Application Security Consultant

Vastbouw

Greater London

Hybrid

GBP 70,000 - 110,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Ricoh Europe is seeking an Application Security Consultant to join our Cyber, Risk & Security team. You will lead security reviews and help embed secure development practices across Europe.

You will work with engineering, DevOps, and product teams to implement SAST/DAST, CI/CD security, threat modelling, and secure AI considerations. Strong collaboration and the ability to translate security concepts for developers is essential.

Qualifications

  • Extensive hands-on experience in application security and secure development.
  • Proven ability to conduct thorough security reviews of complex applications.
  • Strong knowledge of vulnerability classes and secure coding practices.
  • Experience embedding security into CI/CD and DevSecOps environments.

Responsibilities

  • Lead application security reviews for high-risk products and services.
  • Conduct SAST, DAST, API security testing, fuzzing and architecture-level assessments.
  • Assess applications against OWASP Top 10 and other security standards.
  • Identify vulnerabilities and translate findings into remediation plans.
  • Provide secure design and coding guidance throughout the development lifecycle.
  • Help grow a pan-European Application Security capability within the Secure Development Centre of Excellence.
  • Promote consistent security methodologies and best practices.
  • Support secure coding standards across Java, C, C++, C#, Python and other languages.
  • Integrate security controls and testing into CI/CD pipelines (SAST, DAST, SCA).
  • Support threat modelling and vulnerability management across products.
  • Collaborate with developers, architects, DevOps and product owners to embed security into workflows.
  • Deliver security awareness sessions and developer-focused training.
  • Contribute to secure AI development initiatives, addressing AI model risks.
  • Monitor emerging threats and propose improvements.

Skills

Extensive experience in application‑s​
Hands-on security reviews
Security principles & vulnerabilities
CI/CD / DevSecOps security
Read/understand code (Java, C, C++, C#
Threat modelling (STRIDE)
App/API/Web security understanding
Clear vulnerability communication
Stakeholder management
Business/regulatory risk awareness

Tools

SAST, DAST, SCA tools

Job description

About Ricoh

A global leader in digital services, recognised for innovation, sustainability and a people-first culture. We feature in the Gartner Magic Quadrant, are listed in the Global 100 Most Sustainable Companies, and have been named one of Forbes’ World’s Best Employers 2025.

At Ricoh, we believe people do their best work when they feel valued and supported. We create inclusive workplaces where you can grow, contribute, and make a positive impact while helping to build a more sustainable future.

Find your place. Transform your future

Our purpose is centred on understanding and improving how people work. By focusing on real working experiences, we support individuals to develop their skills, realise their potential and do work that feels meaningful.

People transform when they Love What They Do

This belief sits at the heart of The Ricoh Promise. It guides how we recruit, how we support our people, and how we work together every day, creating an environment where you can grow, feel valued and make a difference.

When you join us, you are encouraged to share your ideas, challenge the way things are done, and work with others to build something better. If you are looking for a place where your voice is heard, your development is supported, and your work feels meaningful, you will feel at home at Ricoh.

We’re looking for an Application Security Consultant to join our Cyber, Risk & Security team and play a key role in strengthening application security across Ricoh Europe.

This is an opportunity to work at the intersection of software engineering, cybersecurity and risk, helping our teams adopt a genuine shift-left approach and making security part of the development lifecycle from design through to deployment.

You’ll work across both our internal IT environment and customer-facing products and services, helping protect solutions that are used by thousands of people every day and supporting the security of products delivered to customers across Europe.

#RicohEurope

What you will be doing

As our Application Security Consultant, you'll act as a technical authority and trusted advisor to engineering and product teams.

