Position Overview Fast growing FinTech seeking a technically proficient Principal ApplicationSecurity Architect to join our innovative FinTech organisation. This role is critical in shaping the security posture of complex, cloud-native applications that power fast-growing financial services and digital payments platforms. As an ApplicationSecurity Architect, you will work closely with software engineers … deployment and tuning of automated applicationsecuritytesting tools including Static ApplicationSecurityTesting (SAST), DynamicApplicationSecurityTesting (DAST), and Software Composition Analysis (SCA). Collaborate with development teams to integrate securitytesting seamlessly into CI/CD pipelines, enabling early detection and continuous monitoring of vulnerabilities. … security or secure software engineering, preferably within FinTech or highly regulated industries. Hands-on experience with a range of applicationsecuritytesting tools including SAST, DAST, and SCA, and integrating these into automated build and deployment pipelines. Practical expertise with threat modeling methodologies such as STRIDE, PASTA, or Attack Trees. Strong knowledge of secure coding standards More ❯
best work. Whether you're building on our platform, supporting our customers, or shaping our story: You can just ship things. About the Role: We are looking for aSenior ApplicationSecurity Engineerto join our security team (reporting to the Head of Security). In this role, you will drive critical applicationsecurity initiatives across … Vercel's products and platform. Your core focus will be onthreat modeling, open-source software security, secure code review, SDLC tooling, andbug bounty program management. You will support both our internal product engineering teams and customer-facing security programs, ensuring that security is embedded throughout our development lifecycle and that our platform earns the trust of developers … is required. Security Tools & Automation: Hands-on experience with applicationsecurity tooling such as static applicationsecuritytesting (SAST), dynamictesting (DAST), dependency vulnerability scanners, and CI/CD pipeline security integration. Familiarity withGitHub Advanced Securityor similar tools for code scanning and secret detection is a strong plus. Open Source and More ❯
Press space or enter keys to toggle section visibility Location London Job Type Full Time Posted Date 16-Jun-2025 Ref # 62659 We are seeking a Principal Security Engineer to lead and drive security engineering efforts across our cloud and application environments. This strategic, hands-on role requires expertise in cloud security, secure development practices … and the implementation of advanced security controls. You will serve as a leader within the Consumer Security Engineering team, driving security initiatives across cloud platforms, microservice architectures, digital products, applicationsecurity, and enterprise security. You will define and build comprehensive security strategies in collaboration with developers, DevSecOps engineers, ensuring that security is seamlessly … plus. Strong background in DevSecOps, with experience in integrating security into CI/CD pipelines using tools like Jenkins, GitLab, or similar. Experience implementing and managing SAST/DAST tools and processes to secure application development. Deep understanding of applicationsecurity, including secure coding practices, OWASP Top 10, and API security standards. Knowledge of Customer More ❯
Senior Security Engineer We are seeking an experienced Senior Security Engineer to join our dynamicSecurity Team. In this key role, you will be a key contributor to Funding Circle's cloud and applicationsecurity posture. You will leverage your deep expertise in AWS security, secure software development lifecycle (SSDLC) practices, and CI …/CD security to implement and champion robust security solutions. You will act as a subject matter expert and mentor, collaborating closely with engineering and product teams to embed security seamlessly into our cloud infrastructure and development processes, ensuring the protection of our platform and customer data in a fast-paced FinTech environment. Who are we? We … demonstrable expertise in designing, implementing, securing, and managing a wide range of AWS security services . Proven, hands-on experience architecting, building, and integrating security tooling (SAST, DAST, SCA, secrets management, IAST) and automated security controls within CI/CD pipelines (e.g., GitLab CI, Jenkins, GitHub Actions). Strong track record of defining, implementing, measuring, and supporting More ❯
