Static Application Security Testing Jobs in England

26 to 50 of 60 Static Application Security Testing Jobs in England

Product Security Engineer

London, United Kingdom
Smarsh, Inc
Gartner and Forrester, and our sustained, aggressive growth has landed Smarsh in the annual Inc. 5000 list of fastest-growing American companies since 2008. We're seeking a Product Security Engineer to support secure development across our engineering teams. In this hands-on role, you'll help identify and mitigate product risks by participating in security reviews, improving … design reviews and backlog grooming. Threat Modelling : Participate in structured threat modelling exercises with guidance from senior team members. Vulnerability Triage : Work with engineering teams to review findings from SAST, SCA, DAST, and container scans and track remediation progress. Code & Config Review : Conduct basic secure code and configuration reviews, escalating high-risk findings as needed. Security Tooling & Automation : Help … e.g., Python, Java, JavaScript, Go, or C#). Familiarity with cloud platforms (AWS, Azure, or GCP) and container technologies (Docker, Kubernetes). Exposure to security tooling such as SAST, SCA, or DAST scanners (e.g., Semgrep, Endor, Burp). Basic understanding of identity and access controls (OAuth, SAML, API tokens). Strong collaboration and communication skills, with a willingness to More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

DevSecOps Engineer

London, United Kingdom
Hybrid / WFH Options
Foundations Executive Search
65k - £78K + bonus, benefits) We are working with a globally renowned and industry leading UK brand who are going through an exciting phase of growth across their wider Security function, resulting in the need for a DevSecOps Engineer. As a DevSecOps Engineer, you will work within a newly established team in a role that sees you provide hands … on Application Security and DevSecOps responsibilities, as well as being involved in various strategic activities. Your duties would include setting-up, securing and enhancing pipelines, scripting and automation, as well as looking at how things are done, what improvements can be made, supporting cyber change initiatives and driving security awareness/practices as necessary. This role will … most companies of a similar size, who also offer some of the best perks & benefits available! Key skills and experience required: DevSecOps experience Application Security expertise across SAST, DAST & SCA Background and experience in Software Development/Scripting/Automation Ability to work in a fast-paced environment Ability to work on-site for key strategic/important More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Security Engineer (Vlocity/Salesfore Industries)

England, United Kingdom
Hybrid / WFH Options
FPSG Connect
Security Engineer (Vlocity/Salesfore Industries) (Hands on recent career experience of Salesforce Industries/Vlocity is essential) FPSG have a fantastic opportunity to join a large-scale digital transformation programme aimed at uniting multiple internal business units under a new, secure, cloud-native digital platform. Ideal for a hands-on Security Engineer who enjoys embedding security … and cloud network architecture (VPNs, subnets, zones) Experience with API security and integration-related platforms such as Auth0 or API Gateways Proficiency with security tools including SAST (e.g. Snyk, Checkmarx), SCA, and DAST (e.g. OpenZAP, Qualys DAST) Ability to manage secure operations of large-scale software estates, including deployment pipelines, rollback strategies, and uptime monitoring Practical experience building … Engineer, Information Security Specialist, Salesforce Industries, Vlocity, Azure, OWASP CI/CD, DSOMM, SAMM, Cloud Security Posture Management, Prisma Cloud, Azure Defender, Snyk, Checkmarx, OpenZAP, Qualys, DAST, SAST, CI/CD, Infrastructure Security, Auth0, Secure APIs, Networking Protocols, DevSecOps, Secure Development, CRM Security Next Steps Please click "Apply now" and submit your up-to-date CV More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Security Engineer (Vlocity/Salesfore Industries)

Tunbridge Wells, Kent, Royal Tunbridge Wells, United Kingdom
Hybrid / WFH Options
FPSG
Security Engineer Permanent Hybrid - 2 or 3 days p/w on-site Tunbridge Wells area (Hands on recent career experience of Salesforce Industries/Vlocity is essential) FPSG have a fantastic opportunity to join a large-scale digital transformation programme aimed at uniting multiple internal business units under a new, secure, cloud-native digital platform. Ideal for a … and cloud network architecture (VPNs, subnets, zones) Experience with API security and integration-related platforms such as Auth0 or API Gateways Proficiency with security tools including SAST (e.g. Snyk, Checkmarx), SCA, and DAST (e.g. OpenZAP, Qualys DAST) Ability to manage secure operations of large-scale software estates, including deployment pipelines, rollback strategies, and uptime monitoring Practical experience building … Engineer, Information Security Specialist, Salesforce Industries, Vlocity, Azure, OWASP CI/CD, DSOMM, SAMM, Cloud Security Posture Management, Prisma Cloud, Azure Defender, Snyk, Checkmarx, OpenZAP, Qualys, DAST, SAST, CI/CD, Infrastructure Security, Auth0, Secure APIs, Networking Protocols, DevSecOps, Secure Development, CRM Security Next Steps Please click "Apply now" and submit your up-to-date CV More ❯
Employment Type: Permanent
Posted:

