Senior Application Security Specialist
2 days ago
London
The Application Security Specialist exists to embed application security expertise across Europe’s products and services, supporting the Secure Development Practice and enabling a consistent ‘shift-left’ approach. The role is accountable for advancing application security capability, leading security reviews on higher-risk systems, and ensuring secure development practices are adopted across engineering teams. The post holder will act as a technical authority on application security, helping reduce vulnerability risk and improve security outcomes across both internal IT systems and customer-facing solutions. \n \n\n • Strong knowledge of application security principles and practices\n, • Experience with SAST, DAST and software composition analysis tools\n, • Knowledge of secure coding practices across languages such as Java, C, C++\n, • Experience with CI/CD pipelines and DevSecOps integration\n, • Threat modelling techniques and tools\n, • Understanding of OWASP Top 10 and common vulnerability classes\n, • Experience with API security and web application security\n, • Understanding of fuzz testing and advanced testing techniques\n, • Familiarity with secure AI development considerations\n, • Knowledge of secure development frameworks such as SSDF\n, • Understanding of vulnerability management processes\n\n \n Experience Required \n Minimum \n\n • 3 to 5 years in application security, secure development or software engineering with a security focus\n, • Hands-on experience conducting application security reviews\n, • Experience implementing security in CI/CD processes\n, • Experience working with development teams in an enterprise environment\n\n Desirable \n\n • Experience building or contributing to a security CoE or capability model\n, • Experience working in a multi-entity, multinational environment\n, • Experience integrating security into large-scale development programmes\n, • Experience supporting secure AI or data-centric applications\n\n \n Minimum Qualifications Required \n Minimum \n\n • Degree or equivalent professional experience in one of the following:\n, • computer science\n, • software engineering\n, • cyber security\n, • information security or related technical discipline\n, • Evidence of formal or structured learning in secure development or application security (for example through certifications, formal training or demonstrable experience).\n\n Desirable \n\n • Recognised application security or secure development certification, such as:\n, • CSSLP (Certified Secure Software Lifecycle Professional)\n, • GIAC Web Application Penetration Tester (GWAPT) or GWEB\n, • Offensive Security certifications (e.g. OSCP) where relevant to application testing\n, • Cloud security certifications relevant to application hosting environments:\n, • AWS Security Specialty\n, • Microsoft Azure Security Engineer Associate\n, • Google Professional Cloud Security Engineer\n, • DevSecOps or CI/CD related certifications or formal training\n, • ISO 27001 Lead Implementer or Lead Auditor, or demonstrable understanding of ISO control environments\n, • Familiarity with NIST frameworks, particularly NIST CSF and NIST SSDF, demonstrated through training or experience\n, • Relevant vendor certifications linked to SAST, DAST, SCA or pipeline tooling where used in the organisation\n, • Evidence of continuous professional development in secure coding, software assurance or emerging technologies such as AI security\n\n \n Minimum Skills Required \n Minimum \n\n • Strong software engineering foundation: \n, • ability to read and understand code across at least one major language (Java, C, C++, C#, Python or similar)\n, • understanding of common development frameworks and application architectures\n, • Practical application security capability: \n, • hands-on experience identifying and explaining common vulnerabilities\n, • ability to guide remediation in a way developers can implement\n, • Secure development lifecycle knowledge: \n, • understanding of how to embed security into design, build, test and deployment stages\n, • familiarity with shift-left practices and developer workflows\n, • Threat modelling capability: \n, • ability to identify threats, abuse cases and attack surfaces\n, • experience applying structured approaches such as STRIDE or similar\n, • CI/CD and DevOps familiarity: \n, • understanding of pipelines, build processes and release workflows\n, • capability to integrate or advise on automated security testing within pipelines\n, • Analytical and diagnostic capability: \n, • ability to interpret scan results and distinguish false positives from real risk\n, • ability to identify systemic issues rather than isolated defects\n, • Communication and influence: \n, • ability to translate security issues into actionable developer guidance\n, • confidence in engaging engineers, architects and product owners\n, • Risk awareness: \n, • ability to link technical vulnerabilities to business risk and prioritisation\n\n \n Desirable \n\n • Advanced application security techniques: \n, • experience with fuzz testing, advanced dynamic testing or manual code review\n, • experience testing APIs, microservices and distributed systems\n, • DevSecOps implementation: \n, • experience designing or implementing security controls within CI/CD pipelines\n, • hands-on experience integrating SAST, DAST, SCA and secrets scanning tools\n, • Secure architecture understanding: \n, • familiarity with secure design patterns and common failure modes in modern architectures (cloud-native, microservices, serverless)\n, • Secure AI and data-driven systems awareness: \n, • understanding of risks associated with AI models, data pipelines and prompt or model manipulation\n, • Training and enablement capability: \n, • ability to design or deliver developer-focused training or workshops\n, • ability to simplify complex security concepts without diluting technical accuracy\n, • Broader security framework awareness: \n, • working knowledge of OWASP SAMM, ASVS or similar maturity models\n, • familiarity with threat intelligence inputs and how they influence application risk\n, • Tooling depth: \n, • experience selecting, tuning or optimising security tools for development environments\n, • understanding of strengths and limitations of common tooling categories\n, • Multi-environment experience: \n, • exposure to both internal enterprise IT systems and externally facing customer solutions\n, • Ability to operate in federated organisations: \n, • comfort working across multiple teams, geographies and delivery models with varying levels of maturity\n\n