Role overview: Working for a security vendor, the Security team are accountable for the company's Information Security, Security Architecture, Security Compliance, Security Awareness, Security Operations and Information Security Risk Management Activities. You'll work closely with development and operational teams to design, implement/recommend applicationsecurity controls. This … is a new role for the company requiring a passion for cyber security and a hands-on development background to create and develop the applicationsecurity capabilities as part of the SDLC. Ideally you will have a background in software development. Main tasks and responsibilities: Assess and identify gaps in current applicationsecurity controls and … of OWASP Top 10, SANS Top 25 etc Experience working in AWS/Azure/GCP would be beneficial Knowledge of Ci/CD pipelines Thorough understanding of SAST, DAST (including fuzzing), endpoint and perimeter scanning etc. Familiarity with industry security standards (ISO27001, NIST, CCM etc) Network and infrastructure experience. API gateway security, WAF and IDS, SSO, SAML More ❯
You'll Be Working On: ️ Implementing secure development practices and conducting threat modeling for software applications ️ Performing static and dynamicapplicationsecuritytesting (SAST/DAST) to identify vulnerabilities in code ️ Collaborating with DevOps and development teams to integrate security into the CI/CD pipeline ️ Conducting regular applicationsecurity assessments, including penetration … testing and vulnerability scanning ️ Providing guidance and training to development teams on secure coding practices and security tools What We're Looking For: ️ Proven experience as an ApplicationSecurity Specialist or in a … similar applicationsecurity role ️ Strong knowledge of secure coding practices, common vulnerabilities (e.g., OWASP Top 10), and applicationsecuritytesting tools ️ Experience with SAST, DAST, and security code review tools (e.g., Fortify, Veracode, Checkmarx) ️ Familiarity with secure software development frameworks (e.g., OWASP, NIST) ️ Relevant certifications such as CSSLP, CEH, or CISSP are highly desirable More ❯
Senior ApplicationSecurity Engineer Department: Engineering Employment Type: Permanent - Full Time Location: London Reporting To: Sami Eltamawy Compensation: £80,000 - £90,000/year Description London, office-based Freetrade's mission is to become the default place to invest. Investing has been too complicated and expensive for too long, keeping millions from making the most of their savings. … like mutual funds, bonds, and family investment tools. We're also exploring how we can leverage AI to deliver an even better experience for our customers. As a Senior Security Engineer , you'll lead the charge in building and scaling our ApplicationSecurity (AppSec) program from the ground up. Your mission will be to embed security … box, and white-box testing to detect and eliminate vulnerabilities. Test all user-facing surfaces (web, Android, iOS) and backend APIs for security weaknesses. Manage SAST and DAST Findings: Drive effective triage and resolution of security test results, improving signal-to-noise ratios. Perform Threat Modelling: Use frameworks like STRIDE to proactively uncover potential threats and define More ❯
Milan, Edinburgh and Madrid. With our focus on growth in the UK and Europe, now is the perfect time to join us on this high-speed journey. Introducing our Security We focus on designing, implementing, and monitoring security controls to ensure a robust security posture in a fast-evolving environment. As part of our mission to continuously … implement effective countermeasures. Proactively assess the security posture of applications through code reviews, manual penetration testing, and static/dynamicsecuritytesting (SAST/DAST). Security Tooling and Automation : Implement and maintain security tools used in the development and deployment processes (e.g., scanning tools, vulnerability management systems, SAST, DAST, ASPM). Automate … understanding of identifying, assessing, and mitigating security risks in application designs, code, and deployed products. Experience managing and using securitytesting tools such as SAST, DAST, and vulnerability scanning solutions. Strong grasp of secure coding practices and proficiency in integrating security into the Software Development Lifecycle (SDLC). Technical Knowledge and Implementation experience: Direct experience More ❯
RMM Service Automation Platform and has a proven track record of helping MSPs standardize and automate the setup and delivery of IT services to achieve true scalability. The Senior ApplicationSecurity Engineer plays a critical role in enhancing our applicationsecurity posture by conducting advanced security assessments, leading security initiatives, and collaborating with development … teams to integrate security into the software development lifecycle. The position plays a key role in identifying and mitigating security vulnerabilities to protect our applications and data. This role is based in our Edinburgh hub. What You'll Do Assist in maturing organizational processes that drive complex security efforts for internal teams and external partners. Develop and … preferred Thorough understanding of OWASP Top 10 and Secure Development Expertise in automating security tools and integrations, including simple scripting Experience with applicationsecurity tools (SAST, DAST, IAST and SCA) Strong technical knowledge of development and production release process, including CI/CD Experience with the application of threat modeling and other risk identification techniques Scripting More ❯