You’ll:

  • Lead application security reviews for high-risk products and services.
  • Conduct and oversee SAST, DAST, API security, fuzz testing and architecture-level assessments.
  • Assess applications against the OWASP Top 10 and other relevant security standards.
  • Identify vulnerabilities, understand their root causes and translate findings into practical remediation plans.
  • Provide secure design and coding guidance throughout the development lifecycle.
  • Help establish and evolve a pan-European Application Security capability within our Secure Development Centre of Excellence.
  • Develop and promote consistent application security methodologies, standards and best practices.
  • Support secure coding standards across technologies including Java, C, C++ and other relevant languages.
  • Integrate security controls and automated testing into CI/CD pipelines, including SAST, DAST and SCA.
  • Support threat modelling and vulnerability management across products and services.
  • Work closely with developers, architects, DevOps teams and product owners to embed security into their everyday workflows.
  • Deliver security awareness sessions, secure coding workshops and practical training for development teams.
  • Help shape our approach to secure AI development, including risks around AI models, data handling and misuse.
  • Monitor emerging application security threats and recommend improvements to our processes, tooling and development practices.
This is more than finding vulnerabilities

We're looking for someone who can go beyond identifying a security issue and explain why it matters, how it happened and what we can do differently next time.

You’ll need to be comfortable challenging established practices while building strong relationships with engineering teams. Your ability to translate complex security concepts into practical, developer-friendly guidance will be just as important as your technical expertise.

You’ll have the opportunity to influence security practices across multiple teams and geographies, helping create a more consistent and mature approach to secure development across Ricoh Europe.

You will ideally have

You’ll bring a strong software engineering and application security foundation, with:

  • Extensive experience in application security, secure development or software engineering with a security focus.
  • Hands-on experience conducting application security reviews.
  • Strong knowledge of application security principles and common vulnerability classes.
  • Experience with SAST, DAST and Software Composition Analysis (SCA) tools.
  • Experience implementing security within CI/CD and DevSecOps environments.
  • The ability to read and understand code in at least one major language such as Java, C, C++, C#, Python or similar.
  • Knowledge of secure software development lifecycles and shift-left security practices.
  • Experience with threat modelling, such as STRIDE or similar approaches.
  • Understanding of application, API and web security.
  • Experience interpreting security findings, identifying false positives and prioritising genuine risk.
  • The ability to communicate technical vulnerabilities clearly and turn them into actionable recommendations.
  • Strong stakeholder management skills, with confidence working with engineers, architects and product owners.
  • An understanding of how technical vulnerabilities translate into business, regulatory, financial and reputational risk.

Desired:

  • Experience with fuzz testing, advanced dynamic testing or manual code review.
  • Experience securing APIs, microservices or distributed systems.
  • Experience integrating SAST, DAST, SCA or secrets scanning into CI/CD pipelines.
  • Knowledge of secure architecture patterns across cloud-native, microservices or serverless environments.
  • Awareness of AI security, including model, data and prompt/model manipulation risks.
  • Experience delivering developer-focused
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Consultant
Application Security Consultant

Ricoh Europe • Greater London

On-site
GBP 70,000 - 110,000
Application Security Consultant
Application Security Consultant

Ricoh • City Of London

On-site
GBP 70,000 - 110,000
Senior Application Security Consultant
Senior Application Security Consultant

Ricoh • City Of London

On-site
GBP 70,000 - 110,000
IT Security Governance, Risk & Controls Analyst
IT Security Governance, Risk & Controls Analyst

Vastbouw • Greater London

Hybrid
GBP 65,000 - 90,000
IT Security Governance, Risk & Controls Analyst
IT Security Governance, Risk & Controls Analyst

Ricoh Europe • Greater London

On-site
GBP 60,000 - 90,000
Global community
Learning opportunities
Flexible rewards
Application Security Consultant: Secure DevOps & AI
Application Security Consultant: Secure DevOps & AI

Vastbouw • Greater London

Hybrid
GBP 70,000 - 110,000
Application Security Specialist: Shift-Left & Secure AI
Application Security Specialist: Shift-Left & Secure AI

Ricoh Europe • Greater London

On-site
GBP 70,000 - 110,000
IT Security Compliance & Reporting Analyst
IT Security Compliance & Reporting Analyst

Vastbouw • Greater London

Hybrid
GBP 52,000 - 86,000
Love to Connect
Love to Grow
Love to Give Back
+1
Application Security Specialist
Application Security Specialist

Experis - ManpowerGroup • Greater London

Hybrid
GBP 75,000 - 110,000
Competitive salary
Annual bonus
Car allowance
+7
Security Assurance Lead
Security Assurance Lead

Motability Operations Ltd • Greater London

On-site
GBP 70,000 - 100,000