Application & AI Resource- 6 Month Contract - Hybrid in Coventry - Inside IR35
Application & AI Resource- 6 Month Contract - Hybrid in Coventry - Inside IR35
Role Overview
An experienced Application & AI Security Resource to support the security, governance, and resilience of enterprise applications, cloud-native services, APIs, and AI platforms. The position spans application security assessments, DevSecOps initiatives, cloud security governance, and AI risk management across Azure and AWS environments, working closely with development, cloud, infrastructure, and cybersecurity teams.
Key Responsibilities
- Administer and optimise Azure WAF and AWS WAF policies, and conduct application security assessments covering web applications, APIs, and cloud-native services.
- Support secure design and governance of Azure Logic Apps, Function Apps, and related cloud services, assessing and strengthening API security controls, authentication mechanisms, and access management practices.
- Implement and manage enterprise secrets and key management platforms including Azure Key Vault and AWS KMS, embedding security controls within CI/CD pipelines and DevSecOps processes.
- Participate in application threat modelling, architecture reviews, and security risk assessments across the enterprise application landscape.
- Support AI security governance, risk management, and compliance controls, conducting security assessments of AI platforms including Azure OpenAI and Microsoft Copilot, and supporting prompt injection mitigation and secure AI adoption.
Top 5 Skills
- Application & API security - Proven experience in application security roles with a strong understanding of OWASP Top 10, API security controls (authentication, authorisation, encryption), and WAF technologies including Azure WAF and AWS WAF.
- Cloud-native security - Hands-on knowledge of cloud-native security services across Azure and AWS, including secrets management, cryptographic key management, and securing serverless and cloud application services.
- DevSecOps & SSDLC - Experience embedding security within CI/CD pipelines and DevSecOps practices, with understanding of the Secure Software Development Lifecycle and application security testing tools (SAST, DAST, SCA).
- AI & LLM security - Knowledge of AI and LLM security risks, governance frameworks, prompt injection mitigation, and data protection requirements, ideally with exposure to Azure OpenAI, Microsoft Copilot, or equivalent platforms.
- Security assessments & certifications - Experience performing threat modelling, architecture reviews, and risk assessments, with relevant certifications such as AZ-500, SC-100, CISSP, CCSP, CSSLP, or CEH being a strong advantage.
Contract Details:
- Rate: £400 per day Inside IR35
- Location: Hybrid (3x a week) in Coventry
- Duration: 6 Month Initial Contract