Senior Application Security Specialist

La Fosse

Greater London

Hybrid

GBP 81,000 - 99,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A global retail business seeks an Application Security Specialist to join their Information Security Team in London. The successful candidate will own and improve application security tooling, lead testing activities, and work closely with engineering and product teams to embed security into the software development lifecycle. Applicants should possess a strong background in application security and hands-on experience with secure coding and DevSecOps practices. This is a hybrid role offering a competitive salary of up to £90,000 plus bonuses and benefits.

Qualifications

  • Strong background in application security within complex technology environments.
  • Hands-on experience with secure coding, SAST, DAST, CI/CD integration, and DevSecOps practices.
  • Good understanding of OWASP Top 10, API security, threat modelling, and common web application attack vectors.

Responsibilities

  • Own and improve application security tooling across web, mobile, and API environments.
  • Lead application security testing activity, including penetration testing and bug bounty.
  • Partner with engineering and product teams to embed security into the SDLC.

Skills

Application security expertise
Secure coding
SAST
DAST
CI/CD integration
DevSecOps practices
OWASP Top 10
API security
Threat modelling

Job description

Application Security Specialist - London (Hybrid) - up to £90,000 + bonus + benefits

La Fosse has partnered with a global retail business to hire an Application Security Specialist into a senior role within their Information Security Team.

This is a key hire for the business, focused on bringing stronger ownership and technical leadership to application security across a large digital estate. The role will suit someone who can act as the go-to SME for AppSec, helping shape the capability, improve tooling, and embed security more effectively into the SDLC.

Responsibilities
  • Own and improve application security tooling, including SAST and DAST, across web, mobile, and API environments.
  • Lead application security testing activity, including penetration testing and bug bounty, working closely with internal teams and external partners.
  • Partner with engineering and product teams to embed security into the SDLC and drive a more proactive approach to AppSec.
  • Support the security of customer-facing applications and APIs, including oversight of threats such as credential stuffing and broader web application risk.
  • Build dashboards, metrics, and KPIs to improve visibility of application security posture and progress.
  • Provide technical leadership within AppSec, helping the wider team build capability and improve processes over time.
Requirements
  • Strong background in application security within complex technology environments.
  • Hands-on experience with secure coding, SAST, DAST, CI/CD integration, and DevSecOps practices.
  • Good understanding of OWASP Top 10, API security, threat modelling, and common web application attack vectors.
  • Able to operate as a credible technical SME while communicating clearly with senior stakeholders.
  • Experience improving security across customer-facing digital platforms in large-scale environments.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer
Senior Application Security Engineer

Tec Partners Recruitment Ltd • City Of London

On-site
GBP 90,000 - 122,000
Application Security Specialist
Application Security Specialist

Experis - ManpowerGroup • Greater London

Hybrid
GBP 75,000 - 110,000
Competitive salary
Annual bonus
Car allowance
+7
Senior Application Security Consultant (SAST/DAST/OWASP )
Senior Application Security Consultant (SAST/DAST/OWASP )

Xpand Group • Greater London

Hybrid
GBP 115,000 - 138,000
Application Security Specialist
Application Security Specialist

Experis IT • Greater London

Hybrid
GBP 90,000 - 120,000
Hybrid working
Competitive salary
Annual bonus
+2
Senior AppSec Lead: Drive SDLC Security & Risk
Senior AppSec Lead: Drive SDLC Security & Risk

La Fosse • Greater London

Hybrid
GBP 100,000 - 125,000
Senior Application Security Engineer
Senior Application Security Engineer

McCabe & Barton • Greater London

On-site
GBP 60,000 - 90,000
Application Security Engineer JavaScript
Application Security Engineer JavaScript

Client Server • Greater London

Hybrid
GBP 68,000 - 80,000
Bonus
Equity
Benefits package
Application Security Lead - Hybrid, DevSecOps & AI Security
Application Security Lead - Hybrid, DevSecOps & AI Security

Experis - ManpowerGroup • Greater London

Hybrid
GBP 75,000 - 110,000
Competitive salary
Annual bonus
Car allowance
+7
Senior Application Security Engineer / DevSecOps Engineer
Senior Application Security Engineer / DevSecOps Engineer

Additional Resources Ltd. • Greater London

Hybrid
GBP 80,000 - 90,000
London office
Remote/hybrid work
Excellent benefits package
Senior Application Security Engineer / DevSecOps Engineer
Senior Application Security Engineer / DevSecOps Engineer

Additional Resources • City Of London

Hybrid
GBP 72,000 - 88,000