London, United Kingdom Posted on 24/02/2025 Job Description: SecurityTesting Engineer Location: Remote with occasional travel as required Employment Type: Permanent About the Role Scrumconnect Consulting is looking for a SecurityTesting Engineer to ensure the security, resilience, and compliance of … GOV.UK digital services . This role involves identifying vulnerabilities, mitigating security risks, and ensuring adherence to government security policies and DDAT frameworks . You will work closely with developers, security architects, and business stakeholders to embed securitytesting into Agile development workflows and DevSecOps pipelines. … comprehensive security test plans for GOV.UK digital services. Identify security vulnerabilities through static and dynamic applicationsecuritytesting (SAST & DAST) . Ensure securitytesting is seamlessly integrated into CI/CD pipelines and DevSecOps processes. Define security requirements and best practices More ❯
Manchester, North West, United Kingdom Hybrid / WFH Options
Secure Recruitment Ltd
SOFTWARE APPLICATIONSECURITY ENGINEER £90,000 + 15% Bonus + Excellent Staff Benefits including Strong Pension, Life Assurance Hybrid Working ( 2 Days per Week Onsite ) An interesting opportunity has presented itself within one of the UKs largest Independent Software Based Organisations who are one of a major driving … forces behind Innovative Development of Enterprise-Led Internet Technology. They are now looking for an ApplicationSecurity Engineer to join their existing & high performing In - House Security Team of 35 Staff including SOC & Cyber Analysts through to Experienced Cyber Security Engineers & Security Architects. As an … AppSec Engineer you will focus on the technical side of IT Security, specifically looking at ApplicationSecurity & Code Analysis, ensuring their Applications are Built Securely. The Information & Cyber Security Team deal with the Security of Closed-Sourced, Open-Source & In-House Developed Applications ensuring that More ❯
Job Title: ApplicationSecurity Engineer Job Type: Permanent Location: UK or Europe (Remote) Salary: $150,000 - $180000 About the Role My client is seeking an ApplicationSecurity Engineer to strengthen our security posture by identifying vulnerabilities, integrating best practices into CI/CD pipelines , and … ensuring compliance with PCI DSS, SOC 2, GDPR, and CCPA . You'll work closely with development teams to embed security into the Software Development Lifecycle (SDLC) from the ground up. If you're passionate about securing applications and solving complex security challenges, we want to hear from … Conduct security reviews and threat modeling during the application design phase. Perform static and dynamic applicationsecuritytesting (SAST/DAST) on internal and third-party applications. Define and maintain security standards for software development. Integrate security tools and processes into CI More ❯
Your expertise in DevOps, combined with your deep understanding of security, will help us incorporate StaticApplicationSecurityTesting (SAST) scanning and other security measures throughout our development lifecycle. Engaging with colleagues across Gallagher Re, you'll have an inquisitive approach to your work … travel to this will be required. How you'll make an impact Design, implement, and maintain secure and efficient CI/CD pipelines, integrating SAST scanning and other security tools Collaborate with development, operations, and security teams to ensure security best practices are followed throughout the development … on security, preferably in a Senior DevSecOps Engineer or similar role Hands-on experience with StaticApplicationSecurityTesting (SAST) tools and their integration into CI/CD pipelines Deep understanding of security concepts, practices, and technologies, such as access control, encryption, and vulnerability More ❯
Senior Security Engineer We are seeking an experienced Senior Security Engineer to join our dynamic Security Team. In this key role, you will be a key contributor to Funding Circle's cloud and applicationsecurity posture. You will leverage your deep expertise in AWS security, secure software development lifecycle (SSDLC) practices, and CI/CD security to implement and champion robust security solutions. You will act as a subject matter expert and mentor, collaborating closely with engineering and product teams to embed security seamlessly into our cloud infrastructure and development processes … designing, implementing, securing, and managing a wide range of AWS security services. Proven, hands-on experience architecting, building, and integrating security tooling (SAST, DAST, SCA, secrets management, IAST) and automated security controls within CI/CD pipelines (e.g., GitLab CI, Jenkins, GitHub Actions). Strong track record More ❯
Manchester, Lancashire, United Kingdom Hybrid / WFH Options
慨正橡扯
