22 of 22 Permanent Static Application Security Testing Jobs in the UK

Senior Application Security Engineer / DevSecOps Engineer

Hiring Organisation
Additional Resources
Location
London, United Kingdom
Employment Type
Permanent
Salary
£80000 - £90000/annum
have a background in Application Security, DevSecOps or Product Security, with hands-on experience embedding application security into the SDLC If so, this could be an opportunity worth considering. Join a well-established health research organisation and charity supporting large-scale medical research. You will … controls and cloud security governance. Experience with KQL. Experience securing APIs, internet-facing services, Kubernetes, preferably AKS, and containerised environments. Experience with SAST, DAST, IAST and SCA. Knowledge of security automation, security-/policy-as-code and secure engineering practices. Familiarity with GitHub and GitHub Actions. ...

DevSecOps Engineer

Hiring Organisation
Oscar Associates (UK) Limited
Location
Surrey, South East, United Kingdom
Employment Type
Permanent
Salary
£80,000
VNets, Private Endpoints and Front Door/WAF Introducing deployment practices such as blue/green releases, automated rollback and infrastructure drift detection Integrating SAST, DAST, dependency and container scanning into development pipelines Conducting web application security testing using Burp Suite, OWASP ZAP or similar tools Identifying … securing web applications in a production environment Practical experience using Burp Suite for application security testing Experience with SonarQube or comparable SAST tooling Strong knowledge of OWASP Top 10, vulnerability management and remediation Experience building repeatable Azure deployments using Terraform Scripting ability with PowerShell, Python or Bash ...

Application Security Engineer

Hiring Organisation
DGH Recruitment
Location
City of London, London, United Kingdom
Employment Type
Permanent
Salary
£75,000
threat modelling and review application architectures - Implement application security controls and proactive measures to prevent security incidents - Implement and manage SAST/SCA tooling across application repositories to identify source code risks - Scale automated DAST solutions across applications to maximise testing coverage - Carry … software development or experience contributing to Open-Source projects - Experienced with DAST tools such as Burp Suite, OWASP Zap or similar - Experience with SAST/SCA tools such as Snyk, Veracode, Checkmarx or similar - Proficient in one or more of the following languages - Python, JavaScript, .NET or Java - Demonstrated experience ...

Senior Security Engineer

Hiring Organisation
Hackajob Ltd
Location
Birmingham, West Midlands, United Kingdom
Employment Type
Permanent
Salary
£90,000
diverse, ambitious team that celebrates creativity and collaboration. Ready to make your mark? Join us and be part of something bigger. As a Senior Security Engineer, you will work in close collaboration with our technology teams to design and implement secure, cloud-based software solutions for our clients. Working … development lifecycle, embedding security practices (e.g. vulnerability management, threat modelling etc.) and automating security artifact generation (e.g. secret scanning, container security, SAST, DAST etc.). You will provide subject matter expertise in application security or cloud security sharing knowledge on threats and vulnerabilities, identifying ...

Security Engineer

Hiring Organisation
Tiro Partners Limited
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
£60,000 - £90,000 per annum
Security/Python/DevSecOps/Azure/Security Engineer Role: Senior Application Security Engineer Remote UK | 1 day per week in London Salary: Up to £85,000 We’re looking for a Senior Application Security Engineer to join our security team … build secure applications and platforms. The role Embed security into the SDLC and CI/CD pipelines, including GitHub Actions. Implement and operate SAST, DAST, IAST and SCA tooling. Secure applications, APIs, Kubernetes and containers. Develop security and policy-as-code capabilities using tools such as OPA. Help ...

Application Security Engineer

Hiring Organisation
Hackajob Ltd
Location
South West London, London, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£85,000
doing: Were on a mission to build a tech-forward, secure environment that empowers developers rather than putting roadblocks in their way. As an Application Security Engineer, youll act as a core technical guide across our software development lifecyclehelping us embed security directly into our code … technical mentor. Integrate security assessments, code reviews, and penetration testing seamlessly into the SDLC. Evaluate, implement, and run modern security tooling (SAST, DAST, IAST) to streamline vulnerability checks. Research emerging AI and LLM threat classes to design proactive, cutting-edge defensive architectures. Participate in incident response investigations ...

