Senior Application Security Specialist

Sanderson

Greater London

Hybrid

GBP 67,000 - 89,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Sanderson is seeking a Security Engineer (DevSecOps - Applications) to embed security into software delivery across three streams. This hands-on role will work alongside three senior engineers to ensure consistent security practices and fast remediation.

You'll set up security scanning in CI/CD, build reusable security modules, and review code and configurations for vulnerabilities. London onsite once a week with a six-month initial term.

Qualifications

  • Hands-on software, DevOps or platform engineering with a security focus.
  • Experience with CI/CD and security scanning tools (SAST, SCA, secrets, IaC and container scanning).
  • Python or Bash and Terraform.
  • AWS fundamentals including IAM, plus containers and Kubernetes knowledge.
  • Good vulnerability management understanding (CVSS, EPSS).
  • Clear written communication and cross-team collaboration.

Responsibilities

  • Set up and tune security scanning in CI/CD pipelines and reduce false positives.
  • Build shared security modules, policy libraries and templates for three teams.
  • Review code, infrastructure-as-code and configurations for security issues.
  • Handle day-to-day vulnerability management, including pen test findings and fixes.
  • Oversee secrets management, certificates and access reviews; keep CAB records up to date.
  • Be the go-to security contact and support delivery teams when priorities shift.

Skills

CI/CD security scanning
SAST/SCA/secrets/IaC/container scans
Python
Terraform
AWS IAM
Kubernetes
Vulnerability management
Clear written communication

Tools

SAST tools
SCA tools
IaC scanners
Container scanning tools
CI/CD platforms

Job description

Security Engineer (DevSecOps - Applications)

Duration – 6 months initial

Location – London once a week on site

Reports to: Head of Security Architecture and Engineering

The role:

This is a hands-on engineering role focused on building security into software as developed and deployed. You'll work across three workstreams alongside three Senior DevSecOps Engineers. You'll pick up work where it's most needed, keep security consistent across all three workstreams and make sure nothing falls between them.

It suits a software, DevOps or platform engineer who has already built security into their day-to-day work and wants to take it further. You'll get exposure to platform, AI and integration security.

What you'll do:

  • Set up and tune security scanning in CI/CD pipelines, cut down false positives and help developers fix real issues.
  • Build shared security modules, policy libraries and templates that all three teams can reuse.
  • Review code, infrastructure-as-code and configuration changes for security issues.
  • Handle day-to-day vulnerability management, including pen test findings: prioritise what's genuinely exploitable, track fixes and check they've worked.
  • Look after secrets management, certificates and access reviews and keep security documentation, control evidence and CAB records up to date.
  • Be the go-to person when security is blocking a delivery team, cover for the senior engineers when priorities shift and flag where teams are solving the same problem in different ways.

What you’ll need

  • Hands‑on experience in software engineering, DevOps or platform engineering with a strong security focus, or in security engineering.
  • Experience with CI/CD and security scanning tools (SAST, SCA, secrets, IaC and container scanning).
  • Python or Bash and Terraform.
  • AWS fundamentals including IAM, plus working knowledge of containers and Kubernetes.
  • A good grasp of vulnerability management, including CVSS, EPSS and judging whether an issue is really exploitable.
  • Clear written communication and comfortable switching between teams.

Nice to have:

  • A security certification such as AWS Certified Security – Specialty, CKS, CompTIA Security+, GIAC or CISSP.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer / DevSecOps Engineer
Senior Application Security Engineer / DevSecOps Engineer

Additional Resources • City Of London

On-site
GBP 72,000 - 88,000
Senior Security Engineer
Senior Security Engineer

Data Science Festival • Greater London

On-site
GBP 100,000 - 135,000
Generous holiday allowance
Pension scheme
Ongoing learning and professional development
+2
Senior Application Security Engineer / DevSecOps Engineer
Senior Application Security Engineer / DevSecOps Engineer

Additional Resources Ltd. • Greater London

On-site
GBP 80,000 - 90,000
London office
Remote/hybrid work
Excellent benefits package
Application Security Specialist
Application Security Specialist

Experis - ManpowerGroup • Greater London

On-site
GBP 75,000 - 110,000
Competitive salary
Annual bonus
Car allowance
+7
Senior DevSecOps Engineer – Applications
Senior DevSecOps Engineer – Applications

Sanderson • Greater London

Hybrid
GBP 67,000 - 89,000
Software Security Engineer - Hybrid Working
Software Security Engineer - Hybrid Working

Oliver James • England

On-site
GBP 70,000 - 90,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Synergize Consulting Limited • Reading

On-site
GBP 81,000 - 115,000
Senior Security Architect
Senior Security Architect

develop • Greater London

On-site
GBP 99,000 - 121,000
Up to £110,000 salary
Benefits package
Remote or hybrid working
Senior Application Security Specialist
Senior Application Security Specialist

La Fosse • Greater London

On-site
GBP 81,000 - 99,000
Software Security Engineer
Software Security Engineer

Data Science Festival • Greater London

On-site
GBP 90,000 - 150,000
Hybrid working model
Pension scheme
Generous holiday allowance