Permanent OWASP Jobs in Wales

23 of 23 Permanent OWASP Jobs in Wales

Software Engineer in Test

cardiff, United Kingdom
Hybrid / WFH Options
SecureFlag
control). Knowledge of SQL and experience verifying backend data consistency. Familiarity with containerized environments (Docker, Kubernetes). Familiarity with tools like Burp Suite, OWASP ZAP, or static analysis tools is a plus. What We Offer Competitive salary and benefits package. Opportunities for learning, growth, and contributing to a product More ❯
Posted:

Software Engineer in Test

newport, midlands, United Kingdom
Hybrid / WFH Options
SecureFlag
control). Knowledge of SQL and experience verifying backend data consistency. Familiarity with containerized environments (Docker, Kubernetes). Familiarity with tools like Burp Suite, OWASP ZAP, or static analysis tools is a plus. What We Offer Competitive salary and benefits package. Opportunities for learning, growth, and contributing to a product More ❯
Posted:

Quality Engineer

newport, midlands, united kingdom
Hybrid / WFH Options
Experis
communication skills * Proven team engagement skills * Proven coaching skills * Quality Driven * Adaptable/ability to context switch * Stakeholder Management Optional Skills: * Junit * Playwright * Gatling * OWASP Zap * SonarQube * GitHub Copilot * Wiremock * Wave * Axe * Kubernetes * Docker * Micro-services * AWS * Open API * WCAG * Cucumber/Gherkin * Selenium * Agile Scrum * Agile Practices All profiles More ❯
Posted:

Security Architect

newport, wales, United Kingdom
Matchtech
Proficiency in threat modelling methodologies and tools (e.g., STRIDE, DREAD, Attack Trees) Familiarity with other standards such as ISO/IEC 27001, ISO 27005, OWASP, and MOD ISN 23/09 Ability to identify, assess and mitigate risks across software and hardware product ecosystems Strong written and verbal communication skills More ❯
Posted:

Senior Application Security Engineer

cardiff, United Kingdom
Lawrence Harvey
vulnerabilities. Requirements: 5+ years of hands-on experience in application security and secure software development. Strong knowledge of secure coding practices and common vulnerabilities (OWASP) Experience with SAST, DAST, and IAST tools and integrating them into CI/CD pipelines. Proficiency in writing and reviewing code (JavaScript, Java, Python) with More ❯
Posted:

Senior Application Security Engineer

newport, midlands, United Kingdom
Lawrence Harvey
vulnerabilities. Requirements: 5+ years of hands-on experience in application security and secure software development. Strong knowledge of secure coding practices and common vulnerabilities (OWASP) Experience with SAST, DAST, and IAST tools and integrating them into CI/CD pipelines. Proficiency in writing and reviewing code (JavaScript, Java, Python) with More ❯
Posted:

Information Security Risk and Consulting Lead

cardiff, United Kingdom
Hybrid / WFH Options
Principality Building Society
Cyber risk assessments, which follow frameworks such as CSF. Interpret and advise on current standards and guidance such as, but not limited to NCSC, OWASP and NIST. Good analytical skills and ability to demonstrate discretion and confidentiality in highly sensitive situations. The ability to work independently and as part of More ❯
Posted:

Information Security Risk and Consulting Lead

newport, wales, United Kingdom
Hybrid / WFH Options
Principality Building Society
Cyber risk assessments, which follow frameworks such as CSF. Interpret and advise on current standards and guidance such as, but not limited to NCSC, OWASP and NIST. Good analytical skills and ability to demonstrate discretion and confidentiality in highly sensitive situations. The ability to work independently and as part of More ❯
Posted:

Penetration Tester

cardiff, United Kingdom
Hybrid / WFH Options
Maxwell Bond
experience. Eligibility for or possession of UK Security Clearance (preferred but not required). Solid understanding of common attack techniques and vulnerability classes (e.g., OWASP Top 10, MITRE ATT&CK). Strong familiarity with tools such as Burp Suite, Nmap, Metasploit, etc. Excellent communication and reporting skills. Required Qualifications: Demonstrable More ❯
Posted:

Penetration Tester

newport, midlands, United Kingdom
Hybrid / WFH Options
Maxwell Bond
experience. Eligibility for or possession of UK Security Clearance (preferred but not required). Solid understanding of common attack techniques and vulnerability classes (e.g., OWASP Top 10, MITRE ATT&CK). Strong familiarity with tools such as Burp Suite, Nmap, Metasploit, etc. Excellent communication and reporting skills. Required Qualifications: Demonstrable More ❯
Posted:

Information Security Manager

newport, wales, United Kingdom
TRIA
audits & penetration testing What You’ll Bring CISSP or equivalent + 6-7 years in InfoSec Experience maturing security programs & frameworks ( ISO27001, NIST CAF, OWASP ) Strong knowledge of SIEM, IDS/IPS, RBAC, vulnerability management Understanding of cloud, COTS/SaaS platforms & IoT security Ability to communicate risks & strategies at More ❯
Posted:

Information Security Risk & Consulting Lead

Cardiff, South Glamorgan, United Kingdom
Principality Building Society
and develop policies in line with regulatory standards. Conduct cyber risk assessments following frameworks like CSF. Interpret and advise on standards such as NCSC, OWASP, and NIST. Maintain discretion and confidentiality in sensitive situations. Work independently and collaboratively within the security team. We are passionate about creating an inclusive workplace More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Product Security Architect

newport, wales, United Kingdom
Advanced Resource Managers
ISN 23/09 Secure by Design Knowledge of security frameworks, such as ISO/IEC 27001, NIST 800-30, NIST 800-53 or OWASP Working with risk management frameworks and methodologies (e.g., ISO 27001/2, ISO27005/31000, NIST 800-30, NIST 800-53) If this all sounds More ❯
Posted:

System Development Manager

cardiff, United Kingdom
Hybrid / WFH Options
TRIA
at rest/in transit, and other application security standards. Ensure software and infrastructure meet organizational security and compliance requirements (e.g., GDPR, ISO 27001, OWASP Top 10). Team Management & Culture Build and scale high-performance engineering teams, including backend, frontend, full-stack, data, and security engineers. Define and track … APIs, ETL, Azure Data Factory DevOps/Infra : CI/CD pipelines (e.g., GitHub Actions, Azure DevOps), containerization, Azure PaaS Security : Secure development lifecycle, OWASP, authentication/authorization protocols Leadership Attributes Technically credible leader with the ability to deep-dive on architecture and code when necessary. Strong decision-making skills More ❯
Posted:

System Development Manager

newport, midlands, United Kingdom
Hybrid / WFH Options
TRIA
at rest/in transit, and other application security standards. Ensure software and infrastructure meet organizational security and compliance requirements (e.g., GDPR, ISO 27001, OWASP Top 10). Team Management & Culture Build and scale high-performance engineering teams, including backend, frontend, full-stack, data, and security engineers. Define and track … APIs, ETL, Azure Data Factory DevOps/Infra : CI/CD pipelines (e.g., GitHub Actions, Azure DevOps), containerization, Azure PaaS Security : Secure development lifecycle, OWASP, authentication/authorization protocols Leadership Attributes Technically credible leader with the ability to deep-dive on architecture and code when necessary. Strong decision-making skills More ❯
Posted:

Cybersecurity Engineer

Newport, Gwent, United Kingdom
KLA-Belgium
Company Overview The SPTS division of KLA designs, manufactures and markets wafer processing solutions for the global semiconductor and related industries. SPTS provides industry leading etch and deposition process technologies on a range of single wafer handling platforms. End-market More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Software Tester / UK

cardiff, United Kingdom
Hybrid / WFH Options
G&L Consulting
/components interact correctly. Test APIs, databases, and service flows. Security Testing & Penetration Testing (Ethical Hacking) Simulate attacks to find vulnerabilities. Tools: Burp Suite , OWASP ZAP , Metasploit . CEH , OSCP , CISSP certifications an advantage Vulnerability Testing Scan systems for known vulnerabilities. Collaborate with SecOps and DevSecOps teams. Security QA/… Secure Code Testing Test software from a secure coding perspective. Ensure compliance with secure development standards (OWASP Top 10, etc.). Test Management Oversee testing across multiple teams and or products. Handle stakeholder communication, budget, vendor selection, and process compliance. Test Architectecture Design testing frameworks, strategies, and toolchains. Advise on More ❯
Posted:

