Senior Application Security Analyst – L3

Company: Global Relay
Apply for the Senior Application Security Analyst – L3
Location: London
Job Description:

Overview

In this role you will lead advanced application security testing and threat modelling to bolster secure product development. You will partner with engineering to shape security strategy, mentor analysts, and own the security testing program across web, mobile, and API surfaces. You’ll drive secure design through structured threat models and implement automation to improve coverage and efficiency. This is a chance to make a measurable impact on the security posture of mission-critical enterprise solutions.

Pay / Benefits

  • mentoring and coaching
  • diverse and inclusive culture
  • career growth opportunities
  • supportive learning environment
  • appears to value innovation and impact

Responsibilities

  • Lead advanced security testing of critical applications and services across web, mobile, and API surfaces
  • Own threat modelling using STRIDE and PASTA for new features and architecture changes
  • Design security test strategies for new products and major changes
  • Act as primary security liaison between engineering and the Application Security team
  • Oversee scanning-tool usage and KPIs in the CI/CD pipeline
  • Manage triage, escalation, and evidence-quality framework for findings
  • Develop and maintain test cases, automation frameworks, and custom tooling
  • Own the security release process including remediation verification and closure standards
  • Mentor and coach analysts; provide training materials and quality review of findings
  • Provide expert root-cause analysis and remediation guidance for complex defects

Key requirements

  • 5–8 years hands-on experience in application security testing
  • Advanced knowledge of internet and network technologies
  • Expert understanding of web and API technologies and vulnerabilities (OWASP Top 10, API/LLM Top 10, Mobile Top 10)
  • Advanced mobile security testing (Android/iOS) including reverse engineering, runtime manipulation, Frida scripting, Objection
  • Advanced knowledge of container orchestration and Kubernetes security (RBAC, workload isolation)
  • Advanced AI/LLM security assessment
  • Strong understanding of security controls and their effectiveness at scale
  • Offensive security skills in manual web/API testing, authentication/authorization bypass, session management, and data-protection testing
  • Knowledge of threat remediation techniques for programming languages used at Global Relay
  • Awareness of APTs, MITRE ATT&CK, and emerging vulnerability classes for test strategy design
  • Ability to build and own automation (Python, Bash), integrate with TestRail and Jira, automate Burp Suite Pro in CI/CD, and familiarity with Postman and SonarQube
  • Excellent communication skills and ability to influence stakeholders
  • Recognised advanced certifications preferred (e.g., OSCP, OSWE)
  • Excellent communication and ability to influence stakeholders
  • Mentoring and coaching capabilities
  • Collaborative, cross-functional teamwork
  • Penetration testing across web, mobile, and API surfaces
  • Threat modelling (STRIDE, PASTA)
  • CI/CD tooling and KPI tracking

…

Posted: October 1st, 2026