Security Architect – DevSecOps + Application Security

Company: Colt Telecom
Apply for the Security Architect – DevSecOps + Application Security
Location: London
Job Description:

Overview

In this role you will shape secure software development at Colt, embedding security into CI/CD pipelines and product design. You’ll work with Engineering, DevOps, Cloud, SOC and Risk teams to ensure applications are secure by design and by default. You’ll lead architecture with a focus on DevSecOps, testing, and governance across internally developed software. This is a hands-on, cross-functional role at scale, shaping security practices across the software lifecycle. Join Colt to help safeguard digital services while enabling fast, secure delivery.

Pay / Benefits

  • Flexible working hours and option to work from home
  • Extensive induction program with mentors
  • Opportunities for further development and education
  • Global Family Leave Policy
  • Employee Assistance Program
  • Internal inclusion and diversity networks

Responsibilities

  • Provide security architecture expertise for application security and DevSecOps across the SDLC
  • Contribute to the target architecture for secure software development aligned to Secure by Design
  • Integrate security controls into CI/CD pipelines (GitLab) with automated testing and policy enforcement
  • Design and implement application security controls (SAST, DAST, SCA, secrets scanning)
  • Collaborate with engineering to promote DevSecOps practices and secure coding
  • Support security reviews and assurance activities for internally developed apps and services
  • Identify and mitigate risks from vulnerabilities, insecure coding, and exposed credentials
  • Coordinate and execute third-party penetration testing of internet-facing applications
  • Define test scope, track findings, and ensure remediation
  • Provide remediation guidance and prioritisation to engineering teams
  • Develop and maintain secure coding standards and architectural patterns
  • Ensure alignment with TSA, DORA and ISO27001 in design and deployment
  • Foster a security-first culture within development teams and stay aware of emerging risks and AI/LLM related risks
  • Produce and maintain architecture artefacts, standards and guidance

Key requirements

  • 5+ years in information security with strong focus on application security and DevSecOps
  • Solid understanding of secure SDLC and OWASP Top 10
  • Hands-on experience with DevSecOps tooling in CI/CD (GitLab pipelines)
  • Experience with SAST, DAST, SCA and secrets/credentials scanning
  • Experience contributing to security design reviews for applications and APIs
  • Experience supporting or participating in penetration testing and remediation tracking
  • Strong knowledge of modern application architectures (APIs, microservices, cloud-native)
  • Understanding of authentication and session management concepts
  • Experience with risk assessments using recognised frameworks
  • Ability to translate vulnerabilities into business-facing risk and remediation actions
  • Strong collaboration and communication skills
  • strong collaboration with engineering and development teams
  • clear technical and non-technical communication
  • SAST
  • DAST
  • SCA / dependency scanning
  • Secrets / credentials scanning

Posted: September 17th, 2026