Senior Application Security Consultant (SAST/DAST/OWASP )
London
£500 - £550/day
Posted 1 day ago
About the role
Senior Application Security Consultant (SAST/DAST/OWASP )/ DevSecOps Security - Banking - London
Secure SDLC | SAST | DAST | Threat Modelling | Cloud Security | CI/CD
Location: London (Hybrid - 8 days onsite per month)
Contract: 12 Months + extension
Rate: £500-£550 per day (Umbrella)
The Opportunity
We're looking for an experienced Senior Application Security Consultant / DevSecOps Security Architect to join a high-performing Cyber Security function within a large enterprise technology environment.
Working alongside software engineering, cloud, architecture and DevOps teams, you'll play a key role in embedding security throughout the Software Development Lifecycle, ensuring applications are designed, developed and deployed securely.
This is an excellent opportunity for someone passionate about Secure-by-Design, DevSecOps and modern Application Security within a large-scale cloud environment.
Key Responsibilities
Lead application security reviews across business-critical applications and cloud platforms.
Conduct security architecture and secure design reviews.
Perform application security risk assessments and define security requirements.
Lead Threat Modelling workshops using STRIDE, MITRE ATT&CK or similar methodologies.
Embed Secure SDLC principles into engineering teams.
Integrate security tooling into CI/CD pipelines and DevSecOps processes.
Review and analyse SAST, DAST and Software Composition Analysis (SCA) findings.
Work closely with development teams to prioritise vulnerability remediation.
Define security testing requirements and support penetration testing activities.
Produce security standards, technical guidance and best practice documentation.
Act as the Application Security SME across multiple technology programmes.Essential Skills
Application Security
Secure Software Development Lifecycle (SSDLC)
OWASP Top 10
Secure Coding
Secure Design Reviews
API Security
REST APIs
Microservices Security
Application Security Risk AssessmentsThreat Modelling
STRIDE
MITRE ATT&CK
Security Architecture
Risk AssessmentsDevSecOps
CI/CD Security
GitHub Actions
GitLab
Jenkins
Azure DevOps
Security Automation
Shift Left SecuritySecurity Testing
SAST
DAST
SCA
Vulnerability Management
Penetration TestingCloud Security
AWS, Azure or GCP
Kubernetes
Docker
Container Security
Cloud Security Best PracticesSecurity Tooling
Experience with one or more of:
Checkmarx
Fortify
SonarQube
Veracode
Semgrep
Burp Suite
OWASP ZAP
Snyk
Trivy
Prisma Cloud
Aqua
WizIdeal Background
You'll ideally have:
8+ years in Cyber Security
Strong Application Security or DevSecOps experience
Experience working directly with software engineering teams
Experience embedding security into CI/CD pipelines
Strong knowledge of Secure SDLC
Experience conducting Threat Modelling sessions
Excellent stakeholder management and communication skills
Previous experience within Banking, Financial Services, Insurance or another highly regulated enterprise environmentContract Details
12-month contract
£500-£600 per day (Umbrella)
Hybrid working - 8 days onsite per month in London
Immediate interview availability preferred*Rates depend on experience and client requirements
About this listing
Screened by Joboru
This role passed our automated spam and quality filters and was active in our feed when last checked. Joboru is an aggregator — here is how we screen listings. If anything looks off, tell us.
Similar jobs you may like
SC Cleated FPGA Engineer
1 day agoExperis
Programme Manager - Business Change
1 day agoTria
Data Protection and Privacy Analyst
1 day agoAdecco
Database Administrator
1 day agoExperis
IT Support
1 day agoOffice Angels
Senior Data Strategy Consultant, Marketing Solutions
1 day agoTransunion
Microsoft Purview Engineer
1 day agoRandstad Technologies Recruitment
Director of Investment, Risk and Operations
1 day agoExperis
Data Solution Architect
1 day agoExperis