Overview
In this role you will shape secure software development at Colt, embedding security into CI/CD pipelines and product design. You’ll work with Engineering, DevOps, Cloud, SOC and Risk teams to ensure applications are secure by design and by default. You’ll lead architecture with a focus on DevSecOps, testing, and governance across internally developed software. This is a hands-on, cross-functional role at scale, shaping security practices across the software lifecycle. Join Colt to help safeguard digital services while enabling fast, secure delivery.
Pay / Benefits
- Flexible working hours and option to work from home
- Extensive induction program with mentors
- Opportunities for further development and education
- Global Family Leave Policy
- Employee Assistance Program
- Internal inclusion and diversity networks
Responsibilities
- Provide security architecture expertise for application security and DevSecOps across the SDLC
- Contribute to the target architecture for secure software development aligned to Secure by Design
- Integrate security controls into CI/CD pipelines (GitLab) with automated testing and policy enforcement
- Design and implement application security controls (SAST, DAST, SCA, secrets scanning)
- Collaborate with engineering to promote DevSecOps practices and secure coding
- Support security reviews and assurance activities for internally developed apps and services
- Identify and mitigate risks from vulnerabilities, insecure coding, and exposed credentials
- Coordinate and execute third-party penetration testing of internet-facing applications
- Define test scope, track findings, and ensure remediation
- Provide remediation guidance and prioritisation to engineering teams
- Develop and maintain secure coding standards and architectural patterns
- Ensure alignment with TSA, DORA and ISO27001 in design and deployment
- Foster a security-first culture within development teams and stay aware of emerging risks and AI/LLM related risks
- Produce and maintain architecture artefacts, standards and guidance
Key requirements
- 5+ years in information security with strong focus on application security and DevSecOps
- Solid understanding of secure SDLC and OWASP Top 10
- Hands-on experience with DevSecOps tooling in CI/CD (GitLab pipelines)
- Experience with SAST, DAST, SCA and secrets/credentials scanning
- Experience contributing to security design reviews for applications and APIs
- Experience supporting or participating in penetration testing and remediation tracking
- Strong knowledge of modern application architectures (APIs, microservices, cloud-native)
- Understanding of authentication and session management concepts
- Experience with risk assessments using recognised frameworks
- Ability to translate vulnerabilities into business-facing risk and remediation actions
- Strong collaboration and communication skills
- strong collaboration with engineering and development teams
- clear technical and non-technical communication
- SAST
- DAST
- SCA / dependency scanning
- Secrets / credentials scanning
…