A Senior Information Security Specialist, who will focus on the technical side of IT Security, specifically looking at applicationsecurity and code analysis to ensure applications are built securely. The applicationsecurity team deals with the security of closed source, open source, and … that is secure and compliant with the Company's regulatory obligations. You will be working closely with the software development function to ensure that application-based vulnerabilities are understood and mitigated. It is therefore important that you possess an understanding of the Secure Software Development Lifecycles and the assessment … of code. This role is part of the broader Information Security department, which is comprised of engineers and analysts with varying backgrounds. Collectively, the team utilises enterprise and bespoke tooling to identify and mitigate threats to safeguard the Business. This role is eligible for inclusion in the Company's More ❯
Manchester Area, United Kingdom Hybrid / WFH Options
bet365
Who we are looking for A Senior Information Security Specialist, who will focus on the technical side of IT Security, specifically looking at applicationsecurity and code analysis to ensure applications are built securely. The applicationsecurity team deal with the security of … that is secure and compliant with the Company’s regulatory obligations. You will be working closely with the software development function, to ensure that application based vulnerabilities are understood and mitigated. It is therefore important that you possess an understanding of the Secure Software Development Lifecycles and the assessment … of code. This role is part of the broader Information Security department, which is comprised of engineers and analysts with varying backgrounds. Collectively, the team utilises enterprise and bespoke tooling to identify and mitigate threats to safeguard the Business. This role is eligible for inclusion in the Company’s More ❯
Stoke-On-Trent, England, United Kingdom Hybrid / WFH Options
bet365
Who we are looking for A Senior Information Security Specialist, who will focus on the technical side of IT Security, specifically looking at applicationsecurity and code analysis to ensure applications are built securely. The applicationsecurity team deal with the security of … that is secure and compliant with the Company’s regulatory obligations. You will be working closely with the software development function, to ensure that application based vulnerabilities are understood and mitigated. It is therefore important that you possess an understanding of the Secure Software Development Lifecycles and the assessment … of code. This role is part of the broader Information Security department, which is comprised of engineers and analysts with varying backgrounds. Collectively, the team utilises enterprise and bespoke tooling to identify and mitigate threats to safeguard the Business. This role is eligible for inclusion in the Company’s More ❯
ApplicationSecurity Consultant (AppSec) Permanent Role Fully Remote Up to £80K per annum Are you a skilled applicationsecurity professional with a strong grasp of cloud-native development and a passion for safeguarding software systems? Join an innovative cyber security consultancy working at the forefront … of resilience, supporting clients across the military, government, finance, and tech sectors. As an ApplicationSecurity Consultant, you'll be the go-to expert on software-level threats and controls. You'll play a key role in embedding security within cloud-native development environments-particularly AWS-by … development teams in secure coding best practices through workshops, threat modelling, and code reviews. Define and enforce security checkpoints across the DevOps lifecycle (SAST, DAST, SCA). Champion secure API design, including robust authentication, authorisation, and validation techniques. Identify and mitigate security vulnerabilities through reviews and penetration test More ❯
Our client a large global financial services company are currently looking for an ApplicationSecurity Engineer to join their team on a long-term contract basis. The role is a 50/50 hybrid working … split, and an exciting opportunity to join them at a time of growth. The right person for the role will have experience with: Strong SAST tooling experience Experience in the development of applications and are up to date with the current evolutions in the domain of application development Strong … interest in applicationsecurity and your ambition is to be become an expert in this domain in the next 3-5 years. Very good understanding of Software development lifecycle in an Agile environment and you understand DevOps Good understanding of software development lifecycle and the security checks More ❯
