-date security policies, standards, and best practices Communicate risks and mitigation strategies to senior stakeholders Translate business needs into effective … security controls Key Skills & Experience: 5+ years in security architecture or consulting in regulated environments Deep knowledge of secure SDLC, DevSecOps, cloud (Azure/AWS), and frameworks (OWASP, MITRE) Hands-on experience with vulnerability tools, threat modelling, and compliance (GDPR, HIPAA, PCI) Strong communication and stakeholder engagement skills Technical knowledge across .NET, Java, scripting (Python, PowerShell), APIs, and More ❯
and microservices to support frontend and data services. Perform data wrangling, cleaning, and transformation for analytics and reporting. Write clean, modular, and high-performance code with strong documentation. Ensure applicationsecurity, performance, and scalability across services. Stay up-to-date with the latest technologies in data engineering and Python development. Requirements Technical Skills 2–3 years of hands More ❯
We are working with a leading global law firm seeking an experienced and forward-thinking Application Engineer to take ownership of its legal technology stack and GenAI applications. This is a pivotal role focused on the deployment, maintenance, and optimisation of the firm’s core systems that support legal workflows, document and matter management, and AI-enhanced productivity. PLEASE … You will work closely with legal teams, vendors, and IT colleagues to ensure secure, innovative, and high-performing technology solutions. Reporting directly to the Head of Infrastructure and Information Security, this is a fantastic opportunity to shape the legal tech landscape of a global firm and collaborate regularly with senior stakeholders, including partners. Key Responsibilities: Manage and optimise the … GenAI applications (e.g., iManage Cloud, Intapp, M365 Copilot, ChatGPT Enterprise). Provide expert 2nd/3rd line support and lead on technical design and implementation of new tools. Ensure applicationsecurity, stability, and performance through proactive maintenance and patching. Evaluate emerging legal tech and GenAI tools for innovation opportunities. Partner with legal teams to enable automation and AI More ❯
South East London, England, United Kingdom Hybrid / WFH Options
InfoSec People Ltd
The role is hybrid 1 day a week in their London Office. The Specialist ApplicationSecurity Engineer will play a pivotal role in ensuring the integrity and security of our applications across various platforms. You will lead the charge in implementing robust security measures, collaborating closely with cross-functional teams to fortify our defenses against cyber … threats. KEY ACCOUNTABILITIES & RESPONSIBILITIES Focused on applicationsecurity initiatives across cloud and on-premises environments, employing a diverse suite of tools including Semgrep for SAST, Snyk for SCA, GHAS for secret scanning, Burp Suite for DAST, and python for automation. Forge partnerships with external vendors to optimize and seamlessly integrate security tools into our applicationsecurity workflow, ensuring comprehensive coverage and operational efficiency. Drive the seamless integration of applicationsecurity processes into development pipelines, leveraging Azure DevOps (ADO), GitHub Actions, and similar tools for streamlined automation. Actively contribute to the formulation and enforcement of applicationsecurity policies and procedures, utilizing advanced tool capabilities to mitigate risks effectively. Engage with internal stakeholders More ❯
South East London, England, United Kingdom Hybrid / WFH Options
Oliver Bernard
ApplicationSecurity Engineer - FinTech Our client is a growing FinTech, building cutting edge trading platforms for hedge funds and investment managers around the world. In London, they’re looking for an ApplicationSecurity Engineer, with strong Penetration Testing experience, to join them. This is an initial 6 month contract, hybrid working (3 days a week in … the office), outside IR35 and paying ~£550 - £600 per day. This hire is part of a security -focused transformation and you’ll be responsible for identifying and mitigating security vulnerabilities, and risk, within their applications. You’ll focus on building security tools, penetration testing and performing security assessments, whilst updating internal security processes and documentation … the process. Required: Strong experience as an App Sec Engineer Extensive experience of Penetration Testing Hands-on experience with tools such as Burp Suite and Metasploit Capable of designing Security policies, procedures and best practices The ability to investigate and respond to Security related incidents within applications, and work closely with Dev teams throughout API Testing experience (with More ❯