Overview
In this role you will strengthen the security of the organisation’s software by performing secure code reviews, SAST/DAST, and vulnerability assessments, embedding security throughout the CI/CD pipeline. You will conduct pre-release manual penetration testing and threat modelling to identify risks early. The role partners with engineering and DevSecOps teams to secure cloud workloads on Azure and/or AWS. This is a hybrid position based in London, Manchester, or Glasgow with periodic office presence.
Pay / Benefits
- hybrid work model
- salary up to 85k
- bonus potential
- regional hybrid presence in London, Manchester, or Glasgow
Responsibilities
- perform secure code reviews and vulnerability assessments
- conduct SAST/DAST scans and manage vulnerability remediation
- embed security practices across the CI/CD lifecycle
- carry out pre-release manual penetration testing
- conduct threat modelling to identify threats and mitigations
- work with engineering and DevSecOps teams to improve security posture
- secure cloud environments on Azure and/or AWS
- utilise Kali Linux for manual testing when needed
Key requirements
- strong application security experience
- knowledge of OWASP Top 10
- experience with Veracode or similar scanning tools
- DevSecOps/CI/CD experience
- cloud security experience on Azure and/or AWS
- Kali Linux familiarity
- manual PenTesting skills
- application security
- OWASP Top 10
- Veracode
- SAST/DAST
- DevSecOps/CI/CD
- cloud security (Azure/AWS)
…
