software security design review Strong knowledge of Agile, DevSecOps, System Engineer and or equivalent Knowledge of security standards and secure development principles such as NCSC Secure Development & Deployment Guidance, OWASP, NIST Secure Software Development Framework (SSDF - 800-218), Microsoft Azure Secure Development best practices, ISO27001 Experience with Azure cloud infrastructure, particularly Azure PaaS service Experience with Azure DevOps, particularly CI More ❯
Bristol, Avon, South West, United Kingdom Hybrid / WFH Options
Hargreaves Lansdown
technical knowledge of applicationsecurity architecture, cloud platforms (AWS, Azure, GCP), microservices, APIs, and identity/access management. Strong familiarity with modern programming languages, frameworks, and security vulnerabilities (e.g., OWASP Top Ten, SANS 25). Proven experience driving digital transformation initiatives, including migration of legacy applications to cloud-native platforms and adoption of SaaS/PaaS solutions. Understanding of UK More ❯
Employment Type: Permanent, Part Time, Work From Home
London, South East, England, United Kingdom Hybrid / WFH Options
Akkodis
and Azure DevOps (CI/CD) Familiar with scripting languages like PowerShell, YAML, JSON Expertise in applicationsecurity tools and DevSecOps processes Understanding of key frameworks and standards (e.g. OWASP, NIST SSDF, ISO27001, NCSC) Experience with threat modelling, risk assessments, and secure design reviews Comfortable owning security strategy and tooling across complex, modern product landscapes Strong communicator - able to engage More ❯
Government and Industry security and privacy framework standards such as ISO 27001 and GovAssure, identifying appropriate and proportionate remediation steps to address any compliance gaps. Desirable Criteria Awareness of OWASP projects, particularly Top 10s, ASVS, SAMM and DSOMM. Awareness of UK Government good practice guides 44 and 45 to support authentication and verification processes. Experience of securing the delivery and More ❯
Cambridge, Cambridgeshire, England, United Kingdom
Opus Recruitment Solutions Ltd
built solutions. Hands-on experience with Azure DevOps , CI/CD pipelines , and containerized environments ( Docker , Kubernetes ). Strong knowledge of API testing , performance profiling, and security practices including OWASP Top 10 and penetration testing . Familiarity with AI/ML systems , including LLM evaluation techniques, output scoring, and validation frameworks. Understanding of prompt engineering , RAG , model orchestration , and hallucination More ❯
EKS, AKS, OpenShift), CI/CD pipelines, and infrastructure as code (Terraform) Security integration experience across the DevSecOps lifecycle, including: SAST, DAST, SCA, and IAST tools (e.g., Checkmarx, Veracode, OWASP ZAP) Secrets management tools like HashiCorp Vault Vulnerability management solutions such as Prisma Cloud Testing frameworks like Selenium Familiarity with JIRA, Confluence, and GitLab/Jenkins-based CI/CD More ❯
EKS, AKS, OpenShift), CI/CD pipelines, and infrastructure as code (Terraform) Security integration experience across the DevSecOps lifecycle, including: SAST, DAST, SCA, and IAST tools (e.g., Checkmarx, Veracode, OWASP ZAP) Secrets management tools like HashiCorp Vault Vulnerability management solutions such as Prisma Cloud Testing frameworks like Selenium Familiarity with JIRA, Confluence, and GitLab/Jenkins-based CI/CD More ❯
EKS, AKS, OpenShift), CI/CD pipelines, and infrastructure as code (Terraform) Security integration experience across the DevSecOps lifecycle, including: SAST, DAST, SCA, and IAST tools (e.g., Checkmarx, Veracode, OWASP ZAP) Secrets management tools like HashiCorp Vault Vulnerability management solutions such as Prisma Cloud Testing frameworks like Selenium Familiarity with JIRA, Confluence, and GitLab/Jenkins-based CI/CD More ❯
EKS, AKS, OpenShift), CI/CD pipelines, and infrastructure as code (Terraform) Security integration experience across the DevSecOps lifecycle, including: SAST, DAST, SCA, and IAST tools (e.g., Checkmarx, Veracode, OWASP ZAP) Secrets management tools like HashiCorp Vault Vulnerability management solutions such as Prisma Cloud Testing frameworks like Selenium Familiarity with JIRA, Confluence, and GitLab/Jenkins-based CI/CD More ❯
. Proficient in Git or other version control systems. Desirable Knowledge, Skills and Experience: Certifications in OCI or other cloud platforms (AWS, GCP). Experience with security tools like OWASP ZAP, Burp Suite, etc. Familiarity with Jira, Confluence, or similar tools. Knowledge of compliance frameworks (e.g., GDPR, HIPAA, ISO 27001, ISO 13485). Background in start-up or scale-up More ❯
CD pipelines, Docker/Kubernetes, and IaC tools. Ops mindset: Proficiency with monitoring/observability tools (Prometheus, Grafana, ELK, Splunk). Security awareness: Knowledge of secure coding practices and OWASP considerations in Java applications. Financial acumen: Able to manage budgets and optimise spend on tools/services. Client-facing ability: Comfortable explaining technical issues in plain language to non-technical More ❯
problem-solving, communication, and high ownership. Desired Skills Experience with OpenSearch/ELK, Prometheus, or Grafana for logging/monitoring. Knowledge of compliance frameworks (ISO 27001, GDPR, NIST SSDF, OWASP ASVS/SAMM). Background in building and operating high-throughput, low-latency services. Strong mentoring and technical leadership abilities. This role is ideal for a high-agency engineer who More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Akkodis
