Overview
In this role you protect Shawbrook’s software from cyber threats and safeguard digital assets. You’ll work across a complex tech environment, applying security best practices and modern tooling to harden web apps and cloud deployments. You’ll partner with DevSecOps to embed security into CI/CD and stay ahead of evolving risks. This position offers exposure to a wide range of systems and a chance to shape secure software delivery at scale.
Pay / Benefits
- Market leading family friendly policies
- Free Headspace access
- Free Peppy app for fertility and menopause
- EAP support
- Cycle to work scheme
- Pension scheme & death in service
Responsibilities
- Conduct thorough code reviews to improve security and compliance
- Perform advanced penetration testing and vulnerability assessments
- Utilize Qualys and other patch management tools for up-to-date security
- Deploy Veracode and similar tools to remediate code security issues
- Collaborate with DevSecOps teams to automate security in the CI/CD pipeline
- Harness Azure and cloud security practices for secure cloud applications
- Apply OWASP Top Ten knowledge to enhance web app security
- Stay updated on AI/ML for security threat prevention
- Secure containerized apps with Docker and Kubernetes
- Secure APIs using modern security mechanisms and protocols
Key requirements
- Web Application Security Experience using OWASP Top Ten and related tools
- In-depth Code Review to identify vulnerabilities and ensure secure coding practices
- Experience with Scanning Tools such as Veracode or equivalent
- DevSecOps and CI/CD collaboration to integrate security
- Cloud Security Experience with Azure and AWS
- OWASP Top Ten
- Veracode
- CI/CD
- DevSecOps
- Azure
- AWS
…
