76 to 100 of 100 OWASP Jobs in London

Penetration Tester

Hiring Organisation
DGH Recruitment
Location
City of London, London, United Kingdom
Employment Type
Permanent
Salary
£55,000
engagement, and plan testing that meets their assurance needs. * Apply manual and tool-assisted testing techniques aligned with recognised methodologies and frameworks, including the OWASP Web Security Testing Guide, PTES, and MITRE ATT&CK. * Deliver Cyber Essentials Plus assessments, including scoping, conducting the required technical tests, verifying remediation and supporting ...

Senior Front-End Developer

Location
Greater London, England, United Kingdom
setups (Nx, Turborepo), Storybook, Playwright/Cypress, Vitest/Jest Performance monitoring (Lighthouse, Web Vitals) and logging/observability Security best practices (CSP, SRI, OWASP, dependency auditing) CDN, edge functions, SSR/SSG, ISR architectures Micro-frontend or design-system experience #J-18808-Ljbffr ...

Technical Security Consultant

Location
Greater London, England, United Kingdom
including SAST, SCA, DAST, secrets scanning, IaC scanning, API security, threat modelling and CI/CD security. Map controls against frameworks including NIST SSDF, OWASP SAMM and OWASP DSOMM. Review security tooling and integrations across GitHub, GitLab, CI/CD and cloud environments. Conduct control-effectiveness assessments, evidence reviews ...

Founding Security Engineer: Build Security for AI Litigation

Location
Greater London, England, United Kingdom
ensure we are secure and demonstrably so to our customers. You’ll embed secure-by-design practices, monitor for irregular behaviour, align with OWASP Top 10 and AWS Well-Architected, and lead risk assessments and policy documentation under ISO 27001 ISMS. #J-18808-Ljbffr ...

Senior Manager, Security Architecture

Location
Greater London, England, United Kingdom
guardrails. Nice to have Working familiarity with AI security standards and references such as the NIST AI RMF, ISO 42001, MITRE ATLAS, or the OWASP LLM Top 10. Hands‐on experience with policy‐as‐code and turning standards into enforced controls. Contributions to security standards, frameworks, or industry practice. ...

Response Engineer – Cloudflare Managed Defense Center (CMDC)

Location
Greater London, England, United Kingdom
advanced Security Operations, or high-level Technical Support/Incident Response for enterprise infrastructure Proven capability to handle both Application Security (including knowledge of OWASP Top 10 vulnerabilities, L7 WAF, HTTP/S anomalies, Bot mitigation) and Network Security (L3/L4 volumetric DDoS, protocol abuse) Working knowledge of threat ...

Senior Fullstack Engineer - NestJS Vue

Hiring Organisation
Hireful
Location
Central London, London, United Kingdom
Employment Type
Contract, Work From Home
data modelling. Migrations, indexes, and a sense of what a query actually costs. - Security as a working habit. Authentication and authorisation, tenant isolation, the OWASP Top 10, secret handling, validation at the trust boundary. We'll go into this in the interview, and again every week. - Architecture judgement. ...

AI Security Consultant

Location
Greater London, England, United Kingdom
practical terms. Experience with AI governance, responsible AI, model risk management or AI assurance. Familiarity with frameworks and guidance such as NIST AI RMF, OWASP Top 10 for LLM Applications, OWASP Agentic AI guidance, MITRE ATLAS, ISO 27001, NIST CSF, CIS Controls or cloud security frameworks. Experience with SOC operations ...

Director of AI Security & Cloud Defense

Location
City of Westminster, England, United Kingdom
sales to guard customer data and regulatory readiness. You will drive AI security integration, incident command, tabletop exercises, and risk management using NIST/OWASP frameworks, while mentoring a global security team. #J-18808-Ljbffr ...

Response Engineer - Cloudflare Managed Defense Center (CMDC)

Location
Greater London, England, United Kingdom
advanced Security Operations, or high-level Technical Support/Incident Response for enterprise infrastructure Proven capability to handle both Application Security (including knowledge of OWASP Top 10 vulnerabilities, L7 WAF, #J-18808-Ljbffr ...

Senior Platform Security Engineer - Core Services

Location
Greater London, England, United Kingdom
over 8 years of experience and a strong focus on security feature design, authentication workflows, and extensive knowledge of secure coding practices, including OWASP Top 10. Additional perks include equity options, private medical insurance, and a hybrid working model. #J-18808-Ljbffr ...

Enterprise Security Architect

Location
City Of London, England, United Kingdom
The Apex Group was established in Bermuda in 2003 and is now one of the world’s largest fund administration and middle office solutions providers. Our business is unique in its ability to reach globally ...

Director, Security Engineering

Location
Greater London, England, United Kingdom
injection, machine identities), hardening against AI-driven threats (phishing-resistant MFA, supply chain/developer guardrails, help desk impersonation defenses), and implementing NIST/OWASP/ATLAS risk frameworks. Additionally, you will oversee enterprise architecture, secure-by-default software lifecycles, and risk-based vulnerability management. Job Responsibilities … engineer, an executive, and an enterprise customer on the same incident and land it with all three. Nice to have: securing AI product features, OWASP Top 10 for LLM Applications, the NIST AI Risk Management Framework, MITRE ATLAS, SOC 2, or ISO 27001. Education Degree in a STEM field, preferably ...

Senior AI Engineer

Hiring Organisation
MarkIT Placements
Location
London, United Kingdom
Employment Type
Contract, Work From Home
Contract Rate
From £700 to £900 per day
Senior Applied AI Engineer Defence & National Security Location: London/Oxford Hybrid Contract: 6 months initially, with strong potential for extension Day Rate: £700£900 per day, depending on experience IR35: Outside IR35 Start Date ...

