Senior Application Security Specialist
1 day ago
Slough
The Application Security Specialist exists to embed application security expertise across Europe’s products and services, supporting the Secure Development Practice and enabling a consistent ‘shift-left’ approach. The role is accountable for advancing application security capability, leading security reviews on higher-risk systems, and ensuring secure development practices are adopted across engineering teams. The post holder will act as a technical authority on application security, helping reduce vulnerability risk and improve security outcomes across both internal IT systems and customer-facing solutions. • Strong knowledge of application security principles and practices, • Experience with SAST, DAST and software composition analysis tools, • Knowledge of secure coding practices across languages such as Java, C, C++, • Experience with CI/CD pipelines and DevSecOps integration, • Threat modelling techniques and tools, • Understanding of OWASP Top 10 and common vulnerability classes, • Experience with API security and web application security, • Understanding of fuzz testing and advanced testing techniques, • Familiarity with secure AI development considerations, • Knowledge of secure development frameworks such as SSDF, • Understanding of vulnerability management processes Experience Required Minimum • 3 to 5 years in application security, secure development or software engineering with a security focus, • Hands-on experience conducting application security reviews, • Experience implementing security in CI/CD processes, • Experience working with development teams in an enterprise environment Desirable • Experience building or contributing to a security CoE or capability model, • Experience working in a multi-entity, multinational environment, • Experience integrating security into large-scale development programmes, • Experience supporting secure AI or data-centric applications Minimum Qualifications Required Minimum • Degree or equivalent professional experience in one of the following:, • computer science, • software engineering, • cyber security, • information security or related technical discipline, • Evidence of formal or structured learning in secure development or application security (for example through certifications, formal training or demonstrable experience). Desirable • Recognised application security or secure development certification, such as:, • CSSLP (Certified Secure Software Lifecycle Professional), • GIAC Web Application Penetration Tester (GWAPT) or GWEB, • Offensive Security certifications (e.g. OSCP) where relevant to application testing, • Cloud security certifications relevant to application hosting environments:, • AWS Security Specialty, • Microsoft Azure Security Engineer Associate, • Google Professional Cloud Security Engineer, • DevSecOps or CI/CD related certifications or formal training, • ISO 27001 Lead Implementer or Lead Auditor, or demonstrable understanding of ISO control environments, • Familiarity with NIST frameworks, particularly NIST CSF and NIST SSDF, demonstrated through training or experience, • Relevant vendor certifications linked to SAST, DAST, SCA or pipeline tooling where used in the organisation, • Evidence of continuous professional development in secure coding, software assurance or emerging technologies such as AI security Minimum Skills Required Minimum • Strong software engineering foundation:, • ability to read and understand code across at least one major language (Java, C, C++, C#, Python or similar), • understanding of common development frameworks and application architectures, • Practical application security capability:, • hands-on experience identifying and explaining common vulnerabilities, • ability to guide remediation in a way developers can implement, • Secure development lifecycle knowledge:, • understanding of how to embed security into design, build, test and deployment stages, • familiarity with shift-left practices and developer workflows, • Threat modelling capability:, • ability to identify threats, abuse cases and attack surfaces, • experience applying structured approaches such as STRIDE or similar, • CI/CD and DevOps familiarity:, • understanding of pipelines, build processes and release workflows, • capability to integrate or advise on automated security testing within pipelines, • Analytical and diagnostic capability:, • ability to interpret scan results and distinguish false positives from real risk, • ability to identify systemic issues rather than isolated defects, • Communication and influence:, • ability to translate security issues into actionable developer guidance, • confidence in engaging engineers, architects and product owners, • Risk awareness:, • ability to link technical vulnerabilities to business risk and prioritisation Desirable • Advanced application security techniques:, • experience with fuzz testing, advanced dynamic testing or manual code review, • experience testing APIs, microservices and distributed systems, • DevSecOps implementation:, • experience designing or implementing security controls within CI/CD pipelines, • hands-on experience integrating SAST, DAST, SCA and secrets scanning tools, • Secure architecture understanding:, • familiarity with secure design patterns and common failure modes in modern architectures (cloud-native, microservices, serverless), • Secure AI and data-driven systems awareness:, • understanding of risks associated with AI models, data pipelines and prompt or model manipulation, • Training and enablement capability:, • ability to design or deliver developer-focused training or workshops, • ability to simplify complex security concepts without diluting technical accuracy, • Broader security framework awareness:, • working knowledge of OWASP SAMM, ASVS or similar maturity models, • familiarity with threat intelligence inputs and how they influence application risk, • Tooling depth:, • experience selecting, tuning or optimising security tools for development environments, • understanding of strengths and limitations of common tooling categories, • Multi-environment experience:, • exposure to both internal enterprise IT systems and externally facing customer solutions, • Ability to operate in federated organisations:, • comfort working across multiple teams, geographies and delivery models with varying levels of maturity