Start Date: ASAP About the Role Our client, a leading global organization, is looking for an experienced DevSecOps Pentester to join a leading security team in London. Youll perform penetration tests and security assessments across CI/CD pipelines, cloud environments, and applications, integrating automated security tools and practices into DevOps workflows. This role is ideal for someone who … and development teams, and help improve enterprise security posture. Key Responsibilities Integrate security tools and practices into CI/CD pipelines for continuous validation. Conduct manual and automated security testing on web apps, APIs, pipelines, and cloud infrastructure. Identify and exploit vulnerabilities in CI/CD workflows, IaC, containers, and cloud-native architectures (AWS, Azure, GCP, Docker, Kubernetes). … threat modeling, and secure design review. Proficiency in automating security checks using Jenkins, GitLab, Ansible, or similar tools. Secure coding knowledge and familiarity with common developer pitfalls. Scripting for testing/automation: Python, Bash, Go. Cloud-native and container experience: Docker, Kubernetes, IaC. Cloud security knowledge: AWS, Azure, GCP, and cloud security best practices. Experience collaborating in agile, fast More ❯
Role/Job Title: DevSecOps Pentester Work Location: London (2 - 3days) The Role Conducts security assessments and penetration tests across CI/CD pipelines, cloud infrastructure, and application environments. Integrates automated security tools and practices within DevOps workflows to ensure continuous security validation. Identifies and exploits vulnerabilities in code, containers, APIs, and infrastructure-as-code before they reach production. … automation efforts. Identify potential security threats and vulnerabilities during the design phase identify flaws in CI/CD, IaC, and cloud/containerized environments. Perform manual and automated security testing on web apps, APIs, pipelines. Participate in agile ceremonies (sprint planning, threat modeling, grooming). Create detailed reports, providing actionable advice to clients on how to address the identified … automating security checks within the CI/CD pipeline using tools like Jenkins, GitLab, and Ansible is vital. Knowledge of secure coding practices and common developer pitfalls. Scripting for testing/automation (Python, Bash, Go). Experience with cloud-native architectures (Docker, Kubernetes, IaC). Knowledge of securing cloud platforms (AWS, Azure, GCP) and understanding cloud security best practices. More ❯
coding. Collaborating with architects and developers to review designs and code for vulnerabilities. Embedding/improving threat modelling and secure development practices into the SDLC. Designing and integrating security testing plans. Performing and overseeing application security testing and driving remediation. Managing end-to-end vulnerability workflows, including bug bounty findings. Supporting incident response activities when needed. Monitoring and … in an on-call rotation. What we’re looking for 3+ years in software engineering plus 2+ years in application security. Strong knowledge of OWASP, application vulnerabilities, and security testing techniques. Experience with secure web application development and Agile/DevOps methodologies. Familiarity with pen testing, bug bounty, or hacker community collaboration. Strong communication skills – able to influence More ❯
Cambridge, Cambridgeshire, East Anglia, United Kingdom
Morson Talent
coding. Collaborating with architects and developers to review designs and code for vulnerabilities. Embedding/improving threat modelling and secure development practices into the SDLC. Designing and integrating security testing plans. Performing and overseeing application security testing and driving remediation. Managing end-to-end vulnerability workflows, including bug bounty findings. Supporting incident response activities when needed. Monitoring and … in an on-call rotation. What we're looking for 3+ years in software engineering plus 2+ years in application security. Strong knowledge of OWASP, application vulnerabilities, and security testing techniques. Experience with secure web application development and Agile/DevOps methodologies. Familiarity with pen testing, bug bounty, or hacker community collaboration. Strong communication skills – able to influence More ❯
hybrid role : Location: Cambridge, UK with travel to the office once per week. What you'll be doing: Provide guidance on security best practices and compliance and undertake security testing Identify Application security risks and requirements for new projects and system developments Represent cyber in review sprints on application security prior to live implementation Collaborate with the architecture and … threat modelling capability and evangelise secure coding in the development lifecycle Provide technical specialist advice to ensure that security standards are understood and can be complied with Develop security testing plans and integrate into the software development lifecycle (S-SDLC) Perform and oversee security testing and manage remediation of identified vulnerabilities Take part in the security incident response … we're looking for: At least 3 years of experience in software engineering. At least 2 years of experience in application security. In-depth knowledge of application security vulnerabilities, testing techniques, and the OWASP framework. Team player able to build relationships across the organization. In-depth understanding of secure web application development. Experience in web application and Agile development More ❯
Offensive Security Researcher/Security Consultant | Elite Cybersecurity Scale-Up | Fully Remote (Global) Ready to take your offensive security skills to the next level? This is your chance to join a fast-scaling cybersecurity innovator , backed by funding, recognised by More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Xact Placements Limited
Offensive Security Researcher/Security Consultant | Elite Cybersecurity Scale-Up | Fully Remote (Global) Ready to take your offensive security skills to the next level? This is your chance to join a fast-scaling cybersecurity innovator , backed by funding, recognised by More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Xact Placements Limited
Offensive Security Researcher/Security Consultant | Elite Cybersecurity Scale-Up | Fully Remote (Global) Ready to take your offensive security skills to the next level? This is your chance to join a fast-scaling cybersecurity innovator , backed by funding, recognised by More ❯