Senior ApplicationSecurity Engineer page is loaded Senior ApplicationSecurity Engineer Apply locations London, UK time type Full time posted on Posted 2 Days Ago job requisition id JR100290 Who we are We're the people behind the global loyalty currency, Avios, and home to three ambitious, growing businesses;IAG Loyalty, British Airways Holidays andThe Wine … CI/CD pipelines, facilitate threat modelling sessions, and review security-sensitive design decisions around authentication, cryptography, and logging. You'll also ensure that tools such as SAST, DAST, and SCA are effective and efficient, and that testing programmes - including pen testing, vulnerability scanning, and bug bounty - are delivering value. You'll triage vulnerabilities, support engineering teams … including the OWASP Top 10 Proficient in coding, scripting (e.g. Python, Bash), and automating security in CI/CD Hands-on experience with security tools like SAST, DAST, and SCA Familiar with cloud environments (especially AWS), containers, and microservices Comfortable reviewing technical designs, performing threat modelling, and advising on secure architecture Strong communicator who collaborates well with engineers More ❯
Gartner and Forrester, and our sustained, aggressive growth has landed Smarsh in the annual Inc. 5000 list of fastest-growing American companies since 2008. We're seeking a Product Security Engineer to support secure development across our engineering teams. In this hands-on role, you'll help identify and mitigate product risks by participating in security reviews, improving … tooling, and supporting vulnerability remediation. You'll work closely with senior security engineers and cross-functional teams to build security into our software development lifecycle. This is a great opportunity for a security-minded engineer who wants to grow their technical breadth while making meaningful impact in a cloud-first, DevOps-centric environment. You must be comfortable … Conduct structured threat modeling and security assessments for new features, architectures, and services. Vulnerability Management & Remediation: Work closely with engineering teams to identify and remediate vulnerabilities from SAST, DAST, SCA, container security, and cloud security scans. Code & Architecture Review: Conduct secure code reviews and architectural security assessments to identify risks early in the development process. Automation More ❯
Leeds, Yorkshire, United Kingdom Hybrid / WFH Options
Junglee Games India Private Limited
Product Security Architect page is loaded Product Security Architect Apply locations Leeds, UK Dublin, Ireland posted on Posted 14 Days Ago job requisition id JR129906 Product Security Architect Product Security Architect Location - Leeds/Dublin Hybrid - 2 days per week At Flutter, Product Security encompasses not just application code, but also infrastructure as code … enterprise embed security into the product development lifecycles. This role is the key advisor on AppSec standards, secure development practices, threat modelling, and security tooling (e.g. SAST, DAST, SCA, IaC scanning, container security, etc.), ensuring consistency and maturity in how applications are built and maintained. By aligning teams with modern DevSecOps principles, developer enablement, and security … development of a global secure development policy, including approved tools, practices, and coding standards. Technology & Tooling Strategy: Evaluate, recommend, and support the rollout of AppSec tools such as SAST, DAST, SCA, container and IaC scanners, runtime protections, and CI/CD pipeline integrations. Collaborate with platform and DevOps teams to ensure tool integration and automation into developer workflows across brands. More ❯
Salesforce Security Engineer Salary : £85,000 Locations: Leeds, Manchester, Redhill, Tunbridge Wells, Bournemouth, or Bristol (Hybrid/Flexible) We're looking for a Salesforce Security Engineer who brings strong engineering fundamentals and hands-on experience to the intersection of Salesforce development and security engineering . You'll play a critical role in enhancing the security posture … principles to assess and uplift Salesforce security maturity. Own and improve pipeline security including static code analysis (SAST), dynamicapplicationsecuritytesting (DAST), dependency checks, and secure deployment patterns. Conduct threat modelling for Salesforce-based estates, identifying and mitigating risks early in the development lifecycle. Perform and refine security tests across APIs … Bring Hands-on experience with Salesforce development (particularly APEX) and a deep understanding of how engineering and security intersect. Strong grasp of secure coding practices and experience running DAST/SAST on Salesforce environments. Exposure to or working knowledge of DSOMM , OWASP, and threat modelling methodologies. Experience integrating security into CI/CD pipelines , especially in complex enterprise More ❯