Software Tester / UK

newport, midlands, United Kingdom
Hybrid / WFH Options
G&L Consulting
/components interact correctly. Test APIs, databases, and service flows. Security Testing & Penetration Testing (Ethical Hacking) Simulate attacks to find vulnerabilities. Tools: Burp Suite , OWASP ZAP , Metasploit . CEH , OSCP , CISSP certifications an advantage Vulnerability Testing Scan systems for known vulnerabilities. Collaborate with SecOps and DevSecOps teams. Security QA/… Secure Code Testing Test software from a secure coding perspective. Ensure compliance with secure development standards (OWASP Top 10, etc.). Test Management Oversee testing across multiple teams and or products. Handle stakeholder communication, budget, vendor selection, and process compliance. Test Architectecture Design testing frameworks, strategies, and toolchains. Advise on More ❯
Posted:

Penetration Tester

cardiff, United Kingdom
TLScontact
vulnerabilities and non-trivial security issues. Support technical teams in resolving vulnerabilities and strengthening security measures. Develop and maintain security testing methodologies aligned with OWASP, NIST, and CIS Controls . Integrate security testing into the CI/CD pipeline to detect and fix vulnerabilities early. Ensure compliance with industry security … continuous improvements. What You Bring to TLScontact Demonstrable experience in penetration testing and security testing . Hands-on expertise with security tools (Burp Suite, OWASP ZAP) and scripting languages (Python, Bash, PowerShell, Metasploit, Checkmarx). Experience with CI/CD tools (GitLab, Jenkins, GitHub Actions). Deep understanding of secure More ❯
Posted:

Penetration Tester

newport, midlands, United Kingdom
TLScontact
vulnerabilities and non-trivial security issues. Support technical teams in resolving vulnerabilities and strengthening security measures. Develop and maintain security testing methodologies aligned with OWASP, NIST, and CIS Controls . Integrate security testing into the CI/CD pipeline to detect and fix vulnerabilities early. Ensure compliance with industry security … continuous improvements. What You Bring to TLScontact Demonstrable experience in penetration testing and security testing . Hands-on expertise with security tools (Burp Suite, OWASP ZAP) and scripting languages (Python, Bash, PowerShell, Metasploit, Checkmarx). Experience with CI/CD tools (GitLab, Jenkins, GitHub Actions). Deep understanding of secure More ❯
Posted:

Application Security Specialist

cardiff, United Kingdom
Korn Ferry
role will be circa £650 per day, inside IR35 Key Skills Required: Strong Security and Development background, in SDLC-focused roles Deep knowledge of OWASP API Top 10 Able to review Swagger/Open API specs for vulnerabilities Advise on secure API design patterns Familiar with fallback controls such as … WAF's, API gateways Experience using SIEM/logging tools to track API threats Familiarity with NIST, OWASP SAMM, or internal security frameworks Experience producing risk dashboards/reports for API's Able to translate technical risks into business language, collaborating with key stakeholders Experience in large-scale, enterprise environments More ❯
Posted:

Application Security Specialist

newport, midlands, United Kingdom
Korn Ferry
role will be circa £650 per day, inside IR35 Key Skills Required: Strong Security and Development background, in SDLC-focused roles Deep knowledge of OWASP API Top 10 Able to review Swagger/Open API specs for vulnerabilities Advise on secure API design patterns Familiar with fallback controls such as … WAF's, API gateways Experience using SIEM/logging tools to track API threats Familiarity with NIST, OWASP SAMM, or internal security frameworks Experience producing risk dashboards/reports for API's Able to translate technical risks into business language, collaborating with key stakeholders Experience in large-scale, enterprise environments More ❯
Posted: