Experience working with ISO 27001, Cyber Essentials, and preferably NIST CSF, SOC 2, or SWIFT frameworks. Strong understanding of security in the context of software development and applicationsecurity (OWASP, SDLC, DevSecOps). Hands-on, pragmatic approach with the ability to operate in a lean, fast-paced environment. Excellent communication skills, with the ability to engage both technical and non More ❯
with other teams to drive improvements in security across our entire organisation. What you'll have: Excellent security and technology background Strong understanding of webapplicationsecurity concepts, including OWASP Top 10 vulnerabilities, secure coding practices, and applicationsecurity testing tools Experience with security tools and technologies, such as webapplication firewalls (WAFs), and static and dynamic applicationsecurity testing More ❯
contribute to Red Team and social engineering operations. Support junior team members and engage in knowledge sharing. Key Skills & Experience: 3-5 years' penetration testing experience. Strong understanding of OWASP, SSL/TLS, SSH, and HTTP. Comfortable conducting black box, grey box, and white box testing. Familiar with tools like Kali, Burp Suite, Metasploit, Nmap, Nessus, and Qualys. Knowledge of More ❯
City of London, London, Grange, United Kingdom Hybrid / WFH Options
Applause IT Recruitment Ltd
contribute to Red Team and social engineering operations. Support junior team members and engage in knowledge sharing. Key Skills & Experience: 3-5 years' penetration testing experience. Strong understanding of OWASP, SSL/TLS, SSH, and HTTP. Comfortable conducting black box, grey box, and white box testing. Familiar with tools like Kali, Burp Suite, Metasploit, Nmap, Nessus, and Qualys. Knowledge of More ❯
to engage in various security projects and initiatives, encouraging new challenges and collaboration across teams. What you'll have: Strong security and technology background Understanding of webapplicationsecurity, OWASP Top 10, and testing tools Experience with security tools like WAFs, SAST/DAST Experience with endpoint (EDR, ZTNA) and cloud (CSPM, CNAPP) security tools Good AWS experience or knowledge More ❯
experience in mobile application development, with proficiency in Kotlin or Android SDK A solid understanding of security protocols, encryption, and authentication mechanisms Knowledge of relevant security frameworks, such as OWASP MASVS Expertise implementing and bypassing controls like certificate pinning, facial recognition, and biometric authentication controls Experience with secure coding practices and familiarity with industry standards (e.g., ISO 27001, NIST) Background More ❯
experience in InfoSec within fintech, SaaS, or regulated tech environments. Deep knowledge of cloud (AWS), DevSecOps, and secure SDLC practices. Strong understanding of compliance frameworks (PCI, GDPR, NIST, ISO, OWASP). Proven ability to manage audits, incidents, cross-functional teams, and regulators. Excellent interpersonal, leadership, and cross-functional collaboration skills. Demonstrated ability to operate effectively in a flat, fast-paced More ❯
experience Minimum 10 years of experience in cybersecurity, preferably in enterprise or financial environments Strong knowledge of: IAM, PKI, network & platform security, applicationsecurity, CI/CD security automation, OWASP, SAST/DAST Familiar with security frameworks (e.g. ISO 27001, NIST, DORA, GDPR) Able to bridge the gap between business objectives and technical solutions Languages: Professional level of English is More ❯
tools like Jenkins, GitLab, or similar. Experience implementing and managing SAST/DAST tools and processes to secure application development. Deep understanding of applicationsecurity, including secure coding practices, OWASP Top 10, and API security standards. Knowledge of Customer Identity and Access Management (CIAM) solutions and API security frameworks. Knowledge of one or more programming languages with the ability to … monitoring tools (e.g., SIEM, SOAR). The other stuff we are looking for We'd also love you to bring; Deep understanding of applicationsecurity, including secure coding practices, OWASP Top 10, and API security standards. Knowledge of Customer Identity and Access Management (CIAM) solutions and API security frameworks. Knowledge of one or more programming languages with the ability to More ❯
VPNs, and VLANs. Basic experience with SIEMs and security logs Understanding of vulnerability management practices Understanding of penetration testing, Threat Hunting, Red Teaming methodologies Familiarity with applicationsecurity and OWASP Top Ten Scripting languages Experience with capture-the-flags Familiarity with audit principles and different information security compliance standards Soft Skills: Analytical Thinking: Ability to assess risks, detect anomalies, and More ❯
including AWS Lambda, Spring Boot, NodeJS, Python FastAPI, Oracle, PostgreSQL and MongoDB. Build solutions as part of a DevSecOps and Agile ecosystem supported by tooling including Atlassian, Jenkins, GitLab, OWASP and AWS componentry. Ensure your solution works in a reliable and resilient way using Site Reliability Engineering methods to increase availability while reducing costs and callouts. Help the client and More ❯
Manchester, Lancashire, United Kingdom Hybrid / WFH Options
Deloitte LLP
including AWS Lambda, Spring Boot, NodeJS, Python FastAPI, Oracle, PostgreSQL and MongoDB. Build solutions as part of a DevSecOps and Agile ecosystem supported by tooling including Atlassian, Jenkins, GitLab, OWASP and AWS componentry. Ensure your solution works in a reliable and resilient way using Site Reliability Engineering methods to increase availability while reducing costs and callouts. Help the client and More ❯
Cambridge, Cambridgeshire, United Kingdom Hybrid / WFH Options
Deloitte LLP
including AWS Lambda, Spring Boot, NodeJS, Python FastAPI, Oracle, PostgreSQL and MongoDB. Build solutions as part of a DevSecOps and Agile ecosystem supported by tooling including Atlassian, Jenkins, GitLab, OWASP and AWS componentry. Ensure your solution works in a reliable and resilient way using Site Reliability Engineering methods to increase availability while reducing costs and callouts. Help the client and More ❯
Bristol, Gloucestershire, United Kingdom Hybrid / WFH Options
Deloitte LLP
including AWS Lambda, Spring Boot, NodeJS, Python FastAPI, Oracle, PostgreSQL and MongoDB. Build solutions as part of a DevSecOps and Agile ecosystem supported by tooling including Atlassian, Jenkins, GitLab, OWASP and AWS componentry. Ensure your solution works in a reliable and resilient way using Site Reliability Engineering methods to increase availability while reducing costs and callouts. Help the client and More ❯
Bristol, England, United Kingdom Hybrid / WFH Options
Deloitte LLP
including AWS Lambda, Spring Boot, NodeJS, Python FastAPI, Oracle, PostgreSQL and MongoDB. Build solutions as part of a DevSecOps and Agile ecosystem supported by tooling including Atlassian, Jenkins, GitLab, OWASP and AWS componentry. Ensure your solution works in a reliable and resilient way using Site Reliability Engineering methods to increase availability while reducing costs and callouts. Help the client and More ❯
Manchester, England, United Kingdom Hybrid / WFH Options
Deloitte LLP
including AWS Lambda, Spring Boot, NodeJS, Python FastAPI, Oracle, PostgreSQL and MongoDB. Build solutions as part of a DevSecOps and Agile ecosystem supported by tooling including Atlassian, Jenkins, GitLab, OWASP and AWS componentry. Ensure your solution works in a reliable and resilient way using Site Reliability Engineering methods to increase availability while reducing costs and callouts. Help the client and More ❯
London, England, United Kingdom Hybrid / WFH Options
Bondsmith
technologies, including firewalls, intrusion detection/prevention systems (IDS/IPS), SIEM, antivirus solutions, encryption mechanisms, and vulnerability assessment tools. Hands-on experience in security tools (e.g., SAST, DAST, OWASP ZAP). Relevant security certifications, such as Security+, IAT II/III level, or equivalent. Strong capability in risk assessment, vulnerability management, and data informed decision-making. Solid understanding of More ❯
technologies, including firewalls, intrusion detection/prevention systems (IDS/IPS), SIEM, antivirus solutions, encryption mechanisms, and vulnerability assessment tools. Hands-on experience in security tools (e.g., SAST, DAST, OWASP ZAP). Relevant security certifications, such as Security+, IAT II/III level, or equivalent. Strong capability in risk assessment, vulnerability management, and data informed decision-making. Solid understanding of More ❯
Experience in designing and building scalable, responsive systems. Experience in NoSQL such as ElasticSearch. Knowledge of technologies such as WebRTC, AJAX, and Web Sockets. Knowledge and experience working to OWASP ASVS or equivalent applicationsecurity standards. Proven experience of delivering applications with a high degree of usability. Experience of working in an Agile environment, preferably SCRUM. Framework experience such as More ❯
like LaunchDarkly Familiarity with Agile methodologies and product delivery frameworks. API development using asp.net core (C#) Exposure to using OAuth2.0/Open ID Connect in Angular applications. Familiarity with OWASP top 10 and securityweb applications. Company Benefits Competitive salary - accredited Living Wage employer 25 days holiday per year, plus bank holidays Option to purchase up to 5 additional days More ❯
Manchester, Lancashire, United Kingdom Hybrid / WFH Options
Lloyds Banking Group
Platform (GCP) Security & Compliance Cloud and a pplication security: Cloud posture management tools (e.g. Azure Dender, GCP SCCE), WAFs (e.g. Azure WAF, Cloud Armor AWS WAF), and protection against OWASP Top 10 and emerging threats. Network & infrastructure security: Network security principles (e.g. segmentation, monitoring, intrusion detection/prevention). Any experience in Zero Trust architecture in cloud environments would be More ❯
Manchester, England, United Kingdom Hybrid / WFH Options
Lloyds Banking Group
Platform (GCP) Security & Compliance Cloud and a pplication security: Cloud posture management tools (e.g. Azure Dender, GCP SCCE), WAFs (e.g. Azure WAF, Cloud Armor AWS WAF), and protection against OWASP Top 10 and emerging threats. Network & infrastructure security: Network security principles (e.g. segmentation, monitoring, intrusion detection/prevention). Any experience in Zero Trust architecture in cloud environments would be More ❯
Git. Experience working within an Agile environment, in particular Scrum, and applying supporting practices. In addition, any experience in the following would be beneficial: Knowledge and experience working to OWASP ASVS or equivalent applicationsecurity standards. Experience of recent .NET versions. Experience in developing containerized applications with Docker and using orchestration such as Kubernetes. Experience in NoSQL databases such as More ❯
London, England, United Kingdom Hybrid / WFH Options
Object Splendor
applications in production environments. Common architectural patterns (e.g. layered, hexagonal, clean). Databases (Including concepts like indexes and transaction scopes). Performance and monitoring. Security practices (e.g. understanding of OWASP Top 10). Be comfortable safely refactoring legacy code. Be able to work alongside client-facing support and product owners to analyse business requirements. Be keen to learn new technologies More ❯
cases and performance bottlenecks proactively. Implement and promote 15-factor app principles for highly scalable APIs and integrations. Work closely with security teams to ensure APIs are compliant with OWASP and API security patterns. Guide development teams on proper API design patterns, governance, and documentation practices. Required Skills: Strong expertise in MuleSoft Anypoint Platform (Design Center, Runtime Manager, API Manager More ❯