Cyber Security Technical Project Manager B2B SaaS, AWS, Agile

Hiring Organisation
Smart Sourcer Limited
Location
City of London, London, United Kingdom
Employment Type
Permanent
Cyber Security Technical Project Manager B2B SaaS, AWS, Agile, Global Security Hardening Outstanding opportunity for a technical Cyber Security Project Manager to join this global B2B SaaS business to drive delivery across a global Security Hardening programme . Youll work with the Technical Operations Director, CISO …/SAML, MFA, RBAC Cloud Security: AWS security controls, CSPM, VPC security, encryption AppSec: Snyk, GitHub Advanced Security, SAST/DAST, secrets management, API security Endpoint: CrowdStrike, SentinelOne Network: WAF, CDN security, Zero Trust Network Access Data Security: DLP, SIEM/SOAR, logging ...

Application Security Engineer

Hiring Organisation
Hackajob Ltd
Location
South West London, London, United Kingdom
Employment Type
Permanent
hundreds of thousands of restaurant, grocery and convenience partners across the globe. About this role At Just Eat Takeaway.com, weve built a world-class security team that believes passionately in protecting our products, as well as the data of our customers and employees. As an application security … technology Detailed knowledge of OWASP Top 10, and in relation how to design appropriate security controls Experience working with Secure Coding Tools (SCA, SAST & Secrets) Experience in identifying & addressing vulnerabilities throughout SDLC, with the ability to switch between defensive & offensive mindset Experience securing AI-enabled applications and assessing common ...

DevSecOps Engineer

Hiring Organisation
Digital Waffle
Location
Manchester, England, United Kingdom
Location: London, Gloucester or Manchester (Hybrid) Salary: Up to £100,000 + Benefits Security Clearance: Active SC Clearance required We're working with a leading technology organisation supporting critical government and defence programmes, who are looking to hire an experience d DevSecOps Engine er to join their growing cyber … secure cloud infrastructure across AWS, Azure and/or GCP Implement Infrastructure as Code (Terraform, CloudFormation or similar) Automate security testing including SAST, DAST, SCA and container scanning Improve container and Kubernetes security through best practice implementation Work closely with development teams to identify and remediate security ...

DevSecOps Engineer

Hiring Organisation
Digital Waffle
Location
Gloucestershire, England, United Kingdom
Location: London, Gloucester or Manchester (Hybrid) Salary: Up to £100,000 + Benefits Security Clearance: Active SC Clearance required We're working with a leading technology organisation supporting critical government and defence programmes, who are looking to hire an experience d DevSecOps Engine er to join their growing cyber … secure cloud infrastructure across AWS, Azure and/or GCP Implement Infrastructure as Code (Terraform, CloudFormation or similar) Automate security testing including SAST, DAST, SCA and container scanning Improve container and Kubernetes security through best practice implementation Work closely with development teams to identify and remediate security ...

Lead Security Assurance Engineer

Hiring Organisation
Hackajob Ltd
Location
Bristol, Avon, South West, United Kingdom
Employment Type
Permanent, Part Time, Work From Home
Salary
£90,000
severity, backlog age, coverage, recurrence rate) to senior stakeholders. Drive security into the team's normal rhythm. Embed threat modelling, secure code review, SAST, SCA, dependency policy, and container scanning into design and delivery cycles - making security a shared engineering responsibility rather than a specialist handover … practice familiarity Familiarity with structured threat modelling approaches - STRIDE, MITRE ATT&CK, attack trees - and experience embedding these into agile delivery ceremonies Experience integrating SAST, SCA, dependency scanning, and container security tooling into CI/CD pipelines as part of a shift-left security approach Made Tech sponsors ...

