through reviews and penetration test support. Key Requirements: Solid understanding of cloud-native applicationsecurity, especially AWS environments. Experience with API security standards (e.g., OWASP API Top 10). Familiarity with DevSecOps practices and tools. One or more certifications: CSSLP, CISSP, OSWE, CREST CRT/CCT App, GIAC GWAPT. Apply More ❯
Oxford, Oxfordshire, United Kingdom Hybrid / WFH Options
Sophos Group
A pragmatic approach to securing products leveraging different technologies, facing different threat profiles. Strong knowledge of applicationsecurity and common webapplication vulnerabilities (e.g., OWASP Top 10) and experience with secure coding practices. A background in a software or cloud engineering role is preferable, but not required. A willingness to More ❯
At least 8 years of experience working in IoT security, with a focus on healthcare or medical devices Familiarity with security frameworks like NIST, OWASP, and industry-specific standards, such as FDA cybersecurity guidelines Experience in assessing and managing security risks through penetration testing, threat modeling, and other methods Knowledge More ❯
similar. Experience implementing and managing SAST/DAST tools and processes to secure application development. Deep understanding of applicationsecurity, including secure coding practices, OWASP Top 10, and API security standards. Knowledge of Customer Identity and Access Management (CIAM) solutions and API security frameworks. Knowledge of one or more programming More ❯
or risks, with a focus on recommendations for enhancements or remediation, and proficiency in multiple security assessment methodologies (e.g., Open Worldwide ApplicationSecurityProject (OWASP) Top Ten, National Institute of Standards and Technology (NIST) Cybersecurity Framework), offensive testing tools, or resiliency testing equivalents Excellent communication, collaboration, and report writing skills More ❯
CI/CD experience with microservices Hands-on with modern auth providers (Auth0, Kinde, Okta, Cognito), including RBAC Familiarity with GraphQL Strong understanding of OWASP Top 10, CSP, CSRF, and XSS mitigation Confident written communicator – clear documentation and stakeholder updates are a must Bonus points for: Experience migrating to managed More ❯
london, south east england, United Kingdom Hybrid / WFH Options
Natcap
CI/CD experience with microservices Hands-on with modern auth providers (Auth0, Kinde, Okta, Cognito), including RBAC Familiarity with GraphQL Strong understanding of OWASP Top 10, CSP, CSRF, and XSS mitigation Confident written communicator – clear documentation and stakeholder updates are a must Bonus points for: Experience migrating to managed More ❯
writing, execution, and regression testing Automation testing using Cypress, Appium Familiarity with Azure DevOps (test case & defect management) Performance & security testing tools: JMeter, LoadRunner, OWASP ZAP API testing with Postman SQL for database/backend testing Soft Skills Strong analytical and troubleshooting skills High attention to detail Excellent communication and More ❯
Nottingham, Nottinghamshire, East Midlands, United Kingdom
Microlise
PowerShell Experience with monitoring/logging tools SolarWinds, Grafana, Elastic Familiarity with security concepts such as Zero Trust, Identity and Access Management Vulnerability management, OWASP Understanding of CI/CD pipelines Familiar with Entra ID, AD, DNS, Azure Ability to troubleshoot complex issues across various infrastructure platforms Were looking for More ❯
PowerShell Experience with monitoring/logging tools SolarWinds, Grafana, Elastic Familiarity with security concepts such as Zero Trust, Identity and Access Management Vulnerability management, OWASP Understanding of CI/CD pipelines Familiar with Entra ID, AD, DNS, Azure Ability to troubleshoot complex issues across various infrastructure platforms Were looking for More ❯
PowerShell Experience with monitoring/logging tools SolarWinds, Grafana, Elastic Familiarity with security concepts such as Zero Trust, Identity and Access Management Vulnerability management, OWASP Understanding of CI/CD pipelines Familiar with Entra ID, AD, DNS, Azure Ability to troubleshoot complex issues across various infrastructure platforms Were looking for More ❯
practices and version control systems including CI/CD build pipelines (GitLab, Jenkins, Selenium). Experience of Secure web and API development best practices (OWASP) and authentication protocols and encryption techniques. Candidates MUST be based locally to West Yorkshire and have full right to work in the UK. No sponsorship More ❯
