DevSecOps and Attack Surface Specialist

RSA Group

Greater London

Hybrid

GBP 90,000 - 120,000

Full time

5 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Annual discretionary bonus
Up to 11% pension contributions
25 days annual leave + bank holidays +
buy/sell options
Career development and mentoring
Inclusive culture + employee networks
Share investment options

Job summary

Intact Insurance, formerly RSA, is enhancing its security stance in the UK. We seek a DevSecOps and Attack Surface Specialist to embed security across the software development lifecycle and AI systems. You will lead SAST/DAST programs, manage external attack surfaces, and drive AI-focused security initiatives.

You will collaborate with engineering, product, and operations teams to implement automated controls, perform vulnerability validation, and champion secure coding practices across the org.

Qualifications

  • Proven experience across the full software development lifecycle security.
  • Hands-on with SAST/ SCA tooling (Semgrep, Checkmarx, Snyk, OWASP Dependency Check).
  • Experience configuring DAST tools (OWASP ZAP, Burp Suite Enterprise, Invicti).
  • Ability to triage, validate, and reproduce vulnerabilities with manual testing and proof of concept development.
  • Knowledge of secure coding practices across common languages.
  • Familiarity with CI/CD pipelines and automated security gates.
  • Experience with attack surface management and asset discovery.

Responsibilities

  • Champion shift-left security by integrating automated controls early in development.
  • Lead application security initiatives, including Pentest, SAST, SCA and DAST scanning and remediation.
  • Manage external application attack surface by monitoring domains and assets.
  • Drive integration of AI-specific security practices across the organisation.

Skills

Application security
SAST & SCA tooling
DAST tools
Vulnerability triage
Secure coding
CI/CD security gates
Attack surface management

Tools

Semgrep
Checkmarx
Snyk
OWASP Dependency Check
OWASP ZAP
Burp Suite Enterprise
Invicti

Job description

Intact Insurance is the new name for RSA in the UK, Ireland, and across Europe. It’s a new name and a new way to do business. Backed by global expertise and a commitment to service that feels different, we’re focused on making insurance simpler, faster, and more responsive.

Shape the future:

We’re leading a transformation in insurance helping people, businesses and society prosper in good times and be resilient in bad times. When you join us, you’re not just taking a job, you’re stepping into a career where you can make a real difference.

Grow with us:

We’re customer-driven, community-focused, and committed to helping our people grow. Whether you’re early in your journey or bringing years of experience, we’ll support you with the tools, flexibility, and opportunities to thrive.

Win as a Team:

The DevSecOps and Attack Surface Specialist is responsible for embedding security across the software development lifecycle and extending that posture to artificial intelligence systems. The role sits at the intersection of secure software engineering, offensive testing, attack surface management, and emerging AI risks, acting as both a technical practitioner and a collaborative partner to engineering, product, and operations teams.

You’ll make an impact by:
  • The specialist will champion a shift left philosophy, driving automated security controls earlier in the development process while maintaining rigorous validation of vulnerabilities identified through dynamic and static testing.
  • You will lead application security initiatives, managing Pentest, SAST, SCA and DAST scanning and remediation activities and maintaining asset inventories.
  • The specialist will be responsible for managing Intact’s external application attack surface by monitoring and assessing new and existing domains.
  • You will also lead the integration of AI specific security practices across the organisation and also support the expansion of AI capabilities within the cyber defence team.
Your skills and experience:
  • Strong understanding of application security principles across the full software development lifecycle
  • Hands on experience with SAST and SCA tooling such as Semgrep, Checkmarx, Snyk, and OWASP Dependency Check
  • Experience configuring and operating DAST tools such as OWASP ZAP, Burp Suite Enterprise, and Invicti
  • Ability to triage, validate, and reproduce vulnerabilities through manual testing and proof of concept development
  • Working knowledge of secure coding practices across common languages and frameworks
  • Familiarity with CI and CD pipeline integration, including implementation of security gates and automated controls
  • Experience with attack surface management, including asset discovery, domain enumeration, and external exposure analysis
Why You’ll Love It Here:

Being part of our team means you’ll have the support and freedom to bring your best self to work each day. As a permanent member, here’s what you can look forward to

  • Annual discretionary bonus
  • Up to 11% pension contributions
  • 25 days annual leave + bank holidays + buy/sell options
  • Career development and mentoring
  • Inclusive culture + employee networks
  • Share investment options
Our DEI Commitment:

We celebrate individuality and believe our differences make us stronger. We’re proud to foster a culture where everyone feels respected, valued, and empowered to thrive.
As an Equal Opportunity and Disability Confident Employer, we ensure fair consideration for all applicants and offer interviews to all disabled candidates who meet the essential criteria.
We understand that everyone’s circumstances are different and are happy to explore flexible working options such as reduced hours or job shares to support work–life balance.
If you meet the core criteria but not every requirement, we’d still love to hear from you. Let’s explore how this role could support your next career step. If you need adjustments during the recruitment process, just let us know we’re here to support you.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps and Attack Surface Specialist
DevSecOps and Attack Surface Specialist

RSA Security LLC • Greater London

On-site
GBP 90,000 - 130,000
Annual discretionary bonus
Pension contributions
25 days annual leave + holidays
+3
DevSecOps and Attack Surface Specialist
DevSecOps and Attack Surface Specialist

Royal & Sun Alliance Insurance Ltd • City Of London

Hybrid
GBP 70,000 - 110,000
Annual discretionary bonus
Up to 11% pension contributions
Hybrid working
+5
DevSecOps and Attack Surface Specialist
DevSecOps and Attack Surface Specialist

Intact Insurance UK • Greater London

Hybrid
GBP 80,000 - 110,000
Annual discretionary bonus
Up to 11% pension contributions
Hybrid working
+5
Associate Cyber Security Engineer
Associate Cyber Security Engineer

RSA Security LLC • Greater London

On-site
GBP 55,000 - 85,000
Annual discretionary bonus
Up to 11% pension contributions
25 days annual leave + bank holidays +
+4
Senior Threat Intelligence Analyst
Senior Threat Intelligence Analyst

RSA Group • Horsham

On-site
GBP 70,000 - 110,000
Annual discretionary bonus
Up to 11% pension contributions
25 days annual leave + bank holidays +
+4
Cyber Defence Transformation Analyst
Cyber Defence Transformation Analyst

RSA Security LLC • Greater London

Hybrid
GBP 65,000 - 85,000
Annual discretionary bonus
Pension contributions up to 11%
25 days annual leave + bank holidays +
+3
Associate Cyber Security Engineer
Associate Cyber Security Engineer

Intact Insurance UK • Greater London

Hybrid
GBP 42,000 - 65,000
Annual discretionary bonus
Pension contributions (up to 11%)
Hybrid working
+5
Cyber Defence Transformation Analyst
Cyber Defence Transformation Analyst

Intact Insurance UK • Greater London

Hybrid
GBP 65,000 - 90,000
Annual discretionary bonus
Hybrid working
Pension contributions
+2
Cyber Defence Transformation Analyst
Cyber Defence Transformation Analyst

Intact Insurance • Greater London

Hybrid
GBP 65,000 - 90,000
Annual discretionary bonus
Up to 11% pension contributions
25 days annual leave + bank holidays +
+4
Cyber Security Awareness Analyst
Cyber Security Awareness Analyst

RSA Security LLC • Horsham

On-site
GBP 40,000 - 60,000