UK based, primarily remote working with some travel required to our London Office. Sponsorship is not available for this role. What you will do: Security Integration in CI/CD Pipelines: Implement security controls within CI/CD pipelines using automation and best practices, ensuring vulnerabilities are caught … Incident Response: Develop and maintain monitoring systems and respond to security incidents quickly and effectively. Automated SecurityTesting: Integrate and manage SAST, DAST, and other securitytesting tools to identify security issues in code and applications. Compliance and Governance: Develop and manage Azure policies … such as vulnerability scanners, intrusion detection systems, & security information & event management (SIEM) solutions. Knowledge of container management with Azure Container Registry. Experience in SAST, DAST & other techniques to improve code security Desirable: Proficiency in scripting, preferably with PowerShell. Understanding of DotNet development and deployment pipelines. Experience working with More ❯
Principal Product Security Engineer Apply locations CZ - Prague UK - London time type Full time posted on Posted 6 Days Ago job requisition id JR103958 Our Product Security team is seeking a Principal Product Security Engineer to define and lead a secure development strategy and approach in a … fast-paced, agile development environment. You will be responsible for defining and driving security-related initiatives in collaboration with internal stakeholders. You will bring a wealth of technical expertise and industry experience spanning applicationsecurity, cloud security, DevSecOps and CI/CD. The ideal candidate for … experience with secure software development lifecycle, securitytesting, vulnerability management. Experience with cloud technologies (AWS, Azure), securitytesting and automation (SAST, DAST, SCA), and AI/ML technologies. Deep understanding of DevSecOps principles and agile development. Knowledge of secure architecture and design principles, industry standards (NIST More ❯
to help shape the new flagship development center and contribute to high-impact projects in a thriving tech environment. Position Overview: Were expanding our applicationsecurity team and are looking for someone with Java and Python experience. Youll focus on a subset of our products to understand them … development teams build products that are secure by design. What you will do: Youll support product teams through activities such as: Defining requirements for security features Proactively identifying and controlling risks using techniques like threat modeling Designing and implementing automated security tests Performing manual security assessments including … least one JavaScript framework Test design Unit tests and end-to-end tests both automated and manual A proven history of turning SCA/SAST/DAST results into teachable moments Application penetration testing experience is a bonus. Fluency in English What you'll gain at Intapp: Our More ❯
belfast, antrim, united kingdom Hybrid / WFH Options
Intapp
to help shape the new flagship development center and contribute to high-impact projects in a thriving tech environment. Position Overview: Were expanding our applicationsecurity team and are looking for someone with Java and Python experience. Youll focus on a subset of our products to understand them … development teams build products that are secure by design. What you will do: Youll support product teams through activities such as: Defining requirements for security features Proactively identifying and controlling risks using techniques like threat modeling Designing and implementing automated security tests Performing manual security assessments including … least one JavaScript framework Test design Unit tests and end-to-end tests both automated and manual A proven history of turning SCA/SAST/DAST results into teachable moments Application penetration testing experience is a bonus. Fluency in English What you'll gain at Intapp: Our More ❯
lisburn, antrim, united kingdom Hybrid / WFH Options
Intapp
to help shape the new flagship development center and contribute to high-impact projects in a thriving tech environment. Position Overview: Were expanding our applicationsecurity team and are looking for someone with Java and Python experience. Youll focus on a subset of our products to understand them … development teams build products that are secure by design. What you will do: Youll support product teams through activities such as: Defining requirements for security features Proactively identifying and controlling risks using techniques like threat modeling Designing and implementing automated security tests Performing manual security assessments including … least one JavaScript framework Test design Unit tests and end-to-end tests both automated and manual A proven history of turning SCA/SAST/DAST results into teachable moments Application penetration testing experience is a bonus. Fluency in English What you'll gain at Intapp: Our More ❯
newtownabbey, antrim, united kingdom Hybrid / WFH Options
Intapp
