implement secure software development practices Integrate security gates into CI/CD pipelines following DevSecOps principles Establish security quality gates and acceptance criteria Develop securecoding standards based on OWASP guidelines Create security architecture patterns and reference implementations Security Code Reviews & Testing Conduct in-depth security code reviews for critical features Implement automated security testing … security linters and pre-commit hooks Create automated vulnerability tracking and remediation workflows Implement secret scanning and dependency checking Build security dashboards and metrics reporting Create securecoding guidelines for different technology stacks Develop a security champions program aligned with OWASP SAMM Conduct security training on platform-specific vulnerabilities Provide hands-on guidance during security incidents Build … years of application security experience Deep understanding of security vulnerabilities across web and mobile platforms Hands-on experience with security testing tools and methodologies Expertise in securecoding practices and design patterns Experience with modern development frameworks (React, Angular, ReactNative, Flutter) Security Domain Knowledge Expert knowledge of OWASP standards (Top 10, ASVS, SAMM, MASVS) Understanding of cryptographic More ❯
editorial standards, but also on the security, reliability and resilience of the systems behind every stream, story and service. In Engineering Enablement , we're the team that makes secure, high-velocity delivery possible. We build shared cloud platforms, developer tooling and guardrails that let hundreds of product teams ship confidently and sustainably. We're hiring a Principal Software … across the BBC. You'll work hands-on with engineering teams, applying InfoSec-led policies and architecture in delivery contexts. You'll support threat modelling, promote securecoding practices, and help scale Secure SDLC across the organisation - without reinventing governance or duplicating policy. It's a high-trust role with real impact: translating strategic security … security policy and architectural guidance. Promote secure SDLC practices across engineering teams, collaborating with InfoSec on shared tooling, templates and enablement. Help teams adopt securecoding standards and integrate automated security checks (SAST, DAST, dependency scanning) into CI/CD pipelines. Participate in threat modelling using InfoSec-led methodologies and coordinate validation and review workflows. More ❯
websites to meet the highest security standards. Your expertise will help us continuously analyse and improve our security systems, ensuring that our products and services are not only secure by design but also comply with internal and external regulatory requirements. Other responsibilities include: Security Analysis and Improvement: Continuously analyse our security systems for potential improvements, ensuring that our … well-considered recommendations to management. Development of Security Standards: Develop and maintain best practices and security standards for the organisation, guiding teams in the implementation of securecoding practices. Secure Design: Collaborate with development teams to ensure that web and mobile front-ends, as well as microservice architectures, are designed with robust security measures in … or application security. You should also have a proven experience and knowledge with any combination of the following: Threat modelling and risk assessments, Working knowledge of securecoding principles (OWASP and OWASP mobile, SANS ), Experience with designing and administering identity management (authentication and authorisation including policy enforcement points, token services, protocols such as OAuth2), Working knowledge of More ❯
In this key role, you will be a key contributor to Funding Circle's cloud and application security posture. You will leverage your deep expertise in AWS security, secure software development lifecycle (SSDLC) practices, and CI/CD security to implement and champion robust security solutions. You will act as a subject matter expert and mentor, collaborating closely … as fast, hassle free processes to deliver an unbeatable customer experience. The role Define, champion, and embed secure software development lifecycle (SSDLC) practices and securecoding standards across engineering teams through collaboration, training, and tooling. Architect, build, and maintain automated security controls, tooling, and "security rails" within CI/CD pipelines to ensure secure … CI, Jenkins, GitHub Actions). Strong track record of defining, implementing, measuring, and supporting the adoption of secure software development lifecycle (SSDLC) practices and securecoding standards within engineering organizations. Strong understanding of web application security vulnerabilities (OWASP Top 10 and beyond), attack vectors, and mitigation techniques. Significant experience securing Infrastructure as Code (IaC) , particularly More ❯
