Overview
In this role you will strengthen the security of software across the engineering and DevSecOps lifecycle for a leading UK financial services organisation. You will perform secure code reviews, SAST/DAST scanning, vulnerability assessments, and embed security practices within CI/CD. The role includes pre-release manual pen-testing and threat modelling to mitigate risk. It is a hybrid position based in London, Manchester, or Glasgow, with in-office presence about once a week. A competitive salary and bonus potential accompany the opportunity to influence security across key applications.
Pay / Benefits
- hybrid working model
- bonus potential
Responsibilities
- Secure code reviews and SAST/DAST scanning
- Vulnerability assessments and risk mitigation across CI/CD pipelines
- Embed security practices throughout the CI/CD lifecycle
- Pre-release manual penetration testing
- Threat modelling and security design reviews
Key requirements
- Strong application security experience including OWASP Top 10
- Experience with Veracode or similar scanning tools
- DevSecOps/CI-CD security practices
- Cloud security experience across Azure and/or AWS
- Kali Linux experience and manual penetration testing skills
- OWASP Top 10
- Veracode or similar scanning tools
- SAST/DAST
- DevSecOps/CI/CD
- Cloud security (Azure and/or AWS)
- Kali Linux
…
