Security Architect - Devsecops + Application Security

Colt Technology Services

Greater London

Hybrid

GBP 90,000 - 140,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Flexible working hours
Work from home
Mentor program
Educational opportunities
Employee Assistance Program

Job summary

Colt Technology Services is seeking a Security Architect specialising in Application Security and DevSecOps in London. You will embed security across the software development lifecycle, implement SAST/DAST/SCA tooling, and ensure secure by design practices throughout CI/CD pipelines.

The role collaborates with Engineering, DevOps, Cloud and Risk teams. The candidate should have 5+ years in information security, strong knowledge of OWASP Top 10, and hands-on DevSecOps tooling experience.

Qualifications

  • 5+ years in information security with focus on application security and DevSecOps
  • Strong understanding of secure software development and OWASP Top 10
  • Hands-on experience with DevSecOps tooling in CI/CD
  • Experience with SAST/DAST/SCA and secrets scanning
  • Experience contributing to security design reviews for apps/APIs
  • Experience in penetration testing activities and remediation tracking
  • Understanding of modern architectures (APIs, microservices, cloud-native)
  • Knowledge of authentication and session management concepts
  • Ability to translate vulnerabilities into business risk and remediation actions
  • Strong collaboration with engineering teams and clear communication

Responsibilities

  • Provide security architecture expertise for app security and DevSecOps across SDLC
  • Contribute to secure target architecture aligned to Secure by Design
  • Support integration of security controls into CI/CD pipelines (GitLab) with automated testing
  • Design and implement application security controls (SAST, DAST, SCA, secrets scanning)
  • Work with engineering teams to ensure DevSecOps adoption and secure coding
  • Support security reviews and assurance activities for internal apps/services
  • Identify and reduce risks from app vulnerabilities and insecure coding
  • Coordinate third-party penetration testing of internet-facing apps
  • Define test scope, track execution, and ensure remediation of findings
  • Guide engineering on remediation and prioritisation of vulnerabilities
  • Contribute to secure coding standards and patterns
  • Ensure alignment with TSA, DORA and ISO27001 in app design/deployment
  • Promote security-first culture and awareness
  • Maintain awareness of emerging risks and translate into controls
  • Produce and maintain architecture artefacts, standards, and guidance

Skills

Application security
DevSecOps
CI/CD security
SAST
DAST
SCA / dependency scanning
Secrets scanning
Secure coding practices
Communication
Collaboration with engineering

Education

Security-focused degree or equivalent

Tools

GitLab pipelines

Job description

Colt provides network, voice and data centre services to thousands of businesses around the world, allowing them to focus on delivering their business goals instead of the underlying infrastructure.

Why we need this role

We are looking for a Security Architect specialising in Application Security and DevSecOps to join the Security and Resilience – Security Architecture team.

This role will act as a subject matter expert for secure software development and DevSecOps practices, supporting the integration of security controls into Colt’s development pipelines and ensuring applications are secure by design and by default.

The successful candidate will work closely with Engineering, DevOps, Cloud, SOC and Risk teams to embed security throughout the software development lifecycle, ensuring that Colt’s applications and services are designed, built and tested with security as a core requirement.

The role combines:

  • Application security architecture and design
  • DevSecOps pipeline integration and tooling
  • Security assurance and governance across internally developed applications

You will play an important role in supporting:

  • Security integration into CI/CD pipelines (GitLab)
  • Reduction of vulnerabilities through automated scanning and testing
  • Assurance of internet-facing applications through structured penetration testing activities
What you will do
  • Provide security architecture expertise for application security and DevSecOps, supporting standards and best practices across the software development lifecycle
  • Contribute to the target architecture for secure software development, aligned to Colt’s Secure by Design principles
  • Support the integration of security controls into CI/CD pipelines (GitLab), including automated testing and policy enforcement
  • Design and implement application security controls, including:
    • Static Application Security Testing (SAST)
    • Dynamic Application Security Testing (DAST)
    • Software Composition Analysis (SCA) / dependency scanning
    • Secrets and credentials scanning
  • Work with engineering teams to ensure consistent adoption of DevSecOps practices and secure coding approaches
  • Support security architecture reviews and assurance activities for internally developed applications and services
  • Identify and help reduce risks related to application vulnerabilities, insecure coding practices and exposed credentials
  • Support the coordination and execution of third-party penetration testing of Colt’s internet-facing applications
  • Assist in defining test scope, tracking execution and ensuring remediation of findings is properly managed
  • Provide guidance to engineering teams on remediation and prioritisation of vulnerabilities
  • Contribute to the development and maintenance of secure coding standards and architectural patterns
  • Ensure alignment with regulatory requirements such as TSA, DORA and ISO27001 in application design and deployment
  • Promote a security-first culture within development teams, including awareness and best practices
  • Maintain awareness of emerging risks and technologies, including basic AI/LLM-related application risks, and support translation into practical controls where required
  • Produce and maintain architecture artefacts, standards and guidance documentation
What we're looking for

Must haves:

  • 5+ years of experience in information security, with a strong focus on application security and DevSecOps
  • Strong understanding of secure software development practices and common application security risks (e.g. OWASP Top 10)
  • Hands-on experience working with or integrating DevSecOps tooling within CI/CD environments (e.g. GitLab pipelines)
  • Experience with application security testing tools and practices, including: SAST, DAST, SCA / dependency scanning and Secrets / credentials scanning.
  • Experience contributing to security design reviews for applications and APIs
  • Experience supporting or participating in penetration testing activities, including remediation tracking
  • Strong understanding of modern application architectures (e.g. APIs, microservices, cloud-native applications)
  • Knowledge of authentication and session management concepts within applications
  • Experience performing or supporting risk assessments aligned to recognised frameworks
  • Ability to translate technical vulnerabilities into business-aligned risk and remediation actions
  • Strong collaboration skills with engineering and development teams
  • Strong communication skills (technical and non-technical)

Might haves:

  • Experience with GitLab security tooling and pipeline integrations
  • Familiarity with cloud-native application security (Azure / GCP environments)
  • Exposure to API security controls and testing approaches
  • Basic understanding of AI/LLM application risks, such as prompt injection or data exposure
  • Experience working within regulated environments (telecommunications, financial services, critical infrastructure)
  • Understanding of Telecoms Security Act (TSA) requirements in application design
What we offer you:

Looking to make a mark?

At Colt, you’ll make a difference. Because around here, we empower people. We don’t tell you what to do.

Instead, we employ people we trust, who come together across the globe to create intelligent solutions.

Our global teams are full of ambitious, driven people, all working together towards one shared purpose: to put the power of the digital universe in the hands of our customers wherever, whenever and however they want.

We give our people the opportunity to inspire and lead teams, and work on projects that connect people, cities, businesses, and ideas. We want you to help us change the world, for the better.

Diversity and inclusion

  • Inclusion and valuing diversity of thought and experience are at the heart of our culture here at Colt. From day one, you’ll be encouraged to be yourself because we believe that’s what helps our people to thrive. We welcome people with diverse backgrounds and experiences, regardless of their gender identity or expression, sexual orientation, race, religion, disability, neurodiversity, age, marital status, pregnancy status, or place of birth.

Most recently we have:

  • Signed the UN Women Empowerment Principles which guide our Gender Action Plan
  • Trained 60 (and growing) Colties to be Mental Health First Aiders
  • Please speak with a member of our recruitment team if you require adjustments to our recruitment process to support you. For more information about our Inclusion and Diversity agenda, visit our DEI pages .

Our benefits support you through all parts of life, for both physical and mental health.

  • Flexible working hours and the option to work from home.
  • Extensive induction program with experienced mentors and buddies.
  • Opportunities for further development and educational opportunities.
  • Global Family Leave Policy.
  • Employee Assistance Program.
  • Internal inclusion & diversity employee networks.

A global network

  • When you join Colt you become part of our global network. We are proud of our colleagues and the stories and experience they bring – take a look at ‘Our People’ site including our Empowered Women in Tech.
Create a job alert for this search

Security Architect - DevSecOps + Application Security London, GB

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Architect - DevSecOps + Application Security
Security Architect - DevSecOps + Application Security

Colt Technology Services • City Of London

Hybrid
GBP 90,000 - 130,000
Flexible working hours
Work from home option
Induction program
+4
Security Architect - Platform Engineering
Security Architect - Platform Engineering

Colt Technology Services Group Ltd. • Greater London

Hybrid
GBP 90,000 - 140,000
Flexible working hours
Option to work from home
Induction program with mentors
+3
Security Architect - Platform Engineering
Security Architect - Platform Engineering

Colt Technology Services • Greater London

Hybrid
GBP 90,000 - 130,000
Flexible hours
Work from home
Mentorship program
+3
Security Architect - Platform Engineering
Security Architect - Platform Engineering

Colt Technology Services • City Of London

Remote
GBP 90,000 - 150,000
Flexible working hours
Work from home
Mentor program
+1
Security Architect - Cloud Security + Zscaler Platform
Security Architect - Cloud Security + Zscaler Platform

Colt Technology Services • Greater London

Hybrid
GBP 90,000 - 120,000
Flexible working hours
Option to work from home
Induction program with mentors
+4
Security Architect - Microsoft Security Platform
Security Architect - Microsoft Security Platform

Colt Technology Services • Greater London

Hybrid
GBP 90,000 - 130,000
Flexible working hours
Mentor program and induction
Educational opportunities
+3
Security Architect - Cloud Security + Zscaler Platform
Security Architect - Cloud Security + Zscaler Platform

Colt Technology Services • City Of London

Hybrid
GBP 90,000 - 120,000
Flexible hours
Work from home
Mentors & buddies
+2
Security Operations Specialist
Security Operations Specialist

慨正橡扯 • Greater London

Hybrid
GBP 90,000 - 130,000
Flexible working hours
Work from home option
Extensive induction and development
Security Architect - DevSecOps & App Security
Security Architect - DevSecOps & App Security

Colt Technology Services Group Ltd. • Greater London

On-site
GBP 90,000 - 140,000
Flexible hours
Work from home
Induction program
+2
Security Architect: DevSecOps & App Security
Security Architect: DevSecOps & App Security

Colt Technology Services • Greater London

Hybrid
GBP 90,000 - 140,000
Flexible working hours
Work from home
Mentor program
+2