/CD pipelines, plus scripting languages such as PowerShell, YAML, or JSON Knowledge of applicationsecurity tools, threat modelling, and risk assessments Familiarity with standards/frameworks such as OWASP, NIST SSDF, ISO27001, NCSC Experience guiding engineering teams and influencing security culture Excellent communication skills, able to engage confidently with developers and senior leadership Why join them? You'll be More ❯
through training, documentation, and direct engagement. DevSecOps Engineer - Requirements: 3-5+ years of experience in applicationsecurity or secure software development. Strong understanding of vulnerabilities and prevention techniques (OWASP Top 10). Experience with CI/CD pipelines and integrating AppSec tooling. Strong understanding of modern programming languages (JavaScript, Java, Python). Strong communication skills and ability to collaborate More ❯
Newton Abbot, Devon, England, United Kingdom Hybrid / WFH Options
Reed
Excellent problem-solving skills and attention to detail Commercial experience in professional PHP development Strong understanding of object-oriented programming and SOLID principles Knowledge of secure coding practices (e.g., OWASP) Strong experience with modern PHP frameworks (preferably Laravel or Symfony) Familiarity with relational databases (MySQL) and writing performant queries Comfortable working with Git, Composer, and modern development workflows Strong verbal More ❯
Gloucestershire, United Kingdom Hybrid / WFH Options
SSR General & Management
efforts for security breaches. Provide security guidance and training to teams across the organization. Key Skills & Experience: Strong knowledge of security frameworks (ISO 27001, NIST 800-30/53, OWASP) . Experience with risk management methodologies and compliance with MOD and HMG security standards (JSP, Def Stan 05-138/139). Proficiency in security threat modeling and risk assessments. More ❯
Bristol, Kendleshire, Gloucestershire, United Kingdom Hybrid / WFH Options
SSR General & Management
efforts for security breaches. Provide security guidance and training to teams across the organization. Key Skills & Experience: Strong knowledge of security frameworks (ISO 27001, NIST 800-30/53, OWASP) . Experience with risk management methodologies and compliance with MOD and HMG security standards (JSP, Def Stan 05-138/139). Proficiency in security threat modeling and risk assessments. More ❯
Newton Abbot, Devon, England, United Kingdom Hybrid / WFH Options
Reed
skills and attention to detail Commercial experience in professional PHP development Good commercial level of understanding of object-oriented programming and SOLID principles Knowledge of secure coding practices (e.g., OWASP) Commercial experience with modern PHP frameworks (preferably Laravel or Symfony) Familiarity with relational databases (MySQL) and writing performant queries Comfortable working with Git, Composer, and modern development workflows Strong verbal More ❯
At least 3 years of experience in software engineering. At least 2 years of experience in application security. In-depth knowledge of applicationsecurity vulnerabilities, testing techniques, and the OWASP framework. Team player able to build relationships across the organization. In-depth understanding of secure webapplication development. Experience in webapplication and Agile development methodologies. Comprehensive knowledge of IT More ❯
architecture Experience with security testing tools and techniques Familiarity with CI/CD pipelines and continuous security practices Knowledge of network security (OSI, TCP/IP), webapplicationsecurity (OWASP), and cryptographic controls (PKI, TLS) Demonstrated ability to lead, coach, and develop technical teams Excellent communication skills for technical and non-technical audiences Experience working in a consultancy environment, with More ❯
evolving field. Skills & Experience Essential: Ability to be on-site in Belfast three days per week. Authorisation to work in Ireland. Familiarity with cybersecurity frameworks and best practices (e.g., OWASP Top 10, NIST 800-53). Strong communication and stakeholder management skills. Development experience, ideally with authentication, authorization, SDKs, and APIs. Basic networking knowledge and a sound understanding of common More ❯
Reading, Berkshire, England, United Kingdom Hybrid / WFH Options
Nextech
the business. Actively contribute to incident response, security training, supplier reviews, and client security assurance Stay ahead of evolving threats, and help shape our strategy using frameworks such as OWASP, SASE, and Zero Trust. What We're Looking For Essential: Proven experience in cyber security engineering, including vulnerability management, SIEM, WAFs, and secure infrastructure design. Strong knowledge of TCP/ More ❯
internal teams, promoting knowledge sharing within and across teams. A good understanding of security frameworks including ISO27001/2, Cyber Essentials Plus, CIS Top 20, Data Protection Act 2018, OWASP Top 10. Have or be working towards relevant industry certification such as CISSP, CISM, CRISC or similar. Good understanding of governance and decision making in complex organisations Knowledge and experience More ❯
various security methodologies and processes, and technical security solutions Knowledge (but not a requirement) of the following security tools would be beneficial: SentinelOne, Taegis XDR, Tenable.io, Tanium Knowledge of OWASP, ApplicationSecurity and the principles of Secure Coding. Qualifications Experience as a Security/Network Administrator or equivalent knowledge Previous Security Operations Centre (SOC) experience would be a plus Experience More ❯