Senior Application Security Consultant (SAST/DAST/OWASP )
18 days ago
London
Senior Application Security Consultant (SAST/DAST/OWASP )/ DevSecOps Security - Banking - London \n Secure SDLC | SAST | DAST | Threat Modelling | Cloud Security | CI/CD \n Location: London (Hybrid - 8 days onsite per month) \n Contract: 12 Months + extension \n Rate:£500-£550 per day (Umbrella) \n The Opportunity \n We're looking for an experienced Senior Application Security Consultant / DevSecOps Security Architect to join a high-performing Cyber Security function within a large enterprise technology environment. \n Working alongside software engineering, cloud, architecture and DevOps teams, you'll play a key role in embedding security throughout the Software Development Lifecycle, ensuring applications are designed, developed and deployed securely. \n \n This is an excellent opportunity for someone passionate about Secure-by-Design, DevSecOps and modern Application Security within a large-scale cloud environment. \n Key Responsibilities \n\n • Lead application security reviews across business-critical applications and cloud platforms.\n, • Conduct security architecture and secure design reviews.\n, • Perform application security risk assessments and define security requirements.\n, • Lead Threat Modelling workshops using STRIDE, MITRE ATT&CK or similar methodologies.\n, • Embed Secure SDLC principles into engineering teams.\n, • Integrate security tooling into CI/CD pipelines and DevSecOps processes.\n, • Review and analyse SAST, DAST and Software Composition Analysis (SCA) findings.\n, • Work closely with development teams to prioritise vulnerability remediation.\n, • Define security testing requirements and support penetration testing activities.\n, • Produce security standards, technical guidance and best practice documentation.\n, • Act as the Application Security SME across multiple technology programmes.\n\n Essential Skills \n Application Security \n\n • Secure Software Development Lifecycle (SSDLC)\n, • OWASP Top 10\n, • Secure Coding\n, • Secure Design Reviews\n, • API Security\n, • REST APIs\n, • Microservices Security\n, • Application Security Risk Assessments\n\n Threat Modelling \n\n • STRIDE\n, • MITRE ATT&CK\n, • Security Architecture\n, • Risk Assessments\n\n DevSecOps \n\n • CI/CD Security\n, • GitHub Actions\n, • GitLab\n, • Jenkins\n, • Azure DevOps\n, • Security Automation\n, • Shift Left Security\n\n Security Testing \n\n • SAST\n, • DAST\n, • SCA\n, • Vulnerability Management\n, • Penetration Testing\n\n Cloud Security \n\n • AWS, Azure or GCP\n, • Kubernetes\n, • Docker\n, • Container Security\n, • Cloud Security Best Practices\n\n Security Tooling \n Experience with one or more of: \n\n • Checkmarx\n, • Fortify\n, • SonarQube\n, • Veracode\n, • Semgrep\n, • Burp Suite\n, • OWASP ZAP\n, • Snyk\n, • Trivy\n, • Prisma Cloud\n, • Aqua\n, • Wiz\n\n Ideal Background \n You'll ideally have: \n\n • 8+ years in Cyber Security\n, • Strong Application Security or DevSecOps experience\n, • Experience working directly with software engineering teams\n, • Experience embedding security into CI/CD pipelines\n, • Strong knowledge of Secure SDLC\n, • Experience conducting Threat Modelling sessions\n, • Excellent stakeholder management and communication skills\n, • Previous experience within Banking, Financial Services, Insurance or another highly regulated enterprise environment\n\n Contract Details \n\n • 12-month contract\n, • £500-£600 per day (Umbrella)\n, • Hybrid working - 8 days onsite per month in London\n, • Immediate interview availability preferred\n\n *Rates depend on experience and client requirements