Salesforce Security Engineer Salary : £85,000 Locations: Leeds, Manchester, Redhill, Tunbridge Wells, Bournemouth, or Bristol (Hybrid/Flexible) We're looking for a Salesforce Security Engineer who brings strong engineering fundamentals and hands-on experience to the intersection of Salesforce development and security engineering . You'll play a critical role in enhancing the security posture … principles to assess and uplift Salesforce security maturity. Own and improve pipeline security including static code analysis (SAST), dynamicapplicationsecuritytesting (DAST), dependency checks, and secure deployment patterns. Conduct threat modelling for Salesforce-based estates, identifying and mitigating risks early in the development lifecycle. Perform and refine security tests across APIs … Bring Hands-on experience with Salesforce development (particularly APEX) and a deep understanding of how engineering and security intersect. Strong grasp of secure coding practices and experience running DAST/SAST on Salesforce environments. Exposure to or working knowledge of DSOMM , OWASP, and threat modelling methodologies. Experience integrating security into CI/CD pipelines , especially in complex enterprise More ❯
Cardiff, South Glamorgan, Wales, United Kingdom Hybrid / WFH Options
Hoop Recruitment
Senior Test Engineer (Security) Location: Remote (UK-based) | Contract: PermanentSalary: £40,398 – £51,398 + excellent public sector benefitsWe’re proud to be working with a UK government organisation as they continue their digital transformation journey. They’re now looking to appoint a Senior Test Engineer (Security) to lead and enhance their non-functional testing capability.This is … a fantastic opportunity to work in a supportive, agile environment that prioritises innovation, collaboration and work-life balance. Key responsibilities: Deliver and support securitytesting workstreams, including vulnerability assessments and penetration testing. Lead on best practice in securitytesting and provide guidance to fellow testers. Collaborate closely with developers and delivery teams throughout the software development … lifecycle. Contribute to the design and implementation of automated securitytesting pipelines. Essential skills and experience: Proven experience in security testing. Certification in ethical hacking or penetration testing (e.g. 7Safe CSTA, GIAC), or currently working towards one. Working knowledge of at least five of the following: Burp Suite, OWASP ZAP, Postman, OAuth2/OpenID Jenkins or More ❯
see why Glassdoor and Comparably have recognized CaptivateIQ as a best place to work! About the role: Join our Cybersecurity Team and play a pivotal role in strengthening the security of our infrastructure, applications, and services. As a Security Engineer, you will apply your technical expertise across engineering, applicationsecurity, and incident response to help scale … and mature our security posture. This is a hands-on role that requires a collaborative mindset, strong problem-solving skills, and the ability to identify and respond to security challenges across attack surfaces. You'll work closely with Engineering, Product, and IT teams to embed security across the product lifecycle, triage and mitigate vulnerabilities, and proactively respond … scans, and targeted penetration tests of applications and infrastructure using common security tooling (e.g., Burp Suite, ZAP, Amass, Nmap). Assess and mitigate static (SAST) and dynamic (DAST) vulnerabilities across services and components. Evaluate, implement, and maintain security tooling to support vulnerability management, secure development, and event detection workflows. Define and track metrics related to applicationMore ❯
Cardiff, South Glamorgan, Wales, United Kingdom Hybrid / WFH Options
Hoop Recruitment
Lead Test Engineer (Security) Location: Remote (UK-based) | Contract: Permanent Salary: £41,571 – £56,784 We’re delighted to be supporting a UK government organisation as they continue to transform their digital services. They are now seeking a Lead Test Engineer (Security) to take ownership of the securitytesting strategy across their platforms.This is an opportunity … to lead, mentor, and influence securitytesting practices in an agile, forward-thinking digital department with a strong focus on public value, collaboration, and continuous improvement.Key responsibilities Lead the organisation’s approach to non-functional securitytesting across the full software development lifecycle. Manage and support a team of testers, providing coaching, mentoring, and oversight of … OWASP ZAP, Postman or SOAP UI, OAuth2/OpenID Jenkins/Concourse, Unix/Linux, AWS SQL/MongoDB/Oracle, Git, Karate DSL or Rest Assured SAST/DAST tools, IaC scanning, secrets detection tools Threat modelling (e.g. STRIDE, PASTA), OWASP Top 10 testing Salary & benefits Base salary: £41,571 – £45,784 DDaT allowance More ❯