Lead Software Engineer- Tax & Legal Technology -108720

Hiring Organisation
KPMG UK
Location
London, UK
Used source control and continuous integration tools as part of a team Security Practices: An understanding of application security controls like SAST, DAST, Penetration Testing, etc. Quality Focus: A DevSecOps mindset with focus on delivering value quickly and frequently What will you be doing? Deep Technical … entity framework code first data with Azure SQL or a NoSQL Databases Enterprise Expertise: Build resilient Microservice integrated via a Cloud message bus Security Practices: Comply with secure coding & infrastructure standards and policies Continuous Delivery: Assist with supporting your application using modern DevSecOps tools Quality Focus: Continuously improve ...

Lead Software Engineer- Tax & Legal Technology –108720

Hiring Organisation
KPMG UK
Location
City of London, London, United Kingdom
Used source control and continuous integration tools as part of a team Security Practices: An understanding of application security controls like SAST, DAST, Penetration Testing, etc. Quality Focus: A DevSecOps mindset with focus on delivering value quickly and frequently What will you be doing? Deep Technical … entity framework code first data with Azure SQL or a NoSQL Databases Enterprise Expertise: Build resilient Microservice integrated via a Cloud message bus Security Practices: Comply with secure coding & infrastructure standards and policies Continuous Delivery: Assist with supporting your application using modern DevSecOps tools Quality Focus: Continuously improve ...

DevSecOps Engineer - AI

Hiring Organisation
HCLTech
Location
London Area, United Kingdom
Privacy Notice. This is a hybrid opportunity requires 3 days/week onsite in London. Overall profile we're hiring Senior DevSecOps Engineer Cloud Security Engineer DevSecOps Architecture Security Platform Engineer Ideal candidate summary: Someone … with 8–12+ years of experience who has: Deep DevSecOps implementation experience using AI GCP and Kubernetes expertise CI/CD security implementation SAST, DAST, SCA, SonarQube and Checkmarx hands-on experience Vulnerability management ownership Container and cloud security Security automation and compliance Ability to answer deep ...

Harness

Hiring Organisation
Avance Consulting
Location
City of London, London, United Kingdom
team. We’re seeking a seasoned Harness Platform Specialist with deep expertise across the Harness Software Delivery Platform, including Continuous Integration, Continuous Delivery, Security Testing Orchestration (STO), Chaos Engineering, Cloud Cost Management (CCM), and Harness AI Agents. The ideal candidate will bring hands on experience in designing scalable … pipeline templates. Drive application onboarding to Harness, including assessments, pipeline configuration, troubleshooting, and modernization support (containerization, IaC adoption). Integrate security scanners (SAST, SCA, DAST, container scanning) through Harness STO and enforce governance and compliance using OPA policies. Leverage Harness AI Agents to automate pipeline triaging, self‐healing ...

Forward Deployed Engineer

Hiring Organisation
MarkIT Placements
Location
Bristol, Avon, South West, United Kingdom
Employment Type
Permanent, Work From Home
there is a genuine use case. Production & Engineering You'll own solutions all the way into production, including: Infrastructure and deployment. AI evaluation and testing frameworks. MCP server implementation. Cloud deployment across … Azure, Cloudflare or Vercel . Docker, Kubernetes and/or serverless architectures. TDD and robust software engineering practices. Security, secrets management and SAST/DAST. Structured logging, monitoring, metrics and tracing. Automated CI/CD using tools such as GitHub Actions or Jenkins . Performance, scalability and cost optimisation. ...

Product Manager

Hiring Organisation
AppCheck Ltd
Location
Leeds, England, United Kingdom
love to hear from you. About AppCheck: AppCheck helps organisations identify and manage cyber risk across web applications, APIs and infrastructure. AppCheck develops information security software that provides clients with vulnerability detection and reporting services for web applications and hosted infrastructure. We provide unparalleled detection across … experience in the cybersecurity industry in either a technical or commercial capacity; experience with automated security testing technologies such as DAST/SAST is an advantage but not a must. Experience of working with SaaS/reseller networks. Experience of driving product delivery for users in the global ...

