Senior Application Security Engineer / DevSecOps Engineer

TipTopJob

Greater London

Hybrid

GBP 72,000 - 88,000

Full time

6 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

London office
Remote/hybrid work
Excellent benefits package
Full-time permanent position

Job summary

TipTopJob in London is seeking a Senior Application Security Engineer with hands-on SDLC security experience to work with engineering, architecture and cloud teams. The role is predominantly remote with hybrid options and a London office, offering a competitive salary and benefits.

You will implement security testing, integrate controls into CI/CD, strengthen GitHub Actions security, advise on secure API design, support Azure/Kubernetes, and develop security as code and policy as code.

Qualifications

  • Hands-on experience embedding application security into the SDLC.
  • Experience with Microsoft Azure security controls and cloud security governance.
  • Experience with KQL.
  • Experience securing APIs, internet-facing services, Kubernetes (preferably AKS), and containerised environments.
  • Experience with SAST, DAST, IAST and SCA.
  • Knowledge of security automation, security/policy-as-code and secure engineering practices.
  • Familiarity with GitHub and GitHub Actions.
  • Experience with Terraform and Python.
  • Understanding of cloud security governance.
  • Experience with threat modelling in software engineering contexts.
  • Knowledge of ISO 27001 and its relevance to secure engineering.
  • Exposure to Agile working environments and DevSecOps practices.
  • Ideally experience securing data platforms such as Databricks, Dagster or Snowflake.
  • Eligible to work in the UK.

Responsibilities

  • Implementing and maintaining application security testing solutions.
  • Integrating security controls into CI/CD pipelines.
  • Strengthening the security of GitHub Actions and similar CI/CD platforms.
  • Providing guidance on secure API design and externally accessible systems.
  • Supporting Azure cloud infrastructure, including Azure Kubernetes Service (AKS).
  • Developing security:as:code and policy:as:code.
  • Supporting the security of cloud hosted data platforms.
  • Automating security processes through infrastructure:as:code and scripting.
  • Maintaining technical and security documentation.
  • Supporting development teams with security tooling and best practices.
  • Contributing to threat modelling and compliance activities.

Skills

Hands-on security in SDLC
Threat modelling
Agile working environments
Security automation
Cloud security governance

Tools

Azure
AKS
Kubernetes
GitHub Actions
Terraform
Python
SAST
DAST
IAST
SCA
Databricks
Dagster
Snowflake

Job description

Do you have a background in Application Security, DevSecOps or Product Security, with hands:on experience embedding application security into the SDLC? If so, this could be an opportunity worth considering.Join a well:established health research organisation and charity supporting large:scale medical research. You will work closely with engineering, architecture and cloud teams to integrate security throughout the software development lifecycle.

Microsoft Azure and KQL experience are essential, alongside relevant experience in CI/CD, Kubernetes, API security, security:as:code and security automation. This is a hands:on application security role focused on secure design, application security testing and supporting development teams to build secure applications.

This is a full:time permanent role predominantly remote / hybrid in London offerings benefits and a salary of GBP 80,000 which can be negotiable for right candidate. Please only apply if you have right to work in the UK as Visa sponsorship is not available.

You will be responsible for:
  • Implementing and maintaining application security testing solutions.
  • Integrating security controls into CI/CD pipelines.
  • Strengthening the security of GitHub Actions and similar CI/CD platforms.
  • Providing guidance on secure API design and externally accessible systems.
  • Supporting Azure cloud infrastructure, including Azure Kubernetes Service (AKS).
  • Developing security:as:code and policy:as:code.
  • Supporting the security of cloud:hosted data platforms.
  • Automating security processes through infrastructure:as:code and scripting.
  • Maintaining technical and security documentation.
  • Supporting development teams with security tooling and best practices.
  • Contributing to threat modelling and compliance activities.
Applications are welcomed from candidates with the required experience from backgrounds including:

Application Security Engineer, DevSecOps Engineer, Product Security Engineer, Security Engineer : Application Security, Security Engineer : Product Security, DevOps Security Engineer, Application Security Consultant, Security Engineer : DevSecOps, Secure Software Engineer, Application Security Specialist, Application Security Architect

What we are looking for:
  • Hands:on experience embedding application security into the SDLC.
  • Experience with Microsoft Azure security controls and cloud security governance.
  • Experience with KQL.
  • Experience securing APIs, internet:facing services, Kubernetes, preferably AKS, and containerised environments.
  • Experience with SAST, DAST, IAST and SCA.
  • Knowledge of security automation, security:/policy:as:code and secure engineering practices.
  • Familiarity with GitHub and GitHub Actions.
  • Experience with Terraform and Python.
  • Understanding of cloud security governance.
  • Experience with threat modelling in software engineering contexts.
  • Knowledge of ISO 27001 and its relevance to secure engineering.
  • Exposure to Agile working environments and DevSecOps practices
  • Ideally experience securing data platforms such as Databricks, Dagster or Snowflake
  • Eligible to work in the UK.
What the role offers:
  • GBP 80,000 DOE, negotiable
  • Predominantly remote / hybrid working
  • London office
  • Full:time permanent position
  • Excellent benefits package

This is an excellent opportunity for a Senior Application Security Engineer where you can make a meaningful impact on the safe and effective adoption of emerging technologies.

Important Information: We endeavour to process your personal data in a fair and transparent manner. In applying for this role, Additional Resources will be acting in your best interest and may contact you in relation to the role, either by email, phone or text message. For more information see our Privacy Policy on our website. It is important

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer / DevSecOps Engineer
Senior Application Security Engineer / DevSecOps Engineer

Additional Resources Ltd. • Greater London

Hybrid
GBP 80,000 - 90,000
London office
Remote/hybrid work
Excellent benefits package
Senior Application Security Engineer / DevSecOps Engineer
Senior Application Security Engineer / DevSecOps Engineer

Additional Resources • City Of London

Hybrid
GBP 72,000 - 88,000
Senior Application Security Engineer / DevSecOps Engineer
Senior Application Security Engineer / DevSecOps Engineer

Additional Resources • Greater London

Hybrid
GBP 80,000 - 90,000
Remote/Hybrid work in London
Salary £80k-£90k + benefits
Senior Application Security Engineer
Senior Application Security Engineer

Our Future Health Limited • Greater London

Hybrid
GBP 63,000 - 77,000
Generous Pension Scheme
30 Days Holiday
Enhanced Parental Leave
+4
Senior Application Security Engineer
Senior Application Security Engineer

Our Future Health UK • Greater London

Hybrid
GBP 63,000 - 77,000
Generous Pension
30 Days Holiday
Parental Leave
+6
Senior App Security Engineer, Azure & DevSecOps
Senior App Security Engineer, Azure & DevSecOps

Additional Resources • Greater London

Hybrid
GBP 80,000 - 90,000
Remote/Hybrid work in London
Salary £80k-£90k + benefits
Software Security Engineer
Software Security Engineer

Data Science Festival • Greater London

Hybrid
GBP 90,000 - 150,000
Hybrid working model
Pension scheme
Generous holiday allowance
Application Security Specialist
Application Security Specialist

Experis IT • Greater London

Hybrid
GBP 90,000 - 120,000
Hybrid working
Competitive salary
Annual bonus
+2
Application Security Engineer
Application Security Engineer

Hargreaves Lansdown • West of England

Hybrid
GBP 62,000 - 90,000
Hybrid working (2 days in Bristol)
Discretionary annual bonus
Pension contributions up to 11%
+4
Application Security Specialist
Application Security Specialist

Experis - ManpowerGroup • Greater London

Hybrid
GBP 75,000 - 110,000
Competitive salary
Annual bonus
Car allowance
+7