Senior Application Security Consultant (SAST/DAST/OWASP )
Job Description
Senior Application Security Consultant (SAST/DAST/OWASP )/ DevSecOps Security - Banking - London
Secure SDLC SAST DAST Threat Modelling Cloud Security CI/CD
Location: London (Hybrid - 8 days onsite per month)
Contract: 12 Months + extension
Rate: 500- 550 per day (Umbrella)
The Opportunity
We're looking for an experienced Senior Application Security Consultant / DevSecOps Security Architect to join a high-performing Cyber Security function within a large enterprise technology environment.
Working alongside software engineering, cloud, architecture and DevOps teams, you'll play a key role in embedding security throughout the Software Development Lifecycle, ensuring applications are designed, developed and deployed securely.
This is an excellent opportunity for someone passionate about Secure-by-Design, DevSecOps and modern Application Security within a large-scale cloud environment.
Key Responsibilities
-
Lead application security reviews across business-critical applications and cloud platforms.
-
Conduct security architecture and secure design reviews.
-
Perform application security risk assessments and define security requirements.
-
Lead Threat Modelling workshops using STRIDE, MITRE ATT&CK or similar methodologies.
-
Embed Secure SDLC principles into engineering teams.
-
Integrate security tooling into CI/CD pipelines and DevSecOps processes.
-
Review and analyse SAST, DAST and Software Composition Analysis (SCA) findings.
-
Work closely with development teams to prioritise vulnerability remediation.
-
Define security testing requirements and support penetration testing activities.
-
Produce security standards, technical guidance and best practice documentation.
-
Act as the Application Security SME across multiple technology programmes.
Essential Skills
Application Security
-
Secure Software Development Lifecycle (SSDLC)
-
OWASP Top 10
-
Secure Coding
-
Secure Design Reviews
-
API Security
-
REST APIs
-
Microservices Security
-
Application Security Risk Assessments Threat Modelling
-
STRIDE
-
MITRE ATT&CK
-
Security Architecture
-
Risk Assessments DevSecOps
-
CI/CD Security
-
GitHub Actions
-
GitLab
-
Jenkins
-
Azure DevOps
-
Security Automation
-
Shift Left Security Security Testing
-
SAST
-
DAST
-
SCA
-
Vulnerability Management
-
Penetration Testing Cloud Security
-
AWS, Azure or GCP
-
Kubernetes
-
Docker
-
Container Security
-
Cloud Security Best Practices Security Tooling
Experience with one or more of:
-
Checkmarx
-
Fortify
-
SonarQube
-
Veracode
-
Semgrep
-
Burp Suite
-
OWASP ZAP
-
Snyk
-
Trivy
-
Prisma Cloud
-
Aqua
-
Wiz Ideal Background
You'll ideally have:
-
8+ years in Cyber Security
-
Strong Application Security or DevSecOps experience
-
Experience working directly with software engineering teams
-
Experience embedding security into CI/CD pipelines
-
Strong knowledge of Secure SDLC
-
Experience conducting Threat Modelling sessions
-
Excellent stakeholder management and communication skills
-
Previous experience within Banking, Financial Services, Insurance or another highly regulated enterprise environment Contract Details
-
12-month contract
-
500- 600 per day (Umbrella)
-
Hybrid working - 8 days onsite per month in London
-
Immediate interview availability preferred Rates depend on experience and client requirements
Similar Jobs
Explore similar searches
Browse more roles related to Senior Application Security Consultant (SAST/DAST/OWASP ).