Principal Security Engineer

London, United Kingdom
Hybrid / WFH Options
Orgvue Limited
future states of the organisation and make faster, more informed decisions. The company is headquartered in London, with offices in Philadelphia, The Hague, Toronto, and Sydney. Role The Principal Security Engineer is a strategic, hands-on leader responsible for evaluating, evolving, and executing Orgvue's security engineering strategy across our entire application development and cloud-hosting estate. … Partnering closely with Information Security, Engineering, and Product teams, you will embed secure-by-design principles throughout the software-development lifecycle (SDLC), champion modern DevSecOps practices, and ensure that security is a first-class citizen in everything we build and operate. This role reports directly to the Chief Technology Officer (CTO) and maintains a dotted-line relationship with … Threat Modeling & Risk Assessment - Conduct regular architecture and code-level reviews, drive remediation plans, and present risk posture to leadership. Tooling & Automation - Evaluate, select, and integrate security tooling (SAST, DAST, SCA, container scanners, CSPM, CWPP) and champion IaC/Terraform modules for reusable controls. Collaboration & Mentorship - Act as a trusted advisor to engineering squads, provide security training, and More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Senior Product Security Engineer

London, United Kingdom
Toolbx
an outsized impact, you'll thrive here at Zopa, so join us, and make it count.Want to see us in action? Follow us on The team: Zopa's Product Security team ensures security is baked into our products from the very start of their lifecycles, all the way to the end. We provide the more pre-emptive, design … team of 18. Our current projects include ongoing security assessments and threat models of new, in-house created AI-based systems, improving our security tools - such as SAST and SCA, refining a SLSA strategy, helping to roll out an upcoming bounty program and more! We pride ourselves in being able to collaborate and integrate seamlessly with an engineering … avoid Integrating security tooling, stitching together CI steps, scripts, and small tools to automate security controls and visualise their results in a helpful manner. This could include SAST, SCA, DAST, secrets scanning, vulnerability scanning, or other tooling Being guardians of our Secure Development Lifecycle, ensuring security controls are baked in and "pushed left" as much as reasonably More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Senior Security Engineer

London, United Kingdom
Hybrid / WFH Options
Fruition Group
Senior Security Engineer - Build, Secure, and Scale in a Cloud-Native Environment Location: Hybrid (UK-based) Salary: Competitive + Excellent Benefits Employment Type: Full-time, Permanent Are you a seasoned Security Engineer with a passion for protecting infrastructure at scale? A rapidly growing technology-driven organisation is looking for a Senior Security Engineer to play a pivotal … You'll join a high-performing Platform Engineering team, working alongside cloud specialists, DevOps professionals, and software engineers to build secure, scalable platforms. This is more than a pure security role - it's an opportunity to be hands-on in architecture, engineering, and compliance, while leading the charge on modern, cloud-first security strategy. Responsibilties: Designing and implementing … Hands-on expertise in cloud security (preferably AWS), including securing hybrid and multi-region architectures. Practical knowledge of security tooling: IDS/IPS, SIEM, vulnerability scanners, encryption, SAST/DAST tools, OWASP ZAP, etc. Strong understanding of network security protocols and best practices. Scripting and automation experience (e.g. Python). Proven experience with incident response and threat More ❯
Employment Type: Permanent
Salary: £90,000
Posted:

Field Chief Information Security Officer

London, United Kingdom
Hybrid / WFH Options
UiPath
we're enabling the fully automated enterprise-but innovation must be secure to be transformative. That's where you come in. We're looking for a Field Chief Information Security Officer (Field CISO) to serve as a strategic security advisor to our customers and partners, guiding them through the complex landscape of compliance, governance, and secure development of … Automations and Agentic AI. You'll work at the intersection of customer success, product innovation, and cybersecurity thought leadership-translating strategic security insights into real-world impact. What you'll do Act as the primary security advisor for clients, assessing their needs, and providing strategic recommendations. Conduct security risk assessments and design tailored strategies that align with … knowledge of security frameworks (e.g., NIST, ISO 27001) and compliance standards (e.g., GDPR, HIPAA, PCI-DSS). Strong expertise in secure SDLC, and application security tooling (SAST, DAST, SCA). Excellent communication skills with the ability to influence executive and technical stakeholders. Experience advising on or implementing security strategies in enterprise environments. Familiarity with software development More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Application Security Software Engineer - £50K -£110K

