Senior Application Security Analyst

Global Relay

Greater London

On-site

GBP 90,000 - 130,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Global Relay seeks a Senior Application Security Specialist to lead advanced testing, threat modelling and security strategy across its applications. You will mentor analysts, liaise with engineering, and shape standards in a high‑impact security program.

You will own testing frameworks, automation, and KPI reporting, while driving remediation and security release processes. Strong leadership and deep technical expertise are essential for success.

Qualifications

  • 5–8 years' hands-on experience in application security testing.
  • Strong knowledge of internet and network technologies.
  • Expert understanding of web and API technologies and vulnerabilities.
  • Experience with mobile security testing and Frida scripting is a plus.
  • RBAC, container security and Kubernetes hardening experience.
  • Familiarity with MITRE ATT&CK and threat actor tactics.
  • Ability to automate test cases and integrate with CI/CD tools.

Responsibilities

  • Lead advanced security testing of critical applications and services across web, mobile and API surfaces.
  • Own threat modelling using structured frameworks (STRIDE, PASTA) for new features.
  • Support and engage in the penetration testing programme.
  • Design security test strategies for new products and major changes.
  • Act as SME and primary security contact between engineering and the Application Security team.
  • Oversee scanning-tool usage and KPIs in the CI/CD pipeline.
  • Own triage, escalation and evidence quality across testing streams.
  • Track security metrics and report to senior stakeholders.
  • Build advanced test cases, automation frameworks and tooling.
  • Own the security release process and remediation verification.
  • Mentor analysts; prepare training materials and playbooks.

Skills

Application security testing
Threat modelling
Penetration testing
OWASP Top 10
Kubernetes security
CI/CD security
Python scripting
Communication
OSCP/OSWE

Job description

The Senior Application Security Specialist is a senior technical role leading advanced application security testing, complex vulnerability analysis and threat modelling across the Application & Product Security function. You will provide technical leadership, mentor analysts and specialists, act as a security point of contact for engineering, and contribute to security strategy and standards.


Scope and Autonomy

Leads testing workstreams and sets the technical approach for complex assessments; acts as an escalation point for L1/L2 and a security partner to engineering.


Responsibilities


  • Lead advanced security testing of critical applications and services, including deep-dive manual testing and targeted penetration tests across web, mobile and API surfaces.

  • Own threat modelling using structured frameworks (STRIDE, PASTA), producing threat models for new features and architecture changes.

  • Support and engage in the penetration testing programme.

  • Design security test strategies for new products and major changes.

  • Act as subject-matter expert and primary point of contact between engineering and the Application Security team.

  • Provide oversight of scanning-tool usage and KPIs in the CI/CD pipeline.

  • Own the overarching triage, escalation and evidence-quality framework across all scanning tools and testing streams, resolving the most complex or contested findings and setting the standard L1/L2 analysts and specialists are mentored against.

  • Track and report key security testing metrics (e.g. time-to-remediate, recurring defect patterns) to senior stakeholders.

  • Build and maintain advanced test cases, automation frameworks and custom tooling to improve coverage and efficiency.

  • Own the security release process, including remediation verification and closure standards.

  • Mentor and coach analysts and specialists; provide training material, playbooks and quality review of finding reports.

  • Act as an escalation point for L1/L2 security analysts.

  • Provide expert-level root-cause analysis and remediation guidance for the most complex or systemic security defects and set remediation standards developers and L1/L2 analysts follow across the programme.

  • Develop and maintain process documentation and testing standards.


Qualifications


  • 5–8 years' hands-on experience in application security testing.

  • Advanced knowledge of internet and network technologies.

  • Expert understanding of web and API technologies and common vulnerabilities (OWASP Top 10, API/LLM Top 10, Mobile Top 10).

  • Advanced mobile security testing (Android/iOS)—reverse engineering, runtime manipulation, Frida scripting, Objection.

  • Advanced knowledge of container orchestration and Kubernetes security, including cluster hardening, RBAC and workload isolation.

  • Advanced AI/LLM security assessment.

  • Expert understanding of security controls (access control, encryption, logging/monitoring, secure configuration) and how to assess their effectiveness at scale.

  • Strong offensive security skillset—manual web and API testing, authentication/authorisation bypass, session management, business-logic abuse and data-protection testing.

  • Advanced knowledge of threat remediation techniques specific to the programming languages in use at Global Relay.

  • Strong awareness of advanced persistent threats (APTs), threat actor tactics (e.g. MITRE ATT&CK) and emerging vulnerability classes, and ability to apply this awareness to test strategy design.

  • Ability to build and own automation: scripting test cases (Python, Bash), integrating with TestRail and Jira, building automated Burp Suite Pro scanning workflows in CI/CD, and working knowledge of supporting tools such as Postman and SonarQube.

  • Excellent communication skills; ability to influence technical and non-technical stakeholders.

  • Recognised advanced certifications preferred (e.g. OSCP, OSWE).


Global Relay is unable to offer visa sponsorship for this position. Candidates must have the right to work in the UK at the time of application.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Analyst - L3
Senior Application Security Analyst - L3

Global Relay • Greater London

On-site
GBP 90,000 - 130,000
Senior AppSec Lead: Threat Modelling & Secure Testing
Senior AppSec Lead: Threat Modelling & Secure Testing

Global Relay • Greater London

On-site
GBP 90,000 - 130,000
Senior Application Security Specialist
Senior Application Security Specialist

La Fosse • Greater London

Hybrid
Senior Security Testing Consultant
Senior Security Testing Consultant

Anson McCade • United Kingdom

Hybrid
GBP 86,000 - 102,000
Salary: Up to £102,000 per year
25 days annual leave + public holidays
Private healthcare and dental support
+2
Application Security Specialist
Application Security Specialist

Experis - ManpowerGroup • Greater London

Hybrid
GBP 75,000 - 110,000
Competitive salary
Annual bonus
Car allowance
+7
Application Security Specialist
Application Security Specialist

Experis UK • Greater London

Hybrid
GBP 70,000 - 120,000
Car allowance
Hybrid working
Annual bonus
+2
Senior Security Consultant
Senior Security Consultant

Prism Infosec • Cheltenham

Hybrid
GBP 60,000 - 80,000
Continuous learning opportunities
Flexible working conditions
Collaborative team environment
Security Tester | Contract (12 Months+) | SC Clearance Required (Active/Lapsed) | Inside IR35
Security Tester | Contract (12 Months+) | SC Clearance Required (Active/Lapsed) | Inside IR35

WeDoTech • West of England

On-site
GBP 92,000 - 129,000
Senior Security Analyst
Senior Security Analyst

Made Tech Limited • United Kingdom

On-site
GBP 60,000 - 80,000
Sponsorship for recognized cyber certifications
Support for achieving SC clearance
Application Security (AppSec) Engineer
Application Security (AppSec) Engineer

AND Digital • London

On-site
GBP 60,000 - 80,000