The Cyber Security Architect will work closely with the solution architects and enterprise architects to improve and maintain the cyber security of NAVBLUE'S products, services and infrastructure. The ideal candidate will play a critical role in designing and implementing cybersecurity frameworks to align with the business objectives and mitigate potential threats. Main Responsibilities: Perform Security Risk … and Threat analysis during the initial design and the Software Development Life Cycle planning, analysis, and design phases. Providing recommendations and requirements for mitigating any security weaknesses identified while defining Non-Functional Requirements in coordination with Solutions Architects. Ensure Security by Design is embedded within the Software Development Life Cycle, while ensuring that all security requirements have … knowledge of the SDLC and AWS network architecture Knowledge of the SAFe Agile method would be an asset Understanding of securitytesting in the software pipeline (SAST, DAST, SCA, RASP) Knowledge of STRIDE, DICE and other threat and risk frameworks Knowledge of AWS tools Proven experience managing multiple projects simultaneously Practical interpersonal skills; adaptable to all levels of More ❯
The Cyber Security Architect will work closely with the solution architects and enterprise architects to improve and maintain the cyber security of NAVBLUE'S products, services and infrastructure. The ideal candidate will play a critical role in designing and implementing cybersecurity frameworks to align with the business objectives and mitigate potential threats. Main Responsibilities: Perform Security Risk … and Threat analysis during the initial design and the Software Development Life Cycle planning, analysis, and design phases. Providing recommendations and requirements for mitigating any security weaknesses identified while defining Non-Functional Requirements in coordination with Solutions Architects. Ensure Security by Design is embedded within the Software Development Life Cycle, while ensuring that all security requirements have … knowledge of the SDLC and AWS network architecture Knowledge of the SAFe Agile method would be an asset Understanding of securitytesting in the software pipeline (SAST, DAST, SCA, RASP) Knowledge of STRIDE, DICE and other threat and risk frameworks Knowledge of AWS tools Proven experience managing multiple projects simultaneously Practical interpersonal skills; adaptable to all levels of More ❯
Almondsbury, Gloucestershire, United Kingdom Hybrid / WFH Options
Frontier Resourcing
My growing defence client is seeking a Security Engineer. You'll join a leading organisation that develops cutting edge products and technology. Role Purpose You'll own the security posture across our client's product portfolio-encompassing software, hardware, and services-by embedding robust security controls throughout the development lifecycle, identifying and mitigating risks, and ensuring compliance … tests and automated vulnerability scans; validate fixes. Oversee third-party security assessments as required. Continuous Improvement Drive security tooling and automation (CI/CD integration, SAST/DAST). Stay ahead of emerging threats and security technologies; evangelise best practices across teams. Qualifications & Experience Proven experience (5+ years) in product or applicationsecurity within defence …/31000, NIST 800-series) and Defence Standards (JSPs, Def Stan 05-138/139). Hands-on experience with securitytesting tools and techniques (SAST, DAST, penetration testing). Eligible for UK SC clearance; right to work in the UK. Why Join? You'll Gain exposure to cutting-edge defence technology and intelligence insights. Good salary More ❯
Job Summary We are seeking a pragmatic and highly skilled DevSecOps Engineer to join our Platform team. In this role, you will be responsible for identifying, prioritising and remediating security issues as a security engineer and lead analyst to support the broader organisation. You will collaborate closely with Platform, Infrastructure, Development and Security teams to embed security … code and infrastructure reviews. Develop and execute incident response procedures, leveraging Sentinel playbooks and Logic Apps when required. CI/CD & Automation Integrate automated securitytesting (SAST, DAST, SCA) into Azure DevOps pipelines or GitHub Actions. Create Infrastructure as Code (IaC) with Terraform or ARM templates, embedding security checks. Automate security operations tasks using Azure Functions … Ability to design and enforce patch windows and remediation SLAs. DevSecOps Toolchain Proficient with CI/CD tooling in Azure DevOps or GitHub Actions. Experience integrating SAST (e.g. SonarQube), DAST (e.g. OWASP ZAP) and SCA (e.g. Dependabot, Snyk) into pipelines. Infrastructure as Code: Terraform, ARM or Bicep. Container & Cloud Security Knowledge of containerisation (Docker, Kubernetes/AKS) and container More ❯