Mentor and guide junior engineers, fostering continuous learning and growth Stay updated on industry trends and emerging technologies, contributing to internal tech communities Ensure adherence to securecoding standards to protect sensitive data and reduce vulnerabilities Develop and maintain robust unit tests to guarantee software reliability and maintainability Drive architectural decisions and long-term technology strategy aligned … to engage technical and non-technical stakeholders alike Confidence in navigating, integrating, and developing solutions across multiple systems Solid understanding of software architecture, design patterns, and securecoding best practices Hands-on experience with cloud platforms (AWS, Azure, Google Cloud) and CI/CD pipelines is a plus Familiarity with SQL/NoSQL databases and version control More ❯
Knutsford, Cheshire, North West, United Kingdom Hybrid / WFH Options
Anson Mccade
with cross-functional teams to define technical requirements and translate business goals into elegant technical solutions. Drive code quality through reviews, unit testing, and adherence to securecoding standards. Contribute to architectural decisions and help set engineering direction across teams. Mentor and support junior engineers, promoting a culture of excellence and continuous learning. Stay informed on emerging … history demonstrating stability, technical growth, and progression. Preferred Skills & Experience: Experience with cloud platforms such as AWS, Azure, or GCP. Familiarity with CI/CD pipelines, securecoding, and performance optimisation. Proficiency with relational and NoSQL databases. Exposure to large-scale, enterprise environments, with a mindset for innovation and change. Senior Software Engineer Key Benefits: Competitive salary More ❯
Protect Granola's technology and users by building secure systems and fostering security culture We're looking for a security engineer who is passionate about application security to help us protect our users and build trust as we scale. In this role, you will be responsible for identifying and mitigating security vulnerabilities within Granola's applications, building security … to identify vulnerabilities in our applications Design and implement security tools, frameworks, and methodologies to protect against security threats Work closely with development teams to ensure securecoding practices are integrated throughout the SDLC Perform threat modeling and risk assessments to proactively identify potential risks and develop mitigation strategies Track, analyze, and manage vulnerabilities in applications, providing … threats, vulnerabilities, and technologies to enhance our security posture Your background looks something like: Extensive experience in application security, cybersecurity, or related fields Strong understanding of securecoding practices, threat modeling, risk assessments, and incident response Proficiency in programming languages such as TypeScript, Python, or similar Experience with security tools, security protocols, encryption methods, and application security More ❯
UK SC clearance Are you ready to lead a high-impact security development and testing function? We’re looking for a Security Development and Test Director to oversee secure software development lifecycle, DevSecOps integration, and security testing at scale within a fast-growing security team. This is a unique opportunity to drive operational excellence and shape secure … Drive secure architecture standards and embed security controls into DevOps pipelines Oversee implementation and optimisation of security tooling (SAST, DAST, SCA, container security) Champion securecoding, threat modelling, and DevSecOps maturity improvements Manage budgets, profitability, and resource utilisation for your function Mentor and develop high-performing engineering and testing teams Key Responsibilities Support sales with … technical expertise and solution design Own service delivery quality and client satisfaction Define and enforce secure architecture and coding standards Lead DevSecOps integration with automated security testing in CI/CD Drive continuous process improvements and automation adoption Monitor and report on KPIs like vulnerability remediation, tool adoption, and training uptake Collaborate cross-functionally with architects, engineers More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Anson McCade
UK SC clearance Are you ready to lead a high-impact security development and testing function? We’re looking for a Security Development and Test Director to oversee secure software development lifecycle, DevSecOps integration, and security testing at scale within a fast-growing security team. This is a unique opportunity to drive operational excellence and shape secure … Drive secure architecture standards and embed security controls into DevOps pipelines Oversee implementation and optimisation of security tooling (SAST, DAST, SCA, container security) Champion securecoding, threat modelling, and DevSecOps maturity improvements Manage budgets, profitability, and resource utilisation for your function Mentor and develop high-performing engineering and testing teams Key Responsibilities Support sales with … technical expertise and solution design Own service delivery quality and client satisfaction Define and enforce secure architecture and coding standards Lead DevSecOps integration with automated security testing in CI/CD Drive continuous process improvements and automation adoption Monitor and report on KPIs like vulnerability remediation, tool adoption, and training uptake Collaborate cross-functionally with architects, engineers More ❯
