Senior Application Security Specialist
The Application Security Specialist exists to embed application security expertise across Europe’s products and services, supporting the Secure Development Practice and enabling a consistent ‘shift-left’ approach. The role is accountable for advancing application security capability, leading security reviews on higher-risk systems, and ensuring secure development practices are adopted across engineering teams. The post holder will act as a technical authority on application security, helping reduce vulnerability risk and improve security outcomes across both internal IT systems and customer-facing solutions.
- Strong knowledge of application security principles and practices
- Experience with SAST, DAST and software composition analysis tools
- Knowledge of secure coding practices across languages such as Java, C, C++
- Experience with CI/CD pipelines and DevSecOps integration
- Threat modelling techniques and tools
- Understanding of OWASP Top 10 and common vulnerability classes
- Experience with API security and web application security
- Understanding of fuzz testing and advanced testing techniques
- Familiarity with secure AI development considerations
- Knowledge of secure development frameworks such as SSDF
- Understanding of vulnerability management processes
Experience Required
Minimum
- 3 to 5 years in application security, secure development or software engineering with a security focus
- Hands-on experience conducting application security reviews
- Experience implementing security in CI/CD processes
- Experience working with development teams in an enterprise environment
Desirable
- Experience building or contributing to a security CoE or capability model
- Experience working in a multi-entity, multinational environment
- Experience integrating security into large-scale development programmes
- Experience supporting secure AI or data-centric applications
Minimum Qualifications Required
Minimum
- Degree or equivalent professional experience in one of the following:
- computer science
- software engineering
- cyber security
- information security or related technical discipline
- Evidence of formal or structured learning in secure development or application security (for example through certifications, formal training or demonstrable experience).
Desirable
- Recognised application security or secure development certification, such as:
- CSSLP (Certified Secure Software Lifecycle Professional)
- GIAC Web Application Penetration Tester (GWAPT) or GWEB
- Offensive Security certifications (e.g. OSCP) where relevant to application testing
- Cloud security certifications relevant to application hosting environments:
- AWS Security Specialty
- Microsoft Azure Security Engineer Associate
- Google Professional Cloud Security Engineer
- DevSecOps or CI/CD related certifications or formal training
- ISO 27001 Lead Implementer or Lead Auditor, or demonstrable understanding of ISO control environments
- Familiarity with NIST frameworks, particularly NIST CSF and NIST SSDF, demonstrated through training or experience
- Relevant vendor certifications linked to SAST, DAST, SCA or pipeline tooling where used in the organisation
- Evidence of continuous professional development in secure coding, software assurance or emerging technologies such as AI security
Minimum Skills Required
Minimum
- Strong software engineering foundation:
- ability to read and understand code across at least one major language (Java, C, C++, C#, Python or similar)
- understanding of common development frameworks and application architectures
- Practical application security capability:
- hands-on experience identifying and explaining common vulnerabilities
- ability to guide remediation in a way developers can implement
- Secure development lifecycle knowledge:
- understanding of how to embed security into design, build, test and deployment stages
- familiarity with shift-left practices and developer workflows
- Threat modelling capability:
- ability to identify threats, abuse cases and attack surfaces
- experience applying structured approaches such as STRIDE or similar
- CI/CD and DevOps familiarity:
- understanding of pipelines, build processes and release workflows
- capability to integrate or advise on automated security testing within pipelines
- Analytical and diagnostic capability:
- ability to interpret scan results and distinguish false positives from real risk
- ability to identify systemic issues rather than isolated defects
- Communication and influence:
- ability to translate security issues into actionable developer guidance
- confidence in engaging engineers, architects and product owners
- Risk awareness:
- ability to link technical vulnerabilities to business risk and prioritisation
Desirable
- Advanced application security techniques:
- experience with fuzz testing, advanced dynamic testing or manual code review
- experience testing APIs, microservices and distributed systems
- DevSecOps implementation:
- experience designing or implementing security controls within CI/CD pipelines
- hands-on experience integrating SAST, DAST, SCA and secrets scanning tools
- Secure architecture understanding:
- familiarity with secure design patterns and common failure modes in modern architectures (cloud-native, microservices, serverless)
- Secure AI and data-driven systems awareness:
- understanding of risks associated with AI models, data pipelines and prompt or model manipulation
- Training and enablement capability:
- ability to design or deliver developer-focused training or workshops
- ability to simplify complex security concepts without diluting technical accuracy
- Broader security framework awareness:
- working knowledge of OWASP SAMM, ASVS or similar maturity models
- familiarity with threat intelligence inputs and how they influence application risk
- Tooling depth:
- experience selecting, tuning or optimising security tools for development environments
- understanding of strengths and limitations of common tooling categories
- Multi-environment experience:
- exposure to both internal enterprise IT systems and externally facing customer solutions
- Ability to operate in federated organisations:
- comfort working across multiple teams, geographies and delivery models with varying levels of maturity