challenges. We are dedicated to consistently updating our job descriptions to ensure we continue to lead in banking innovation. How you will contribute and key responsibilities: As a Senior Security Engineer, you will be instrumental in designing and implementing security measures for our mobile applications, services, and websites to meet the highest security standards. Your expertise will … help us continuously analyse and improve our security systems, ensuring that our products and services are not only secure by design but also comply with internal and external regulatory requirements. Other responsibilities include: Security Analysis and Improvement: Continuously analyse our security systems for potential improvements, ensuring that our defences remain at the forefront of cybersecurity practices. Vulnerability … driven streaming technologies, Logging and monitoring, networks, firewalls, load balancers, DNS, CDNs, Working knowledge of agile DevSecOps environments, and CI/CD (Git, Concourse, Terraform), Working knowledge of SAST, DAST, RASP, and IAST tools and building security into existing SDLC processes, Knowledge of cloud Security Architecture of public clouds (such as AWS or GCP), Security certification such More ❯
continuously evolving our recruitment processes to ensure fairness and are open to accommodating any needs you might have. If, due to a disability, you need adjustments to complete the application, please let us know by sending an email with your name, the role to which you would like to apply, and the type of support you need to complete … the application to . For any other non-disability related questions, please reach out to our Talent Partners. The Role In 2025 we are investing in improving security capabilities to our Engineering & Data group. We are looking for a security engineer to guide our engineering practices, improve security in our software delivery lifecycle, and work closely … for security incidents Requirements Experience with developing APIs and Frontend applications Experience architecting secure systems at scale Experience integrating securitytesting into the SDLC i.e. SAST, DAST, SCA Experience with vulnerability scanning and software patching at scale Experience working with at least one major cloud provider (AWS specifically is advantageous) Strong networking foundations Experience with infrastructure as More ❯
Gartner and Forrester, and our sustained, aggressive growth has landed Smarsh in the annual Inc. 5000 list of fastest-growing American companies since 2008. We're seeking a Product Security Engineer to support secure development across our engineering teams. In this hands-on role, you'll help identify and mitigate product risks by participating in security reviews, improving … and backlog grooming. Threat Modelling : Participate in structured threat modelling exercises with guidance from senior team members. Vulnerability Triage : Work with engineering teams to review findings from SAST, SCA, DAST, and container scans and track remediation progress. Code & Config Review : Conduct basic secure code and configuration reviews, escalating high-risk findings as needed. Security Tooling & Automation : Help maintain and … JavaScript, Go, or C#). Familiarity with cloud platforms (AWS, Azure, or GCP) and container technologies (Docker, Kubernetes). Exposure to security tooling such as SAST, SCA, or DAST scanners (e.g., Semgrep, Endor, Burp). Basic understanding of identity and access controls (OAuth, SAML, API tokens). Strong collaboration and communication skills, with a willingness to learn and grow. More ❯
Pre Sales Application Architect + Permanent opportunity + On-site in Bracknell/Basingstoke + SC cleared role + Salary: £75,000 + £6,000 Car allowance + 10% bonus This role involves creating design artefacts that enable the deployment of Applications using industry-standard methodologies. You will collaborate closely with Solution Owners and Project Managers to ensure solutions … Archimate (BizzDesign preferred) Requirements Modelling/Capture techniques such as User Stories and Use Cases AWS and Azure Cloud usage VMWare usage Technical Leadership & Design DevSecOps tooling and practices ApplicationSecurityTesting SAFe (scaled agile) Processes Data Integration Focused: Data Pipeline Orchestration and ELT tooling such as Apache Airflow, Apache NiFi, Airbyte, and Singer Message Brokers and … Microservices Automated Test tooling, ideally Selenium or Robot Framework DevSecOps Key Skills: CI/CD Pipelines, ideally Azure DevOps IaC tooling, including Terraform, Ansible, Harbor SCA/IAST/DAST tooling, e.g., Black Duck, Coverity, JFrog, Snyk Automated Test tooling, ideally Selenium or Robot Framework Test Management Tools, ideally Azure Test Plans Secure Secrets Management, ideally with Azure DevOps and More ❯