Test Engineer DAST IAST Application Security

Client Server

Cambridge

Hybrid

GBP 63,000 - 77,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Bonus
Private Medical Care
Life Assurance
Travel Insurance
Subsidised gym membership

Job summary

A leading software company is looking for a Test Engineer to enhance application security in a hybrid work environment. You’ll perform security testing, conduct threat modeling, and ensure adherence to development best practices. The ideal candidate has a strong understanding of application security, experience with DAST/IAST tools, and the ability to collaborate with development teams effectively. This role offers a competitive salary and various benefits including a bonus, private medical care, and a subsidised gym membership.

Qualifications

  • Strong understanding of the secure software development lifecycle and DevSecOps principles.
  • Good knowledge of common vulnerabilities (e.g., XSS, SQL Injection, Broken Access Control).
  • Hands-on experience with various security testing tools.

Responsibilities

  • Build security into applications via threat modeling and risk assessments.
  • Carry out secure code reviews and provide guidance on best practices.
  • Run DAST against live applications focusing on key security issues.

Skills

Secure software development lifecycle
Application Security principles
DAST and IAST experience
Penetration Testing
Collaborative communication skills

Tools

Burp Suite
OWASP ZAP
Frida
Blackduck
Snyk

Job description

Test Engineer (DAST IAST Application Security) Cambridge / WFH to £70k

Are you a security focussed Test Engineer?

You could be joining a market leading software house that's remote access product is used by hundreds of millions of users worldwide.

What's in it for you:
  • Salary to £70k
  • Bonus
  • Pension, Private Medical Care, Life Assurance, Travel Insurance
  • Subsidised gym membership and a range of other perks
Your role:

As a Test Engineer you'll play a key role in building security into applications, carrying out threat modelling and risk assessments during the design phase to ensure solutions are secure by default. You'll help define security requirements for new features and take part in architecture reviews to spot and address potential risks early.

Working closely with development teams, you'll carry out secure code reviews and provide guidance on best practices, including alignment with CIS Critical Security Controls and the OWASP Top 10, collaborating with engineers to embed security into development workflows rather than treating it as an afterthought.

You'll be hands-on with security testing across a range of environments, running Dynamic Application Security Testing (DAST) against live applications, focusing on issues such as cross-site scripting, SQL injection and broken access control. You'll also use Interactive Application Security Testing (IAST) tools for runtime analysis, including tools such as Burp Suite, OWASP ZAP and Frida, alongside Static Application Security Testing (SAST) and software composition analysis to assess source code, binaries, and third‑party dependencies.

Location / WFH:

You can work from home most of the time, meeting up with colleagues in the Cambridge office on a weekly / monthly basis.

About you:
  • You have a strong understanding of the secure software development lifecycle and DevSecOps principles
  • You have a good knowledge of Application Security principles and common vulnerabilities (e.g., XSS, SQL Injection, Broken Access Control)
  • You have hands‑on experience with DAST, IAST and Penetration Testing tools (e.g., Burp Suite, OWASP ZAP, Frida) and Static Application Security Testing (SAST)
  • You can read and understand code (e.g. Java, Python, C++ or similar)
  • You're familiar with using software composition analysis (SCA) tools such as Blackduck, Mend / Whitesource, Snyk or similar
  • You're collaborative and pragmatic with great communications skills
Apply now

to find out more about this Test Engineer (DAST IAST Application Security) opportunity.

At Client Server we believe in a diverse workplace that allows people to play to their strengths and continually learn. We're an equal opportunities employer whose people come from all walks of life and will never discriminate based on race, colour, religion, sex, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. The clients we work with share our values.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Consultant
Application Security Consultant

Cytix • Manchester

Hybrid
GBP 40,000 - 50,000
Private Healthcare (inc. dental, optical, and hearing)
Unlimited Holidays
EMI share options
Application Security Engineer JavaScript
Application Security Engineer JavaScript

Client Server • Greater London

Hybrid
GBP 68,000 - 80,000
Bonus
Equity
Benefits package
Software Test Engineer - DV
Software Test Engineer - DV

NPAworldwide • Gloucester

Hybrid
GBP 40,000 - 70,000
Hybrid working
Flexible working
Career coach and development support
+5
Backend Software Engineer C++
Backend Software Engineer C++

Client Server • Cambridge

Hybrid
GBP 60,000 - 80,000
Salary up to £80k + Bonus
Pension
Private Medical Insurance
+7
Senior Test Engineer - DV
Senior Test Engineer - DV

NPAworldwide • Manchester

Hybrid
GBP 40,000 - 70,000
Hybrid working
Career coach and development support
Training and professional development
+2
Pen Tester
Pen Tester

Remarkable Jobs • City Of London

Hybrid
GBP 45,000 - 60,000
Test Automation Engineer
Test Automation Engineer

LA International • Greater London

Hybrid
GBP 46,000 - 55,000
Senior Software Development Engineer in Test
Senior Software Development Engineer in Test

LA International • Greater London

Hybrid
Senior Software Test Engineer - DV
Senior Software Test Engineer - DV

NPAworldwide • West of England

Hybrid
GBP 40,000 - 70,000
Hybrid working
Flexible working
Career Coach and development
+4
Senior Application Security Consultant (SAST/DAST/OWASP )
Senior Application Security Consultant (SAST/DAST/OWASP )

Xpand Group • Greater London

Hybrid
GBP 115,000 - 138,000