Senior Vulnerability Management Engineer

Hiring Organisation
HCLTech
Location
London Area, United Kingdom
www.hcltech.com Job Title : Senior Vulnerability Management Engineer Location: London, UK ( Hybrid mode at client location ) Experience: 3 – 6 years in vulnerability management/information security ROLE SUMMARY The L2 Senior Vulnerability Management Engineer owns the organisation's end-to-end vulnerability management programme, spanning EUC, Data Center, Network … estate, co-ordinate emergency patching or compensating controls, and communicate status to security leadership. • Own web application vulnerability management: integrate DAST/SAST findings (Burp Suite, Checkmarx, Veracode) into the unified VM programme. • Manage cloud vulnerability posture: AWS Inspector, Microsoft Defender for Cloud, or Prisma Cloud for hybrid ...

Senior Vulnerability Management Engineer

Hiring Organisation
HCLTech
Location
Birmingham, England, United Kingdom
days work from office Mode of contract: This is Fixed term contract(FTC or FTE) Experience 3 – 6 years in vulnerability management/information security Education B.Tech (Computer Science/Cybersecurity/IT) or equivalent ROLE SUMMARY The L2 Senior Vulnerability Management Engineer owns the organisation … estate, co-ordinate emergency patching or compensating controls, and communicate status to security leadership. Own web application vulnerability management: integrate DAST/SAST findings (Burp Suite, Checkmarx, Veracode) into the unified VM programme. Manage cloud vulnerability posture: AWS Inspector, Microsoft Defender for Cloud, or Prisma Cloud for hybrid ...

Platform Engineer

Hiring Organisation
Richmond Square Consulting Limited
Location
Cheltenham, Gloucestershire, South West, United Kingdom
Employment Type
Permanent, Work From Home
securely and efficiently. The environment is highly technical, fast-moving and low on unnecessary bureaucracy, with the opportunity to work on complex projects where security, performance and reliability genuinely matter. Package £100,000+ basic salary Discretionary bonus Benefits package Hybrid working Cheltenham Training and professional certification opportunities Exposure … secure software delivery Experience building Internal Developer Platforms (IDPs) or developer enablement platforms would be particularly interesting. Exposure to tools or concepts including Coder, SAST, DAST, SBOM generation, vulnerability scanning or policy-as-code would also be advantageous. AWS certification at Associate level or above would be beneficial ...

Platform Engineer

Hiring Organisation
Richmond Square Consulting Limited
Location
Salford, Greater Manchester, North West, United Kingdom
Employment Type
Permanent, Work From Home
securely and efficiently. The environment is highly technical, fast-moving and low on unnecessary bureaucracy, with the opportunity to work on complex projects where security, performance and reliability genuinely matter. Package £100,000+ basic salary Discretionary bonus Benefits package Hybrid working Cheltenham Training and professional certification opportunities Exposure … secure software delivery Experience building Internal Developer Platforms (IDPs) or developer enablement platforms would be particularly interesting. Exposure to tools or concepts including Coder, SAST, DAST, SBOM generation, vulnerability scanning or policy-as-code would also be advantageous. AWS certification at Associate level or above would be beneficial ...

Lead FDE Production & Consulting

Hiring Organisation
Newpage Solutions
Location
City Of Bristol, England, United Kingdom
where current AI tooling helps and where it falls short. Apply engineering practices that hold up in production: TDD, secrets management and rotation,SAST/DAST, structured logging, metrics, tracing, and automated CI/CD (GitHub Actions, Jenkins). Own what you build end-to-end, including the infrastructure … tools (Claude Code, Cursor, GitHub Copilot) with demonstrable workflows, sub-agents, skills, and innovative approaches. Strong Python or TypeScript, with OOP, SOLID, 12-factor application development, and microservice architecture. You've built Next.js applications, FastAPI services, and similar. End-to-end implementation experience with vector databases, retrieval pipelines ...