Kent, England, United Kingdom
Robert Walters
global, market-leading insurance organisation that's shaping the future of digital health and technology. This is your opportunity to be part of an innovative, forward-thinking environment where security, engineering excellence, and customer impact are at the heart of everything we do! What you'll do: Provide hands-on technical expertise in secure software development within a product … improve secure CI/CD pipelines and modern security practices. Ensure risk management, security, and quality are embedded in software delivery. Implement and manage security tooling (SAST, DAST) to support development and testing. Adhere to best practices in architecture, design, coding standards, and SDLC. Mentor and support continuous improvement within the engineering community. What you'll bring … Technical leadership with strong decision-making and prioritisation skills. Expertise in secure systems design and infrastructure. Experience securing CI/CD pipelines and using security tools. Expertise in key technologies such as .NET/C#, Azure PaaS, Javascript, and Salesforce APEX, and in frameworks such as React, Node, React-Native, Playwright, etc Holds the right to work in the More ❯
Employment Type: Full-Time
Salary: £50,000 - £110,000 per annum, Pro-rata, Inc benefits
Posted:

Senior Security Engineer London

London, United Kingdom
Hybrid / WFH Options
Bondsmith Savings Ltd
where you will be making an impact on the financial lives of thousands of savers. We're regulated by the Financial Conduct Authority in the UK. As a Senior Security Engineer, you will play a key role in protecting our systems, networks, and data while ensuring compliance with industry leading security standards such as ISO 27001. Your contributions … will be essential in maintaining customer trust and safeguarding critical information assets. This role sits within thePlatform Engineering Teamand requires a strong technical background, hands-on experience with security tools, and a collaborative mindset to work effectively across teams. The role will involveplatform engineering activities, contributing to the design, implementation, and optimisation of scalable infrastructure. If you're motivated … technologies, including firewalls, intrusion detection/prevention systems (IDS/IPS), SIEM, antivirus solutions, encryption mechanisms, and vulnerability assessment tools. Hands-on experience in security tools (e.g., SAST, DAST, OWASP ZAP). Relevant security certifications, such as Security+, IAT II/III level, or equivalent. Strong capability in risk assessment, vulnerability management, and data informed decision-making. More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Senior Cloud Security Engineer Boston, Massachusetts, United States

London, United Kingdom
Acadian Asset
the firm managed approximately US$122 billion on behalf of major pension funds, endowments, foundations, governments and other investors based in the U.S. and abroad.Position Overview:The Senior Security Engineer, reporting to the Director of Information Assurance, is responsible for cloud platform and DevOps security. This senior role will call upon the candidate's DevSecOps experience to help Acadian … Shift Left, injecting security directly into our Software … Development Lifecycle and consistently governing our AWS Platform-as-a-Service (PaaS) infrastructure. We are looking for candidates with deep experience and understanding of continuous delivery, container security, SAST/DAST, secrets management, Identity and Access Management (IAM) governance, privilege management, encryption and key management, threat detection, logging, cloud infrastructure security and policy-as-code.What You'll Do More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Senior Security Engineer

London, United Kingdom
Omnea Limited
tougher times. What we're looking for We're hiring at both Level 3 (Senior) and Level 4 (Lead) . For calibration, candidates typically bring 5+ years of deep security engineering experience in high-growth, cloud-native SaaS environments - but we care more about impact than years. You'll be the first dedicated security specialist on the team … partnering with product engineers, GTM, and leadership to make Omnea the industry benchmark for security and trust. What You'll Do Make our … security posture airtight. Design and implement security controls across architecture, infrastructure and code (AWS Serverless, CDK/SST, React/TypeScript). Shift security left. Embed SAST/DAST, IaC scanning, secure coding standards and threat-modeling into every stage of our CI/CD pipeline. Own compliance & audits. Run our Vanta instance end-to-end (SOC More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Senior Platform Engineer