to help shape the new flagship development center and contribute to high-impact projects in a thriving tech environment. Position Overview: Were expanding our applicationsecurity team and are looking for someone with Java and Python experience. Youll focus on a subset of our products to understand them … development teams build products that are secure by design. What you will do: Youll support product teams through activities such as: Defining requirements for security features Proactively identifying and controlling risks using techniques like threat modeling Designing and implementing automated security tests Performing manual security assessments including … least one JavaScript framework Test design Unit tests and end-to-end tests both automated and manual A proven history of turning SCA/SAST/DAST results into teachable moments Application penetration testing experience is a bonus. Fluency in English What you'll gain at Intapp: Our More ❯
Job Title: ApplicationSecurity (AppSec) Consultant Location: Remote (UK-based only) Salary: Up to £80,000 Type: Full-time, Permanent Are you passionate about building secure software and driving real impact in the world of cybersecurity? Our client, a cutting-edge cyber consultancy, is seeking an ApplicationSecurity Consultant to strengthen their growing technical team. This is a fully remote role, offering the chance to work alongside experts from diverse industries including defence, finance, and tech— while making a real difference. What You’ll Be … Doing: Partnering with developers and engineers to bake security into every stage of the software development lifecycle. Enhancing DevSecOps practices with tools like SAST, DAST, and SCA—making sure security isn’t just an afterthought. Leading secure code reviews, threat modelling sessions, and providing practical guidance on secure More ❯
consistently updating our job descriptions to ensure we continue to lead in banking innovation. How you will contribute and key responsibilities: As a Senior Security Engineer, you will be instrumental in designing and implementing security measures for our mobile applications, services, and websites to meet the highest security standards. Your expertise will help us continuously analyse and improve our security systems, ensuring that our products and services are not only secure by design but also comply with internal and external regulatory requirements. Other responsibilities include: Security Analysis and Improvement: Continuously analyse our security systems … and monitoring, networks, firewalls, load balancers, DNS, CDNs Working knowledge of agile DevSecOps environments, and CI/CD (Git, Concourse, Terraform) Working knowledge of SAST, DAST, RASP, and IAST tools and building security into existing SDLC processes Knowledge of cloud Security Architecture of public clouds (such as AWS More ❯
Determine the strategy to secure the company’s platforms, including the Kubernetes technology stack and the legacy solutions, while adapting a pragmatic approach balancing security and development velocity. Improve the company’s security standing by developing security features and deploying security products in the company’s … cloud infrastructure (account management, network infrastructure, identity and access management, secret management, security monitoring and automation, and production machine access). Represent the Security Team as point of contact and source of knowledge in Design Review meetings across Engineering; perform threat analysis, define security controls and security … widespread adoption). It’d be really cool if you also: Have experience with threat modeling, performing security audits, penetration testing, and SAST tools. Have production experience with technologies like Kubernetes, Docker, Istio, Prometheus, Vault, Consul, and infrastructure as code. Have published security papers, blogs, or talks More ❯
this position, you'll spearhead Cyber projects with plans to build your own team in 2025 The role combines two dynamic elements: Core IT Security: Leverage your deep technical expertise to maintain the security of our infrastructure, servers, and systems. From leading our Managed Security Service Providers … all new systems and services. Drive application and platform security by conducting penetration tests, running audits, and managing automated scans like SCA, SAST, and DAST. Maintain a strong Cloud Security Posture by continuously improving infrastructure, processes, and policies. Risk & Compliance Own vulnerability and threat management, identify risks … VNets, application gateways, private and service endpoints, and firewalls. Secure Software Development: Deep experience implementing effective secure coding practices (e.g., OWASP Top 10, SAST, DAST, SonarCloud). You can seamlessly integrate security into the SDLC with a shift-left approach. Cloud Security Tools: Practical experience with Azure More ❯
