Senior Application Security Specialist

Secure Source

Greater London

On-site

GBP 70,000 - 110,000

Full time

12 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Secure Source is seeking an Application Security Specialist to embed security expertise across Europe and advance secure development practices. You will lead reviews on high-risk systems and act as the technical authority on application security, helping reduce vulnerability risk across internal and customer-facing solutions.

The role requires 3–5 years in related fields, hands-on review experience, and strong CI/CD security integration capabilities within a multinational environment.

Qualifications

  • 3–5 years in application security, secure development or software engineering with a security focus.
  • Hands-on experience conducting application security reviews.
  • Experience implementing security in CI/CD processes.
  • Experience working with development teams in an enterprise environment.
  • Experience building or contributing to a security CoE or capability model.
  • Experience integrating security across large-scale development programmes.
  • Evidence of formal learning or certifications in secure development.

Responsibilities

  • Embed application security expertise across Europe’s products and services.
  • Lead security reviews on higher-risk systems and projects.
  • Promote secure development practices across engineering teams.
  • Act as a technical authority on application security and risk reduction.

Skills

SAST
DAST
SCA
Java
C/C++
CI/CD
Threat modelling
OWASP Top 10
API security
Fuzz testing
Secure AI development
SSDF
Vulnerability management

Education

Degree in computer science or related field
Secure development / application security certification
Cloud security certifications (AWS/Azure/GCP)

Tools

SAST tools
DAST tools
SCA tools

Job description

The Application Security Specialist exists to embed application security expertise across Europe’s products and services, supporting the Secure Development Practice and enabling a consistent ‘shift-left’ approach. The role is accountable for advancing application security capability, leading security reviews on higher-risk systems, and ensuring secure development practices are adopted across engineering teams. The post holder will act as a technical authority on application security, helping reduce vulnerability risk and improve security outcomes across both internal IT systems and customer-facing solutions.

  • Strong knowledge of application security principles and practices
  • Experience with SAST, DAST and software composition analysis tools
  • Knowledge of secure coding practices across languages such as Java, C, C++
  • Experience with CI/CD pipelines and DevSecOps integration
  • Threat modelling techniques and tools
  • Understanding of OWASP Top 10 and common vulnerability classes
  • Experience with API security and web application security
  • Understanding of fuzz testing and advanced testing techniques
  • Familiarity with secure AI development considerations
  • Knowledge of secure development frameworks such as SSDF
  • Understanding of vulnerability management processes
Experience Required
Minimum
  • 3 to 5 years in application security, secure development or software engineering with a security focus
  • Hands-on experience conducting application security reviews
  • Experience implementing security in CI/CD processes
  • Experience working with development teams in an enterprise environment
  • Experience building or contributing to a security CoE or capability model
  • Experience working in a multi-entity, multinational environment
  • Experience integrating security into large-scale development programmes
  • Experience supporting secure AI or data-centric applications
Minimum Qualifications Required
Minimum
  • Degree or equivalent professional experience in one of the following:
  • computer science
  • software engineering
  • cyber security
  • information security or related technical discipline
  • Evidence of formal or structured learning in secure development or application security (for example through certifications, formal training or demonstrable experience).
  • Recognised application security or secure development certification, such as:
  • CSSLP (Certified Secure Software Lifecycle Professional)
  • GIAC Web Application Penetration Tester (GWAPT) or GWEB
  • Offensive Security certifications (e.g. OSCP) where relevant to application testing
  • Cloud security certifications relevant to application hosting environments:
  • AWS Security Specialty
  • Microsoft Azure Security Engineer Associate
  • Google Professional Cloud Security Engineer
  • DevSecOps or CI/CD related certifications or formal training
  • ISO 27001 Lead Implementer or Lead Auditor, or demonstrable understanding of ISO control environments
  • Familiarity with NIST frameworks, particularly NIST CSF and NIST SSDF, demonstrated through training or experience
  • Relevant vendor certifications linked to SAST, DAST, SCA or pipeline tooling where used in the organisation
  • Evidence of continuous professional development in secure coding, software assurance or emerging technologies such as AI security
  • Strong software engineering foundation:
  • ability to read and understand code across at least one major language (Java, C, C++, C#, Python or similar)
  • understanding of common development frameworks and application architectures
  • Practical application security capability:
  • hands-on experience identifying and explaining common vulnerabilities
  • ability to guide remediation in a way developers can implement
  • understanding of how to embed security into design, build, test and deployment stages
  • familiarity with shift-left practices and developer workflows
  • ability to identify threats, abuse cases and attack surfaces
  • experience applying structured approaches such as STRIDE or similar
  • CI/CD and DevOps familiarity:
  • understanding of pipelines, build processes and release workflows
  • capability to integrate or advise on automated security testing within pipelines
  • Analytical and diagnostic capability:
  • ability to interpret scan results and distinguish false positives from real risk
  • ability to identify systemicissues rather than isolated defects
  • Communication and influence:
  • ability to translate security issues into actionable developer guidance
  • confidence in engaging engineers, architects and product owners
  • ability to link technical vulnerabilities to business risk and prioritisation
  • Advanced application security techniques:
  • experience with fuzz testing, advanced dynamic testing or manual code review
  • experience testing APIs, microservices and distributed systems
  • DevSecOps implementation:
  • experience designing or implementing security controls within CI/CD pipelines
  • hands-on experience integrating SAST, DAST, SCA and secrets scanning tools
  • familiarity with secure design patterns and common failure modes in modern architectures (cloud-native, microservices, serverless)
  • Secure AI and data-driven systems awareness:
  • understanding of risks associated with AI models, data pipelines and prompt or model manipulation
  • Training and enablement capability:
  • ability to design or deliver developer-focused training or workshops
  • ability to simplify complex security concepts without diluting technical accuracy
  • Broader security framework awareness:
  • working knowledge of OWASP SAMM, ASVS or similar maturity models
  • familiarity with threat intelligence inputs and how they influence application risk
  • experience selecting, tuning or optimising security tools for development environments
  • understanding of strengths and limitations of common tooling categories
  • exposure to both internal enterprise IT systems and externally facing customer solutions
  • Ability to operate in federated organisations:
  • comfort working across multiple teams, geographies and delivery models with varying levels of maturity
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Specialist
Application Security Specialist

Experis - ManpowerGroup • Greater London

Hybrid
GBP 75,000 - 110,000
Competitive salary
Annual bonus
Car allowance
+7
Application Security Specialist
Application Security Specialist

Experis IT • Greater London

Hybrid
GBP 90,000 - 120,000
Hybrid working
Competitive salary
Annual bonus
+2
Application Security Engineer
Application Security Engineer

Source Group International • Greater London

Hybrid
GBP 68,000 - 108,000
Senior Application Security Engineer / DevSecOps Engineer
Senior Application Security Engineer / DevSecOps Engineer

Additional Resources • City Of London

Hybrid
GBP 72,000 - 88,000
Senior Application Security Specialist
Senior Application Security Specialist

La Fosse • Greater London

Hybrid
Senior Application Security Engineer
Senior Application Security Engineer

Tec Partners Recruitment Ltd • City Of London

On-site
GBP 90,000 - 122,000
Application Security (AppSec) Engineer
Application Security (AppSec) Engineer

AND Digital • London

On-site
GBP 60,000 - 80,000
Information Security Manager
Information Security Manager

Jobtailor • Greater London

On-site
GBP 100,000 - 150,000
Application Security Architect (Manchester)
Application Security Architect (Manchester)

Insight Investment • Manchester

On-site
GBP 70,000 - 100,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Jobtailor • Greater London

On-site
GBP 110,000 - 140,000