standard development, and building secure software. Proven experience implementing Security in highly regulated environments. Previous experience in cryptocurrency projects is a plus. Experience with OWASP, Static and Dynamic ApplicationSecurity Testing (AST) and dependency validation (SCA) tools. Experience with integration into CI/CD pipelines is a plus. Knowledge of More ❯
experience in applicationsecurity or a related field. Proven experience in leading and managing security teams. Strong understanding of common applicationsecurity vulnerabilities (e.g., OWASP Top 10) and mitigation techniques. Proficiency in security tools and technologies such as static and dynamic analysis tools, penetration testing tools, and security information and More ❯
of DevSecOps, familiarity of applicationsecurity and threat modelling, experience implementing SDLC process, technology, and automation in a DevOps environment; ideally making use of OWASP best practice, experience within agile delivery frameworks, large scale web applications and back-end services, API design, access management data protection and encryption, familiar with More ❯
similar. Experience implementing and managing SAST/DAST tools and processes to secure application development. Deep understanding of applicationsecurity, including secure coding practices, OWASP Top 10, and API security standards. Knowledge of Customer Identity and Access Management (CIAM) solutions and API security frameworks. Knowledge of one or more programming More ❯
Solid understanding of the MVC pattern, REST APIs, and ASP.NET controllers. Experience with front-end frameworks: Vue.js, React, AngularJS, or Knockout. Knowledge of IIS, OWASPsecurity practices, and performance optimization. Excellent interpersonal and communication skills. Strong problem-solving, multitasking, and attention to detail. Knowledge of SEO best practices. Why Join More ❯
Solid understanding of the MVC pattern, REST APIs, and ASP.NET controllers. Experience with front-end frameworks: Vue.js, React, AngularJS, or Knockout. Knowledge of IIS, OWASPsecurity practices, and performance optimization. Excellent interpersonal and communication skills. Strong problem-solving, multitasking, and attention to detail. Knowledge of SEO best practices. Why Join More ❯
network OS, Windows/nix/MacOS, network communication protocols, virtual environments, cloud environments, mobile OS (Android/iOS), and containerized platforms. Understanding of OWASP, the MITRE ATT&CK framework, and the software development lifecycle (SDLC). More ❯
Nice to haves Experience within eCommerce and/or payments. Good understanding of OOP and/or functional paradigms. Good understanding of software security, OWASP and scaling of software systems. Good understanding of NextJS or other similar server-focused frontend metaframework. Bonus points for having used React's server components More ❯
managing Azure subscriptions You have a good knowledge of DevOps and IaC concepts You're familiar with cloud based security (e.g. ISO27001, NIST, CIS, OWASP, SOC2) and Identity and Access Management (IAM) within Azure You're familiar with ARM templates and/or Pulumi Ideally you will have automation and More ❯
London, England, United Kingdom Hybrid / WFH Options
Client Server
and data analysis, parallelising complex simulations to drive improvements whilst optimising for cost and efficiency. You'll ensure the platform meets security standards including OWASP Top 10 and ISO 27001 compliance, collaborating with IT, legal and compliance teams. Location/WFH: You'll join the team in Central London three More ❯
london, south east england, United Kingdom Hybrid / WFH Options
Client Server
and data analysis, parallelising complex simulations to drive improvements whilst optimising for cost and efficiency. You'll ensure the platform meets security standards including OWASP Top 10 and ISO 27001 compliance, collaborating with IT, legal and compliance teams. Location/WFH: You'll join the team in Central London three More ❯
Manchester, Lancashire, United Kingdom Hybrid / WFH Options
慨正橡扯
and static applicationsecurity testing tools. Excellent understanding and experience with manual security testing to find vulnerabilities and logical issues. Knowledge and understanding of OWASP and its utilisation within threat modelling. Experience of software development and languages. Working knowledge of CI and CD pipelines and associated security tooling. Use of More ❯
Manchester Area, United Kingdom Hybrid / WFH Options
bet365
and static applicationsecurity testing tools. Excellent understanding and experience with manual security testing to find vulnerabilities and logical issues. Knowledge and understanding of OWASP and its utilisation within threat modelling. Experience of software development and languages. Working knowledge of CI and CD pipelines and associated security tooling. Use of More ❯