Senior Application Security Consultant (SAST/DAST/OWASP )
Job Description
Senior Application Security Consultant (SAST/DAST/OWASP )/ DevSecOps Security - Banking - London
\nSecure SDLC | SAST | DAST | Threat Modelling | Cloud Security | CI/CD
\nLocation: London (Hybrid - 8 days onsite per month)
\nContract: 12 Months + extension
\nRate:£500-£550 per day (Umbrella)
\nThe Opportunity
\nWe're looking for an experienced Senior Application Security Consultant / DevSecOps Security Architect to join a high-performing Cyber Security function within a large enterprise technology environment.
\nWorking alongside software engineering, cloud, architecture and DevOps teams, you'll play a key role in embedding security throughout the Software Development Lifecycle, ensuring applications are designed, developed and deployed securely.
\n\nThis is an excellent opportunity for someone passionate about Secure-by-Design, DevSecOps and modern Application Security within a large-scale cloud environment.
\nKey Responsibilities
\n- \n
- Lead application security reviews across business-critical applications and cloud platforms. \n
- Conduct security architecture and secure design reviews. \n
- Perform application security risk assessments and define security requirements. \n
- Lead Threat Modelling workshops using STRIDE, MITRE ATT&CK or similar methodologies. \n
- Embed Secure SDLC principles into engineering teams. \n
- Integrate security tooling into CI/CD pipelines and DevSecOps processes. \n
- Review and analyse SAST, DAST and Software Composition Analysis (SCA) findings. \n
- Work closely with development teams to prioritise vulnerability remediation. \n
- Define security testing requirements and support penetration testing activities. \n
- Produce security standards, technical guidance and best practice documentation. \n
- Act as the Application Security SME across multiple technology programmes. \n
Essential Skills
\nApplication Security
\n- \n
- Secure Software Development Lifecycle (SSDLC) \n
- OWASP Top 10 \n
- Secure Coding \n
- Secure Design Reviews \n
- API Security \n
- REST APIs \n
- Microservices Security \n
- Application Security Risk Assessments \n
Threat Modelling
\n- \n
- STRIDE \n
- MITRE ATT&CK \n
- Security Architecture \n
- Risk Assessments \n
DevSecOps
\n- \n
- CI/CD Security \n
- GitHub Actions \n
- GitLab \n
- Jenkins \n
- Azure DevOps \n
- Security Automation \n
- Shift Left Security \n
Security Testing
\n- \n
- SAST \n
- DAST \n
- SCA \n
- Vulnerability Management \n
- Penetration Testing \n
Cloud Security
\n- \n
- AWS, Azure or GCP \n
- Kubernetes \n
- Docker \n
- Container Security \n
- Cloud Security Best Practices \n
Security Tooling
\nExperience with one or more of:
\n- \n
- Checkmarx \n
- Fortify \n
- SonarQube \n
- Veracode \n
- Semgrep \n
- Burp Suite \n
- OWASP ZAP \n
- Snyk \n
- Trivy \n
- Prisma Cloud \n
- Aqua \n
- Wiz \n
Ideal Background
\nYou'll ideally have:
\n- \n
- 8+ years in Cyber Security \n
- Strong Application Security or DevSecOps experience \n
- Experience working directly with software engineering teams \n
- Experience embedding security into CI/CD pipelines \n
- Strong knowledge of Secure SDLC \n
- Experience conducting Threat Modelling sessions \n
- Excellent stakeholder management and communication skills \n
- Previous experience within Banking, Financial Services, Insurance or another highly regulated enterprise environment \n
Contract Details
\n- \n
- 12-month contract \n
- £500-£600 per day (Umbrella) \n
- Hybrid working - 8 days onsite per month in London \n
- Immediate interview availability preferred \n
*Rates depend on experience and client requirements
