Application Security Specialist (Architecture) New
Role details
Job location
Tech stack
Job description
We are looking for an experienced Application security specialist to join our Cyber team with a hyper focus on supporting our application security architecture and risk management programme. You will help us build out a world class capability to align with our key stakeholders in the Games teams to provide a clear plan, review and support with threat modelling, architecture best practices, secure development lifecycle and overall risk remediation.
This is a hybrid role : Location: Cambridge, UK with travel to the office once per week.
What you'll be doing:
-
Provide guidance on security best practices and compliance and undertake security testing
-
Identify Application security risks and requirements for new projects and system developments
-
Represent cyber in review sprints on application security prior to live implementation
-
Collaborate with the architecture and development teams to review the design and code for security vulnerabilities
-
Establish a threat modelling capability and evangelise secure coding in the development lifecycle
-
Provide technical specialist advice to ensure that security standards are understood and can be complied with
-
Develop security testing plans and integrate into the software development lifecycle (S-SDLC)
-
Perform and oversee security testing and manage remediation of identified vulnerabilities
-
Take part in the security incident response team
-
Prepare and monitor application security metrics and KPIs
Note: This position will require participation in an on-call rotation
Requirements
-
At least 3 years of experience in software engineering.
-
At least 2 years of experience in application security.
-
In-depth knowledge of application security vulnerabilities, testing techniques, and the OWASP framework.
-
Team player able to build relationships across the organization.
-
In-depth understanding of secure web application development.
-
Experience in web application and Agile development methodologies.
-
Comprehensive knowledge of IT and information security subject matter.
-
Exposure to methods of promoting security awareness.
-
Strong communication (verbal/written) and influencing skills, with an ability to manage internal and external relationships up to senior levels of management.
-
Anticipates problems and identifies long-term implications of decisions and actions.
-
Ability to work and learn alone.
-
Able to prioritize workload and drive work to set deadlines.
-
Experience working with the hacker/pen-testing community.
Benefits & conditions
When you join Jagex you can look forward to a generous Perks & Benefits package including:
- Private Healthcare, including Dental Plan.
- Minimum 6% Pension contributions.
- Employee Assistance Programme & onsite Counselling.
- Life Insurance.
- Discretionary annual performance bonus.
- Enhanced family leave policies from day 1.
- Flexible working hours.
- 25 days annual leave + Bank holidays & the option to buy/sell holidays + so much more!