Stourbridge, West Midlands, United Kingdom Hybrid / WFH Options
Gambit Nash Limited
development, and turning these into workable new web based and software solutions. You will work across the full suite of digital activity, so you need to be competent in coding using PHP 8.4, HTML 5, CSS 3 and JavaScript as a core skillset, and be able to create websites compatible with all browsers, platforms and responsive to the full … to manage projects from concept through to go live. Additional technical skills youll understand include; Git, JQuery, Ajax, and MySQL/Maria databases. With a team focus on secure software development, you … will follow best practices to ensure that both new and existing code is secure and maintainable, following best practices for secure design, securecoding, security testing, and vulnerability management. Key skills a successful applicant must demonstrate A deep understanding and knowledge of WordPress from theme and plugin development Core skill set of PHP More ❯
or Cambridge Salary: £70,000 - £120,000 (depending on experience and clearance) We are looking for a Full Stack Developer to join a growing public sector team delivering secure, high-impact digital services across Defence & Security. This is a unique opportunity to use your development expertise to help solve real-world challenges for government and national security clients. … collaborative and supportive engineering team, working alongside technical leads, project managers, and stakeholders to deliver robust and scalable solutions. What you'll be doing: Designing, developing and deploying secure, high-performing web applications for government clients Working across the full software development lifecycle, from requirements through to production Building responsive user … interfaces using modern front-end technologies Developing scalable server-side functionality with appropriate frameworks and languages Creating and maintaining RESTful APIs for integration across platforms Following securecoding practices and supporting compliance with government security standards Conducting security reviews and supporting remediation of vulnerabilities Translating technical requirements into delivery plans and code Communicating effectively with both technical More ❯
or Cambridge Salary: £70,000 - £120,000 (depending on experience and clearance) We are looking for a Full Stack Developer to join a growing public sector team delivering secure, high-impact digital services across Defence & Security. This is a unique opportunity to use your development expertise to help solve real-world challenges for government and national security clients. … collaborative and supportive engineering team, working alongside technical leads, project managers, and stakeholders to deliver robust and scalable solutions. What you'll be doing: Designing, developing and deploying secure, high-performing web applications for government clients Working across the full software development lifecycle, from requirements through to production Building responsive user … interfaces using modern front-end technologies Developing scalable server-side functionality with appropriate frameworks and languages Creating and maintaining RESTful APIs for integration across platforms Following securecoding practices and supporting compliance with government security standards Conducting security reviews and supporting remediation of vulnerabilities Translating technical requirements into delivery plans and code Communicating effectively with both technical More ❯
a Lead Software Security Engineer to take our product security program to the next level. This is a high-impact, hands-on role where you'll guide the secure design and development of distributed systems, shape engineering and product roadmaps, and foster a security-first mindset across teams. WHAT YOU'LL DO Be a Security Champion Be a … trusted advisor and advocate for security across the development lifecycle, influencing architecture, design and implementation decisions. Embed securedevelopment practices into day-to-day workflows across engineering teams. Own the vulnerability management lifecycle: from discovery and triage to remediation tracking and coordinated disclosure. Build Secure Products by Design Conduct threat models, security architecture reviews and risk … strong understanding of security principles and engineering realities. Must-Have Experience Proven experience in application and product security, including secure design, threat modeling and securecoding practices. Strong knowledge of security issues in modern software stacks, such as Java, distributed systems, microservices, containers, etc. Experience integrating security tools into development pipelines (eg. static/dynamic More ❯