London, United Kingdom
Omnea Limited
tougher times. What we're looking for We're hiring at both Level 3 (Senior) and Level 4 (Lead) . For calibration, candidates typically bring 5+ years of deep security engineering experience in high-growth, cloud-native SaaS environments - but we care more about impact than years. You'll be the first dedicated security specialist on the team … partnering with product engineers, GTM, and leadership to make Omnea the industry benchmark for security and trust. What You'll Do Make our … security posture airtight. Design and implement security controls across architecture, infrastructure and code (AWS Serverless, CDK/SST, React/TypeScript). Shift security left. Embed SAST/DAST, IaC scanning, secure coding standards and threat-modeling into every stage of our CI/CD pipeline. Own compliance & audits. Run our Vanta instance end-to-end (SOC More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Staff Product Security Engineer London, United Kingdom

London, United Kingdom
Databricks Inc
The Product Security Team's mission is to Left-shift SDLC (Security Development Lifecycle) processes for ALL code written in Databricks (for Customer Use or Supporting Customer internally) to reduce the likelihood of introducing new vulnerabilities in production and minimize the count and effect of externally identified vulnerabilities on Databricks Services. You will be an individual contributor on … the product security team at Databricks, managing SDLC functions for features and products within Databricks. This would include, but is not limited to, security design reviews, threat models, manual code reviews, exploit writing and exploit chain creation. You will also support IR and VRP programs when there is a vulnerability report or a product security incident. You … Code Review, Exploit writing, etc. Work with other security teams to provide support for Incident Response and Vulnerability Response as and when needed. Work with the results of SAST tools to help evaluate and identify false positives and file defects for real issues. Work on DAST tools and related automation for auto-assessment and defect filing. Maintain the automation More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

DevOps Engineer - London Market

City of London, London, United Kingdom
CBSbutler Holdings Limited trading as CBSbutler
cloud landing zones (Azure/AWS) with environment segregation (dev, test, UAT, prod). - Automate infrastructure using Infrastructure as Code (Terraform, ARM, CloudFormation) - Embed security and compliance controls (SAST/DAST/IaC/SBOM). - Enable observability (logging, metrics, tracing, alerting) and support SRE/incident management practices. - Partner with client stakeholders to align DevOps with FCA/… operational resilience and Lloyd's standards. - Support disaster recovery and business continuity planning, including resilience testing. - Mentor client teams in DevOps best practices and drive shift-left adoption of testing, security, and compliance. Skills & Experience: - Proven expertise with CI/CD tooling (Azure DevOps, GitHub Actions, Jenkins, GitLab). - Strong knowledge of infrastructure automation (Terraform, Ansible, Puppet, Chef … . - Hands-on experience with Azure and/or AWS in enterprise or hybrid environments. - Familiarity with containerisation & orchestration (Docker, Kubernetes). - Solid understanding of security controls and compliance in financial services. - Experience with observability tools (Prometheus, Grafana, ELK, Splunk, AppDynamics, etc.). - Awareness of UK/EU financial regulations (GDPR, PRA/FCA, Lloyd's). - Consulting experience More ❯
Employment Type: Permanent
Salary: £75000 - £100000/annum Bonus + Full Benefits
Posted:

Security Development & Test Director

South East, United Kingdom
Hybrid / WFH Options
Anson Mccade
Security Development & Test Director ££140,000 - £155,000 GBP Hybrid WORKING Location: Central London, Greater London - United Kingdom Type: Permanent Security Development & Test Director Anson McCade England, United Kingdom (On-site) SaveApply Security Development & Test Director Hybrid - London or Birmingham | £140k-£155k base + 20% bonus + package Our client is a global security leader, operating … at the cutting edge of digital transformation, cloud integration, and enterprise security. With a workforce of 7500+ cybersecurity specialists and strategic partnerships with top-tier security tech providers, they're redefining how enterprise-grade security is built, deployed, and continuously improved. They're now seeking a Security Development and Test Director to lead their secure software engineering … in career development What you'll be doing: Leading secure architecture standards across engineering teams and embedding security within CI/CD workflows Owning security tooling strategy (SAST, DAST, SCA, container scanning) and driving adoption across development pipelines Building and mentoring high-performing teams in secure coding, DevSecOps, and threat modelling Leading engagements with major clients during pre More ❯
Employment Type: Permanent, Work From Home
Posted:

Principal Software Engineer

London, United Kingdom
Hybrid / WFH Options
BBC Group and Public Services
Press Tab to Move to Skip to Content Link Job Title: Principal Software Engineer - Security Engineer Job Reference: Band: BAND D Salary: £80,000-£90,000k depending on relevant skills, knowledge and experience. The expected salary range for this role reflects internal benchmarking and external market insights. Contract type: Permanent role Location: This is a hybrid role, and the … guidance. Promote secure SDLC practices across engineering teams, collaborating with InfoSec on shared tooling, templates and enablement. Help teams adopt secure coding standards and integrate automated security checks (SAST, DAST, dependency scanning) into CI/CD pipelines. Participate in threat modelling using InfoSec-led methodologies and coordinate validation and review workflows. Review technical designs, proposals and code for alignment … and common secure design patterns. You've helped teams adopt secure SDLC practices, working closely with central security or architecture groups. You know how to embed tools like SAST, DAST, secrets detection and dependency scanning into CI/CD pipelines, and have the scars to prove it. You've worked with complex, multi-tenant cloud platforms - ideally on AWS More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Security Development & Test Director

England, United Kingdom
Hybrid / WFH Options
Anson McCade
Security Development & Test Director Hybrid – London or Birmingham | £140k–£155k base + 20% bonus + package Our client is a global security leader, operating at the cutting edge of digital transformation, cloud integration, and enterprise security. With a workforce of 7500+ cybersecurity specialists and strategic partnerships with top-tier security tech providers, they're redefining how enterprise … grade security is built, deployed, and continuously improved. They're now seeking a Security Development and Test Director to lead their secure software engineering function, drive DevSecOps maturity, and embed security across the development lifecycle. This is a client-facing, commercially strategic position – ideal for a security leader who thrives at the intersection of technical delivery … in career development What you’ll be doing: Leading secure architecture standards across engineering teams and embedding security within CI/CD workflows Owning security tooling strategy (SAST, DAST, SCA, container scanning) and driving adoption across development pipelines Building and mentoring high-performing teams in secure coding, DevSecOps, and threat modelling Leading engagements with major clients during pre More ❯
Posted:

OpenShift Platform Engineer

England, United Kingdom
Hybrid / WFH Options
CBSbutler Ltd
Scripting in Bash or Python Able to support migration checklists, config validation, and post-migration testing Security Tooling experience and integration with CI/CD pipelines - SCA, SAST, DAST If you'd like to discuss this OpenShift Platform Engineer role in more detail, please send your updated CV to and I will get in touch. More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

OpenShift Platform Engineer

Newcastle upon Tyne, Tyne and Wear, Tyne & Wear, United Kingdom
Hybrid / WFH Options
CBSbutler Holdings Limited trading as CBSbutler
Scripting in Bash or Python Able to support migration checklists, config validation, and post-migration testing Security Tooling experience and integration with CI/CD pipelines - SCA, SAST, DAST If you'd like to discuss this OpenShift Platform Engineer role in more detail, please send your updated CV to (url removed) and I will get in touch. More ❯
Employment Type: Contract
Rate: £500 - £600/day
Posted:

Platform Security Engineer

London, United Kingdom
Searchworks Ltd
This is a huge opportunity for an experienced and driven Platform Security Engineer to join a rapidly growing fintech team! As a Platform Security Engineer, you will play a key role in protecting our clients systems, networks, and data while ensuring compliance with industry leading security standards such as ISO 27001. This role sits within the Platform … Engineering Team and requires a strong technical background, hands-on experience with security tools, and a collaborative mindset to work effectively across teams. What you'll do: Develop and implement proactive security strategies, policies, and procedures to protect our systems, networks, and data assets. Lead regular security assessments, including vulnerability scans and penetration tests, identifying risks and … technologies, including firewalls, intrusion detection/prevention systems (IDS/IPS), SIEM, antivirus solutions, encryption mechanisms, and vulnerability assessment tools. Hands-on experience in security tools (e.g., SAST, DAST, OWASP ZAP). Relevant security certifications, such as Security+, IAT II/III level, or equivalent. Strong capability in risk assessment, vulnerability management, and data informed decision -making. More ❯
Employment Type: Permanent
Salary: £90,000
Posted:

DevSecOps SME

London, United Kingdom
Hybrid / WFH Options
Adecco
Months IR35 Status: Inside IR35 Our client, a leading investment bank, is seeking an experienced DevSecOps SME to join their team. This role will lead and advise on integrating security practices into DevOps pipelines. The ideal candidate will have deep expertise across development, security, and operations, with a strong focus on automation, CI/CD, and secure software … development lifecycle (SDLC) practices. Key Responsibilities Lead the integration of security into CI/CD pipelines. Advise on secure coding and deployment practices across teams. Implement and enforce security policies, standards, and best practices. Conduct threat modeling, risk assessments, and vulnerability management. Mentor and train teams on DevSecOps … principles and tools. Skills & Experience Required CI/CD Security Engineering: Proven experience designing and maintaining secure CI/CD pipelines. DevSecOps Tool Integration: Hands-on experience with SAST, DAST, SCA, and secrets management tools. Cross-Functional Collaboration: Ability to work closely with development, operations, and security teams. Threat Modeling & Risk Assessment: Strong knowledge of security risk More ❯
Employment Type: Contract
Posted:

DevSecOps SME

London, South East, England, United Kingdom
Hybrid / WFH Options
Adecco
Months IR35 Status: Inside IR35 Our client, a leading investment bank, is seeking an experienced DevSecOps SME to join their team. This role will lead and advise on integrating security practices into DevOps pipelines. The ideal candidate will have deep expertise across development, security, and operations, with a strong focus on automation, CI/CD, and secure software … development lifecycle (SDLC) practices. Key Responsibilities Lead the integration of security into CI/CD pipelines. Advise on secure coding and deployment practices across teams. Implement and enforce security policies, standards, and best practices. Conduct threat modeling, risk assessments, and vulnerability management. Mentor and train teams on DevSecOps … principles and tools. Skills & Experience Required CI/CD Security Engineering: Proven experience designing and maintaining secure CI/CD pipelines. DevSecOps Tool Integration: Hands-on experience with SAST, DAST, SCA, and secrets management tools. Cross-Functional Collaboration: Ability to work closely with development, operations, and security teams. Threat Modeling & Risk Assessment: Strong knowledge of security risk More ❯
Employment Type: Contractor
Rate: Salary negotiable
Posted:

Senior Devops Solutions Engineer

dunfermline, north east scotland, united kingdom
Hybrid / WFH Options
Kosli
CD tools (Jenkins, GitHub Actions, GitLab etc.) Container platforms (Docker, Kubernetes) Infrastructure-as-code (Terraform, Ansible, Pulumi, CloudFormation) Cloud platforms (AWS, Azure, GCP) Security engineering tools and practices: SAST/DAST tools (Checkmarx, Veracode, SonarQube) Container security (Aqua, Snyk, Anchore) Programming and scripting languages (Python, Go, YAML, JSON etc.) A background in financial services or similar regulated industries. … Familiarity with compliance frameworks, and security requirements (e.g., ISO 27001, SOC 2, SOX, PCI DSS, FedRAMP, FFIEC, NYDFS, and SEC compliance requirements) A track record in consulting , solutions architecture , or technical coaching . Interest in technical sales and supporting go-to-market strategies. Excellent written and verbal communication skills, with the ability to translate complex technical topics to both … technical and non-technical stakeholders. AWS/Azure/GCP certifications, CISSP, CISM, or other security certifications are a plus Perks & Benefits Competitive salary. Generous equity plan. Remote-first working environment with regular travel to customer sites across Europe (London, Zurich, and more). Opportunity to work on innovative solutions with a passionate and driven team. If you are More ❯
Posted:

DevSecOps Advisory Consultant

London, South East, England, United Kingdom
Pontoon
will assist in the delivery on. In full: We are seeking a highly skilled and experienced DevSecOps Subject Matter Expert (SME) to lead and advise on the integration of security practices into our DevOps pipelines. This role requires a deep understanding of development, security, and operations, with a strong emphasis on automation, continuous integration/continuous deployment (CI … software development lifecycle (SDLC) practices. Advise and offer guidance on: * Design, implement, and maintaining secure CI/CD pipelines.* Integrate security tools and practices into DevOps workflows (e.g., SAST, DAST, SCA, secrets management).* Collaborate with development, operations, and security teams to implement and ensure secure coding and deployment practices.* Advise on threat modeling, risk assessments, and vulnerability … management.* Provide expert guidance on cloud security (AWS, Azure, GCP) and container security (Docker, Kubernetes).* Develop and enforce security policies, standards, and best practices.* Lead incident response and root cause analysis for security-related issues.* Mentor and train teams on DevSecOps principles and tools. Candidates will ideally show evidence of the above in their CV More ❯
Employment Type: Contractor
Rate: £800 - £900 per day
Posted:
Static Application Security Testing
England
10th Percentile
£68,750
25th Percentile
£70,000
Median
£78,810
75th Percentile
£105,000
90th Percentile
£109,875