About the role: As a Senior Security Engineer II in the Platform Engineering team, you’ll play a critical role in securing Forter’s high-scale, real-time decision-making platform. You’ll drive security strategy for customer-facing production APIs while balancing development velocity with robust security controls. If you're passionate about building security into the foundation of fast-moving engineering teams, this role offers the autonomy and impact you're looking for. You will have the task of improving the company’s security standing by developing security features and deploying security … including the ability to drive cross-team security initiatives Nice-to-Have Experience with threat modeling, security audits, penetration testing, or SAST tools Contributions to security research, blogs, talks, or open-source security projects Benefits include: Competitive salary Quarterly company bonus Private health insurance, including More ❯
Reston, Virginia, United States Hybrid / WFH Options
ICF
on offering a full range of architecture and planning, system implementation, integration, analytics and O&M for our customers. We are seeking a Senior Security Engineer to support our Federal customer's CIO Cyber Security organization and manage all vulnerability remediation activities, including Binding Operational Directive (BOD) compliance. … Responsibilities: Perform Security Impact Analyses on application releases and provide recommendations to federal leadership Perform software vulnerability scans, interpret the results, and provide vulnerability mitigation recommendations Support and develop analyses of alternatives and decisions on courses of action by providing security insights to project teams and federal … FISMA and NIST requirements, 508 compliance and other Federal IT security management guidelines. Experience with OWASP, Splunk, Java, SQL Experience with DAST and SAST Working Knowledge of CI/CD, APIs and WAF Working at ICF ICF is a global advisory and technology services provider, but we're not More ❯
London-based Quant Trading fund is looking for a Senior Security Architect to influence architecture and lead strategic security projects during a period of rapid expansion. The incoming Security Architect will work with IT, cloud, and engineering teams to implement security solutions for low-latency systems … and multi-cloud platforms (AWS and Azure). Whilst this is predominantly a security architecture role, the incoming architect will perform an advisor/consulting role, helping to guide and influence technology stakeholders to build secure and robust systems. Role and Responsibilities: Support the implementation of security controls … environments Perform vendor security reviews to assess third-party security practices and ensure compliance with standards Integration of security scanning tools (SAST, DAST, etc.) into CI/CD pipelines and runtime environments to ensure continuous security monitoring and threat detection across Cloud - AWS, Azure, and on More ❯
london, south east england, united kingdom Hybrid / WFH Options
Xcede
London-based Quant Trading fund is looking for a Senior Security Architect to influence architecture and lead strategic security projects during a period of rapid expansion. The incoming Security Architect will work with IT, cloud, and engineering teams to implement security solutions for low-latency systems … and multi-cloud platforms (AWS and Azure). Whilst this is predominantly a security architecture role, the incoming architect will perform an advisor/consulting role, helping to guide and influence technology stakeholders to build secure and robust systems. Role and Responsibilities: Support the implementation of security controls … environments Perform vendor security reviews to assess third-party security practices and ensure compliance with standards Integration of security scanning tools (SAST, DAST, etc.) into CI/CD pipelines and runtime environments to ensure continuous security monitoring and threat detection across Cloud - AWS, Azure, and on More ❯
Oxford, Oxfordshire, United Kingdom Hybrid / WFH Options
Sophos Group
About Us Sophos is a global leader and innovator of advanced security solutions for defeating cyberattacks. The company acquired Secureworks in February 2025, bringing together two pioneers that have redefined the cybersecurity industry with their innovative, native AI-optimized services, technologies and products. Sophos is now the largest pure … with internal product and engineering teams to identify potential issues in product designs. Assist in the adoption of shared cybersecurity services such as SCA, SAST, and DAST. Participate in the development and adoption of new standards and policies. Impart education to key stakeholders from both technology and business teams regarding … SSDF, ASVS, and other cybersecurity frameworks. Knowledge of cryptographic techniques and implementations. Familiarity with security tooling used to support a SSDLC (SCA/SAST/DAST/container scanning). A strong desire to stay current and understand emerging technologies and risks. Strong project management skills to drive and More ❯