tech providers, they're redefining how enterprise-grade security is built, deployed, and continuously improved. They're now seeking a Security Development and Test Director to lead their secure software engineering function, drive DevSecOps maturity, and embed security across the development lifecycle. This is a client-facing, commercially strategic position – ideal for a security leader who thrives at … the intersection of technical delivery and business growth. Why join? Shape and scale a modern secure-by-design function in a high-growth global firm Strategic autonomy to influence architecture standards, DevSecOps integration, and engineering culture Engage directly with major enterprise clients and shape security roadmaps that matter Be part of a company recognised for its DEI leadership … CI/CD workflows Owning security tooling strategy (SAST, DAST, SCA, container scanning) and driving adoption across development pipelines Building and mentoring high-performing teams in securecoding, DevSecOps, and threat modelling Leading engagements with major clients during pre-sales, delivery and review phases Managing financials, resource planning, and service maturity across the Secure SDLC More ❯
tech providers, they're redefining how enterprise-grade security is built, deployed, and continuously improved. They're now seeking a Security Development and Test Director to lead their secure software engineering function, drive DevSecOps maturity, and embed security across the development lifecycle. This is a client-facing, commercially strategic position - ideal for a security leader who thrives at … the intersection of technical delivery and business growth. Why join? Shape and scale a modern secure-by-design function in a high-growth global firm Strategic autonomy to influence architecture standards, DevSecOps integration, and engineering culture Engage directly with major enterprise clients and shape security roadmaps that matter Be part of a company recognised for its DEI leadership … CI/CD workflows Owning security tooling strategy (SAST, DAST, SCA, container scanning) and driving adoption across development pipelines Building and mentoring high-performing teams in securecoding, DevSecOps, and threat modelling Leading engagements with major clients during pre-sales, delivery and review phases Managing financials, resource planning, and service maturity across the Secure SDLC More ❯
Lead the end-to-end development of robust, scalable, and secure systems. Guide and mentor junior engineers, fostering a culture of continuous learning and technical excellence. Uphold coding standards through code reviews, best practices, and technical leadership. Drive innovation by staying up-to-date with emerging technologies and industry trends. What You'll Bring: Expertise in one … design systems aligned with business goals. Comfort working across distributed systems and integrating diverse technologies. Preferred Skills & Experience: Deep understanding of software architecture, design patterns, and securecoding practices. Hands-on experience with cloud services such as AWS , Azure , or Google Cloud , and CI/CD pipelines. Proficiency in SQL/NoSQL databases and modern version control More ❯
Huntingdon, Cambridgeshire, East Anglia, United Kingdom Hybrid / WFH Options
Leidos Innovations UK Limited
capability Work with the customer and appropriate agencies to develop new policies, design processes, and procedures, and develop technical designs Assess system vulnerabilities, implement risk mitigation strategies, validate secure systems, and test security products and systems to detect security weakness Maintain and support security enforcing functions Core Skills Experience working in MOD or Home Office project environments Strong … system security, including firewalls, IDS/IPS, micro-segmentation, and host security. Hands on experience with the following security products Trellix, Ivanti, ClearSwift, Yubikey Understanding of securecoding practices and common vulnerabilities (OWASP Top 10, SANS Top 25). Expertise in identity and access management (IAM), including RBAC, ABAC, JWT and Cookie based authentication. Incident detection and … pod security standards, secrets management). Knowledge of container runtime security (e.g., container escapes, rootless containers, sandboxing). Image security best practices, including scanning, signing, and provenance verification. Secure deployment patterns using Tanzu & Kubernetes. Runtime security monitoring. DevSecOps & CI/CD Security Secure CI/CD pipeline design with security testing using like Git and SonarQube. More ❯
and executing Orgvue's security engineering strategy across our entire application development and cloud-hosting estate. Partnering closely with Information Security, Engineering, and Product teams, you will embed secure-by-design principles throughout the software-development lifecycle (SDLC), champion modern DevSecOps practices, and ensure that security is a first-class citizen in everything we build and operate. This … continuously refine the technical security roadmap that aligns with business objectives, industry best practice (e.g., NIST CSF, OWASP SAMM), and compliance frameworks (SOC 2, ISO 27001, GDPR). Secure SDLC & DevSecOps - Build and maintain guardrails for static/dynamic analysis, container and IaC scanning, SBOM management, and supply-chain security; automate enforcement through CI/CD pipelines. Cloud … intelligence sharing, incident response, and compliance initiatives, ensuring organisation-wide alignment. Engineering Partnership & Enablement - Work hand-in-hand with engineering squads to raise security awareness, improve securecoding practices, and foster a culture of shared security ownership. Architecture Alignment - Partner closely with Orgvue's Principal Architect to ensure security patterns, controls, and roadmaps align with overall system More ❯
