Posted 02 August, 2026
Senior Application Security Consultant (SAST/DAST/OWASP )
Salt
Woking, ENG, GB
Full Time
Job Description
Senior Application Security Consultant (SAST/DAST/OWASP )/ DevSecOps Security - Banking - LondonSecure SDLC | SAST | DAST | Threat Modelling | Cloud Security | CI/CDLocation: London (Hybrid - 8 days onsite per month)Contract: 12 Months + extensionRate: £500-£550 per day (Umbrella)The OpportunityWe're looking for an experienced Senior Application Security Consultant / DevSecOps Security Architect to join a high-performing Cyber Security function within a large enterprise technology environment.Working alongside software engineering, cloud, architecture and DevOps teams, you'll play a key role in embedding security throughout the Software Development Lifecycle, ensuring applications are designed, developed and deployed securely.This is an excellent opportunity for someone passionate about Secure-by-Design, DevSecOps and modern Application Security within a large-scale cloud environment.Key ResponsibilitiesLead application security reviews across business-critical applications and cloud platforms.Conduct security architecture and secure design reviews.Perform application security risk assessments and define security requirements.Lead Threat Modelling workshops using STRIDE, MITRE ATT&CK or similar methodologies.Embed Secure SDLC principles into engineering teams.Integrate security tooling into CI/CD pipelines and DevSecOps processes.Review and analyse SAST, DAST and Software Composition Analysis (SCA) findings.Work closely with development teams to prioritise vulnerability remediation.Define security testing requirements and support penetration testing activities.Produce security standards, technical guidance and best practice documentation.Act as the Application Security SME across multiple technology programmes.Essential SkillsApplication SecuritySecure Software Development Lifecycle (SSDLC)OWASP Top 10Secure CodingSecure Design ReviewsAPI SecurityREST APIsMicroservices SecurityApplication Security Risk AssessmentsThreat ModellingSTRIDEMITRE ATT&CKSecurity ArchitectureRisk AssessmentsDevSecOpsCI/CD SecurityGitHub ActionsGitLabJenkinsAzure DevOpsSecurity AutomationShift Left SecuritySecurity TestingSASTDASTSCAVulnerability ManagementPenetration TestingCloud SecurityAWS, Azure or GCPKubernetesDockerContainer SecurityCloud Security Best PracticesSecurity ToolingExperience with one or more of:CheckmarxFortifySonarQubeVeracodeSemgrepBurp SuiteOWASP ZAPSnykTrivyPrisma CloudAquaWizIdeal BackgroundYou'll ideally have:8+ years in Cyber SecurityStrong Application Security or DevSecOps experienceExperience working directly with software engineering teamsExperience embedding security into CI/CD pipelinesStrong knowledge of Secure SDLCExperience conducting Threat Modelling sessionsExcellent stakeholder management and communication skillsPrevious experience within Banking, Financial Services, Insurance or another highly regulated enterprise environmentContract Details12-month contract£500-£600 per day (Umbrella)Hybrid working - 8 days onsite per month in LondonImmediate interview availability preferred*Rates depend on experience and client requirementsTPBN1_UKTJ