Engineering Manager - Payments Integrations

Location
Greater London, England, United Kingdom
your team. Set and enforce best practices across coding standards, testing, observability, and documentation. Ensure the team follows secure software development practices, including OWASP standards, data privacy, and compliance requirements. Guide architectural decisions for low‐latency, high‐availability backend systems and microservices. Champion an AI‐first engineering culture, setting standards … understanding of microservices and event‐driven architectures, APIs, and integration patterns. Experience with SQL and relational databases. Knowledge of secure software development practices and OWASP principles. Champion of AI‐first development — experience setting standards for AI‐assisted coding, automated testing, and code generation using LLMs and tools like Claude Code ...

Founding Security Engineer

Location
Greater London, England, United Kingdom
hardening Monitor systems for irregular behaviour and proactively design detection and prevention mechanisms Ensure infrastructure and applications align with accepted industry standards (e.g. OWASP Top 10 , AWS Well-Architected Framework ) Conduct and lead risk assessments , including third-party/vendor reviews and internal evaluations Document and maintain security policies, procedures … ecosystem and can comfortably navigate enterprise security tools across vendors Have solid foundations in networking, systems, and cloud infrastructure, and can apply frameworks like OWASP and AWS Well‐Architected to real‐world scenarios Have experience reviewing and improving product and infrastructure security, including secure SDLC practices (e.g. threat modelling, secure ...

WAF Engineer

Location
Greater London, England, United Kingdom
appropriate security posture. Design, implement, maintain and optimise WAF policies across multi-cloud environments. Lead the investigation and mitigation of web application attacks, including OWASP Top 10 threats, bot attacks, credential stuffing, scraping, Layer 7 DDoS attacks and other web-based threats. Develop, maintain and enhance custom WAF rules, managed … controls, and attack mitigation policies, rather than solely relying on out-of-the-box managed rules. Extensive knowledge of web application attack vectors, including OWASP Top 10 vulnerabilities, SQL Injection, Cross-Site Scripting (XSS), Remote Code Execution (RCE), bot attacks, credential stuffing, and API abuse. Advanced hands-on expertise ...

Principal AI Security Software Engineer

Location
Greater London, England, United Kingdom
Code. A solid grounding in secure by default engineering, observability and production operability, with practical knowledge of AI security practices such as the OWASP Top 10 for LLM and Generative AI applications and OWASP guidance for agentic AI. We believe in equal opportunity for all and actively encourage applications from ...

Principal AI Security Software Engineer

Hiring Organisation
SGI
Location
Greater London, England, United Kingdom
Code. A solid grounding in secure by default engineering, observability and production operability, with practical knowledge of AI security practices such as the OWASP Top 10 for LLM and Generative AI applications and OWASP guidance for agentic AI. By applying for this role, you consent to SGI contacting ...

Senior/Principal AI Software Engineer

Hiring Organisation
Experis
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
£600 - £800/day
Infrastructure as Code. A solid grounding in secure-by-default engineering, observability and production operability. Practical knowledge of AI security practices, including the OWASP Top 10 for LLM and Generative AI applications and OWASP guidance for agentic AI. Previous experience working within Information Security or Security engineering environments would ...

OT Cyber Consultant -CGEMJP00354346

Location
Greater London, England, United Kingdom
OT Cyber Consultant Rate: up to £368 per day - Umbrella only Duration: 5 months Location: 1 - 3 Strand, London, WC2N 5EH 50% onsite - 50% remote SC Cleared/sole UK national Role Description: The Operational ...

DevSecOps and Attack Surface Specialist

Location
Greater London, England, United Kingdom
application security principles across the full software development lifecycle Hands on experience with SAST and SCA tooling such as Semgrep, Checkmarx, Snyk, and OWASP Dependency Check Experience configuring and operating DAST tools such as OWASP ZAP, Burp Suite Enterprise, and Invicti Ability to triage, validate, and reproduce vulnerabilities through manual ...

Web Security Engineer, Akamai

Hiring Organisation
Sanderson Recruitment
Location
City of London, London, United Kingdom
Employment Type
Contract
Contract Rate
£550 - £600 per day
protection capabilities. Strong hands on experience with Web Application Firewalls (WAF), including policy design, rule tuning, exception management and application onboarding. Good understanding of OWASP Top 10 and OWASP API Security Top 10. Knowledge of HTTP/S, REST APIs and application layer attack mitigation. Experience with vulnerability management, Qualys ...

Senior iOS Security Engineer – ProdSec

Location
Greater London, England, United Kingdom
authentication mechanisms. Security Expertise Runtime Application Self‐Protection (RASP) Anti‐tampering protections Anti‐debugging mechanisms Certificate pinning Application integrity validation Strong understanding of: OWASP Mobile Top 10 OWASP MASVS Secure SDLC practices Mobile attack techniques and adversarial behaviour Knowledge of: Frida Objection Dynamic instrumentation frameworks Jailbreak environments Runtime hooking methodologies ...

Mobile Application Senior Security Engineer London, Milan, Stockholm +1 more £91,196 GBP - £116,438 GBP

Location
Greater London, England, United Kingdom
penetration tests and red-team exercises against the apps, reverse-engineer builds to find what static review misses, and use the OWASP Mobile Application Security Verification Standard (MASVS) and Testing Guide (MASTG) as your working framework rather than a checklist you fill in after the fact. You’ll work closely … binaries to surface sandboxing, permission, and platform-security weaknesses before an outside attacker finds them. You’ll test Klarna's mobile apps against the OWASP MASVS and MASTG, and use the results to drive concrete fixes with engineering teams. You’ll evaluate and stress-test app-hardening and RASP protections ...