Chester, Cheshire, North West, United Kingdom Hybrid / WFH Options
Searchability (UK) Ltd
team responsible for developing and maintaining a highly available, in-house software platform. Our work spans modern APIs, scalable services, and engaging user interfaces. We value quality engineering, secure design, and continuous improvement across the stack. Who We're Seeking: We're on the lookout for a Senior Software Developer with strong backend skills and experience across a … modern cloud-native tech stack. You'll help design and implement robust, secure systems, write clean and testable code, and support key architectural decisions. You'll also collaborate with cross-functional teams, contribute to API development, and mentor junior developers. There's potential to lead a small team and take ownership of a stream of work depending on … vacancy only. We look forward to hearing from you! Key Skills: PHP, Symfony, MySQL, REST APIs, Microservices, JavaScript, React, Java, AWS, Docker, CI/CD, Git, SecureCoding, Test-Driven Development, Distributed Systems, Infrastructure as Code (CDK/Terraform), Linux/Bash More ❯
Stockport, Lancashire, United Kingdom Hybrid / WFH Options
Adria Solutions Ltd
systems, contribute to architectural decisions, and support the continuous improvement of development practices. Key responsibilities: Develop and maintain scalable, high-quality software using C#, .NET, and Azure Lead on coding tasks and contribute to system architecture Perform code reviews and mentor junior developers Collaborate across teams to deliver business-critical solutions Provide second-line technical support as needed Essential … experience: 5+ years in commercial software development Proficiency in C#, .NET, SQL Server, and JavaScript Experience with Azure services and DevOps tools Understanding of securecoding and software development best practices Desirable experience: Microservices, containers (Docker/Kubernetes) Front-end frameworks such as Vue.js Messaging systems (e.g. Service Bus, Kafka) NoSQL databases, REST APIs, CI/CD More ❯
Manchester, North West, United Kingdom Hybrid / WFH Options
Adria Solutions
systems, contribute to architectural decisions, and support the continuous improvement of development practices. Key responsibilities: Develop and maintain scalable, high-quality software using C#, .NET, and Azure Lead on coding tasks and contribute to system architecture Perform code reviews and mentor junior developers Collaborate across teams to deliver business-critical solutions Provide second-line technical support as needed Essential … experience: 5+ years in commercial software development Proficiency in C#, .NET, SQL Server, and JavaScript Experience with Azure services and DevOps tools Understanding of securecoding and software development best practices Desirable experience: Microservices, containers (Docker/Kubernetes) Front-end frameworks such as Vue.js Messaging systems (e.g. Service Bus, Kafka) NoSQL databases, REST APIs, CI/CD More ❯
Manchester, Lancashire, England, United Kingdom Hybrid / WFH Options
Adria Solutions
systems, contribute to architectural decisions, and support the continuous improvement of development practices. Key responsibilities: Develop and maintain scalable, high-quality software using C#, .NET, and Azure Lead on coding tasks and contribute to system architecture Perform code reviews and mentor junior developers Collaborate across teams to deliver business-critical solutions Provide second-line technical support as needed Essential … experience: 5+ years in commercial software development Proficiency in C#, .NET, SQL Server, and JavaScript Experience with Azure services and DevOps tools Understanding of securecoding and software development best practices Desirable experience: Microservices, containers (Docker/Kubernetes) Front-end frameworks such as Vue.js Messaging systems (e.g. Service Bus, Kafka) NoSQL databases, REST APIs, CI/CD More ❯
Almondsbury, Gloucestershire, United Kingdom Hybrid / WFH Options
Frontier Resourcing
vulnerabilities in architectures, codebases, and configurations; drive remediation with development and operations teams. SecureDevelopment Practices Partner with software and hardware engineers to integrate securecoding and design principles (e.g., threat modelling, secure-by-design). Perform security code reviews, provide guidance on secure libraries and frameworks. Standards & Compliance Ensure products More ❯
Bristol, Avon, England, United Kingdom Hybrid / WFH Options
Xpertise Recruitment Ltd
world problems with stakeholders and customers What You’ll Bring: 5+ years of experience in C# and .NET Core Strong grasp of software design principles and securecoding practices (OWASP) Experience with REST API development and deployment in AWS or Azure Familiarity with Entity Framework , SQL/NoSQL databases, and cloud architecture Confidence in automated testing (unit More ❯
City of London, London, England, United Kingdom Hybrid / WFH Options
Matched Group
with cloud message APIs and usage of push notifications. Knowledge of CI/CD pipelines, code signing, and deployment (App Store, Google Play). Understanding of securecoding practices. Excellent written and verbal communication skills For more information, contact Katie at Matched Group. Full Stack Mobile Engineer/Full Stack Mobile Developer/Mobile Engineer/Mobile More ❯