Application Security Engineer (Cyber)

Source Technology Limited

Greater London

Hybrid

GBP 90,000 - 120,000

Part time

43 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Source Technology Limited is seeking an Application Security Engineer (Cyber) for a London-based hybrid role within the Financial Services sector. You will define secure SDLC practices across projects, working with developers to produce secure code in tight timeframes and leading AppSec initiatives.

You will apply deep knowledge of OWASP, data protection, access management, and threat modelling, collaborating with product teams to triage findings and mitigate risks while driving security

Qualifications

  • Degree in Computer Science or Cyber Security.
  • Application development background.
  • Azure DevOps experience.
  • Experience using AI models for security evaluation.
  • Knowledge of OWASP Top 10 for AI-enabled security.
  • Ability to code in Python/JavaScript/C#/PowerShell.
  • Experience in Financial Services is an advantage.
  • Excellent analytical skills with attention to detail.
  • CISSP/CSSLP/CEH/OSCP or similar certification.
  • Presentation skills and ability to communicate to non-technical audiences.
  • Team-player interpersonal skills and collaboration.

Responsibilities

  • Design, maintain and build product security tools and services with software/security engineers.
  • Technical point of contact for automation, CI/CD, and AppSec operations.
  • Use AI models to assess application code for weaknesses and vulnerabilities.
  • Build tools and scripts enabling developers to consume security services.
  • Explain findings from penetration testing to engineers and guide mitigations.
  • Improve SAST, DAST, IaC and WAF/IDS tooling and coverage in cloud environments.

Skills

Azure DevOps
Python
JavaScript
C#
PowerShell
AI security models
GitHub Copilot
Security leadership
CISSP
English proficiency

Education

Computer Science / Cyber Security Degree

Tools

GitHub Copilot

Job description

Application Security Engineer (Cyber) - Financial Services

Contract - Inside I35

London - Hybrid

Who we're looking for

Our clients Cyber Security team is looking for a Cybersecurity engineer with expertise in Application Security domain, who will be responsible to define consistent Secure Software Development Lifecycle practices for all technology projects throughout the planning and delivery cycles that assure application security vulnerabilities are mitigated to tolerable levels.

The successful candidate will have very strong application security, web application development experience and team leadership skills to join a growing Information Security team and assist with the operation of the AppSec function.

About Us

Our client is a global investment manager. They help institutions, intermediaries and individuals around the world invest money to meet their goals, fulfil their ambitions, and prepare for the future.

They have around 5,000 people on six continents, have been around for over 200 years but keep adapting as society and technology changes. What doesn't change is the commitment to helping clients, and society, prosper.

What you'll do

In this position, you are a passionate and talented application security engineer with very deep understanding of OWASP, CWE 25, Data Protection, Access management, software vulnerabilities, best practices design and threat modelling skills, who can work in a dynamic environment. You must be dedicated to able to work with developers in producing secure code in short time frames and be willing to go beyond the standard routine.

Your primary responsibilities includes:

  • Work as part of a team of software and security engineers to design/maintain and build best-in-class product security tools and services.
  • Technical point of contact for product teams as it relates to automation, CI/CD, and Product Application Security Operations
  • Using approved AI models and cyber harnesses to assess application code for business logic weaknesses, misconfiguration and vulnerabilities.
  • Build tools and automation scripts that enable developers to easily consume security services delivered by Security Engineering and Automation team
  • Responsible for security product QA and Testing
  • Build strong relationships with product development teams
  • Run software composition analysis (SCA) tools
  • To understand and explain penetration testing findings to the software engineering teams helping them to triage the findings and explaining how to mitigate the risks
  • To articulate business risk when assessing software vulnerabilities
  • Continuously improve the operations of SAST, DAST and IaC security tools
  • Continuously improve the operations of Web Application Firewalls (WAF) or IDS
  • Continuously improve the coverage of security tooling in Cloud environments e.g. Microsoft Azure & Amazon AWS
The knowledge, experience and qualifications you need
  • Computer Science / Cyber Security Degree
  • Application Development background
  • Azure DevOps experience
  • Prior experience in using AI models and cyber harnesses to support security evaluation of application and software code.
  • GitHub, Copilot, Codex, OWASP Top 10 for Agentic AI, AI skills development and security triage.
  • Ability to code in at least one programming language e.g. Python/JavaScript/CSharp/Powershell
  • Prior experience working in a large organisation or Financial Services is an advantage
  • Excellent analytical skills with attention to details
  • CISSP/CSSLP/CEH/OSCP or similar certification
  • Presentation skills - ability to present complex solutions to a less technical audience
  • Team-player interpersonal skills, with the ability to communicate and collaborate effectively with different people in a variety of roles
  • Passionate about developing a career in Information Security
  • Excellent command of the English language, both written and spoken
What you'll be like
  • Passionate about mastering and innovating best practice in business analysis
  • Inspiring and collaborative leader, model of agile leadership approach
  • Friendly, approachable, enjoys working with people from a variety of backgrounds
  • Capable of remaining positive when under pressure
  • Continuous improvement mind-set, challenges the status quo and seeks self improvement
  • Problem solver, comfortable taking the initiative in challenging and ambiguous circumstances
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Consultant (SAST/DAST/OWASP )
Senior Application Security Consultant (SAST/DAST/OWASP )

Salt • Greater London

Hybrid
Hybrid work model
Senior Application Security Consultant
Senior Application Security Consultant

Salt • Greater London

Hybrid
GBP 90,000 - 120,000
Senior Application Security Consultant (SAST/DAST/OWASP )
Senior Application Security Consultant (SAST/DAST/OWASP )

Xpand Group • Greater London

Hybrid
GBP 115,000 - 138,000
Application Security Consultant
Application Security Consultant

Cytix • Manchester

Hybrid
GBP 40,000 - 50,000
Private Healthcare (inc. dental, optical, and hearing)
Unlimited Holidays
EMI share options
Senior Application Security Specialist
Senior Application Security Specialist

La Fosse • Greater London

Hybrid
Senior Application Security Consultant (SAST/DAST/OWASP )
Senior Application Security Consultant (SAST/DAST/OWASP )

Salt • City Of London

Hybrid
GBP 66,000 - 111,000
Cyber Security Architect
Cyber Security Architect

Wipro • Manchester

On-site
GBP 55,000 - 75,000
Security Architect - Product and Application Security
Security Architect - Product and Application Security

Harrington Starr • Greater London

Hybrid
GBP 90,000 - 130,000
Application Security Engineer (Cyber) - Secure SDLC Lead
Application Security Engineer (Cyber) - Secure SDLC Lead

Source Technology Limited • Greater London

Hybrid
GBP 90,000 - 120,000
Application Security Engineer
Application Security Engineer

Ignite Digital • Greater London

Hybrid
GBP 90,000 - 120,000
Competitive Salary + Bonus
25 days of annual leave
Private medical and dental cover
+4