Senior Application Security Engineer / DevSecOps Engineer

Additional Resources

City Of London

Hybrid

GBP 72,000 - 88,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Additional Resources in London is seeking an experienced Application Security/DevSecOps engineer to embed security across the SDLC. You will collaborate with engineering, architecture and cloud teams to design secure software, implement testing solutions and integrate controls into CI/CD.

The role emphasizes hands-on security design, API protection and cloud security governance. Hybrid remote work in London is offered with a negotiable £80,000 salary for the right candidate; visa sponsorship is

Qualifications

  • Hands-on experience embedding application security into the SDLC.
  • Experience with Microsoft Azure security controls and cloud governance.
  • Experience with KQL.
  • Experience securing APIs, internet-facing services and Kubernetes (AKS).
  • Experience with SAST, DAST, IAST and SCA.
  • Knowledge of security automation and security-/policy-as-code.
  • Familiarity with GitHub and GitHub Actions.
  • Experience with Terraform and Python.
  • Understanding of cloud security governance.
  • Experience with threat modelling in software engineering contexts.
  • Knowledge of ISO 27001 and its relevance to secure engineering.
  • Exposure to Agile and DevSecOps practices.
  • Experience securing data platforms like Databricks, Dagster or Snowflake.
  • Eligible to work in the UK.

Responsibilities

  • Work with engineering and architecture teams to promote secure development.
  • Implement and maintain application security testing solutions.
  • Integrate security controls into CI/CD pipelines.
  • Strengthen security of GitHub Actions and similar CI/CD platforms.
  • Provide guidance on secure API design and externally accessible systems.
  • Support Azure cloud infrastructure, including AKS.
  • Develop security-as-code and policy-as-code.
  • Support security of cloud-hosted data platforms.
  • Automate security processes via infrastructure-as-code and scripting.
  • Maintain security documentation and tooling best practices.
  • Contribute to threat modelling and compliance activities.

Skills

SDLC security
Azure security
KQL
CI/CD
SAST/DAST/IAST

Tools

GitHub Actions
Terraform
Python
AKS
Databricks
Dagster
Snowflake

Job description

Do you have a background in Application Security, DevSecOps or Product Security, with hands‑on experience embedding application security into the SDLC If so, this could be an opportunity worth considering.

Join a well-established health research organisation and charity supporting large-scale medical research. You will work closely with engineering, architecture and cloud teams to integrate security throughout the software development lifecycle.

Microsoft Azure and KQL experience are essential, alongside relevant experience in CI/CD, Kubernetes, API security, security-as-code and security automation. This is a hands‑on application security role focused on secure design, application security testing and supporting development teams to build secure applications.

This is a full‑time permanent role predominantly remote / hybrid in London offering benefits and a salary of £80,000 which can be negotiable for right candidate. Please only apply if you have right to work in the UK as Visa sponsorship is not available.

You will be responsible for:
  • Working with engineering and architecture teams to promote secure development.
  • Implementing and maintaining application security testing solutions.
  • Integrating security controls into CI/CD pipelines.
  • Strengthening the security of GitHub Actions and similar CI/CD platforms.
  • Providing guidance on secure API design and externally accessible systems.
  • Supporting Azure cloud infrastructure, including Azure Kubernetes Service (AKS).
  • Developing security-as-code and policy-as-code.
  • Supporting the security of cloud-hosted data platforms.
  • Automating security processes through infrastructure-as-code and scripting.
  • Maintaining technical and security documentation.
  • Supporting development teams with security tooling and best practices.
  • Contributing to threat modelling and compliance activities.
Applications are welcomed from candidates with the required experience from backgrounds including:
  • Application Security Engineer, DevSecOps Engineer, Product Security Engineer, Security Engineer - Application Security, Security Engineer - Product Security, DevOps Security Engineer, Application Security Consultant, Security Engineer - DevSecOps, Secure Software Engineer, Application Security Specialist, Application Security Architect
What we are looking for:
  • Hands‑on experience embedding application security into the SDLC.
  • Experience with Microsoft Azure security controls and cloud security governance.
  • Experience with KQL.
  • Experience securing APIs, internet‑facing services, Kubernetes, preferably AKS, and containerised environments.
  • Experience with SAST, DAST, IAST and SCA.
  • Knowledge of security automation, security-/policy-as-code and secure engineering practices.
  • Familiarity with GitHub and GitHub Actions.
  • Experience with Terraform and Python.
  • Understanding of cloud security governance.
  • Experience with threat modelling in software engineering contexts.
  • Knowledge of ISO 27001 and its relevance to secure engineering.
  • Exposure to Agile working environments and DevSecOps practices
  • Ideally experience securing data platforms such as Databricks, Dagster or Snowflake
  • Eligible to work in the UK.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer / DevSecOps Engineer
Senior Application Security Engineer / DevSecOps Engineer

Additional Resources Ltd. • Greater London

Hybrid
GBP 80,000 - 90,000
London office
Remote/hybrid work
Excellent benefits package
Senior Application Security Consultant
Senior Application Security Consultant

Salt • Greater London

Hybrid
GBP 90,000 - 120,000
Senior Application Security Engineer
Senior Application Security Engineer

Our Future Health UK • Greater London

Hybrid
GBP 63,000 - 77,000
Generous Pension
30 Days Holiday
Parental Leave
+6
Senior Application Security Engineer
Senior Application Security Engineer

Our Future Health Limited • Greater London

Hybrid
GBP 63,000 - 77,000
Generous Pension Scheme
30 Days Holiday
Enhanced Parental Leave
+4
Senior Application Security Consultant (SAST/DAST/OWASP )
Senior Application Security Consultant (SAST/DAST/OWASP )

Salt • City Of London

Hybrid
GBP 66,000 - 111,000
Senior Application Security Engineer
Senior Application Security Engineer

Tec Partners Recruitment Ltd • City Of London

On-site
GBP 90,000 - 122,000
Senior Application Security Engineer
Senior Application Security Engineer

Tec Partners Recruitment Ltd • Greater London

On-site
GBP 92,000 - 120,000
Head of Application Security
Head of Application Security

Harvey Nash • Greater London

On-site
GBP 120,000 - 180,000
Expenses covered for London visits
Security Engineer
Security Engineer

Copello • Uxbridge

Hybrid
GBP 85,000 - 120,000
Senior Security Engineer
Senior Security Engineer

Data Science Festival • Greater London

Hybrid
GBP 100,000 - 135,000
Generous holiday allowance
Pension scheme
Ongoing learning and professional development
+2