Application Security Architect (Manchester)

Insight
Manchester, UK
2 days ago
Apply on www.collegerecruiter.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Kubernetes Security Application Programming Interfaces (APIs) Automation of Tests Microsoft Azure Burp Suite Cloud Computing Security Static Program Analysis Cyber Security Continuous Integration DevOps Dynamic Program Analysis Github
+19 more
Octopus Deploy Open Web Application Security Systems Development Life Cycle Fortify (Software) Secure Coding Software Engineering Software Security Veracode Cloudformation Kubernetes Checkmarx Teamcity Terraform Prisma Cloud Platform Devsecops Docker Static Application Security Testing Microservices Dynamic Application Security Testing

Job description

Insight Investment is looking for an Application Security Architect to join our Cyber Security team in Manchester. This role focuses on embedding security into the software development lifecycle and driving DevSecOps practices across engineering teams. The ideal candidate will have a strong technical background in application security, secure coding, and automation within CI/CD pipelines.

Role Responsibilities

  • Collaborate with development, DevOps, and architecture teams to integrate security into the SDLC
  • Design and implement secure coding practices and threat modelling processes
  • Lead the integration of security tools into CI/CD pipelines (e.g., SAST, DAST, SCA, IAST)
  • Conduct security assessments of applications, APIs, and microservices
  • Develop and maintain security standards, guidelines, and automation scripts
  • Provide guidance on secure design patterns and architecture decisions
  • Promote a DevSecOps culture and continuous security improvement across development and architecture team

Experience Required

  • Strong understanding of application security principles (e.g., OWASP Top 10, CWE)
  • Hands-on experience with one of each or more security tools:
  • Static Analysis (SAST): Veracode (preferable), Checkmarx, Fortify, etc
  • Dynamic Analysis (DAST): Veracode (preferable), Burp Suite, OWASP ZAP, etc
  • Software Composition Analysis (SCA): Veracode (preferable), Snyk, Black Duck, etc
  • Container Security: Aqua Security (preferable), Prisma Cloud, etc
  • Familiarity with CI/CD tools (e.g., Github Actions, Teamcity, Octopus, Azure DevOps)
  • Knowledge of containerised environments and their security best practices (Docker, Kubernetes)
  • Knowledge of cloud security (Azure) and infrastructure-as-code (Terraform, CloudFormation)
  • (Preferable) Experience with threat modeling tools (e.g., Threat Dragon, IriusRisk)

Insight is committed to being an inclusive employer and encourages applications from all suitably qualified applicants irrespective of background, circumstances, age, disability, gender identity, ethnicity, religion or belief and sexual orientation. If you are a candidate with a disability, or are assisting a candidate with a disability, and require an accommodation to apply for one of our jobs, please email us at

Requirements

Insight Investment is looking for an Application Security Architect to join our Cyber Security team in Manchester. This role focuses on embedding security into the software development lifecycle and driving DevSecOps practices across engineering teams. The ideal candidate will have a strong technical background in application security, secure coding, and automation within CI/CD pipelines., * Strong understanding of application security principles (e.g., OWASP Top 10, CWE)

  • Hands-on experience with one of each or more security tools:
  • Static Analysis (SAST): Veracode (preferable), Checkmarx, Fortify, etc
  • Dynamic Analysis (DAST): Veracode (preferable), Burp Suite, OWASP ZAP, etc
  • Software Composition Analysis (SCA): Veracode (preferable), Snyk, Black Duck, etc
  • Container Security: Aqua Security (preferable), Prisma Cloud, etc
  • Familiarity with CI/CD tools (e.g., Github Actions, Teamcity, Octopus, Azure DevOps)
  • Knowledge of containerised environments and their security best practices (Docker, Kubernetes)
  • Knowledge of cloud security (Azure) and infrastructure-as-code (Terraform, CloudFormation)
  • (Preferable) Experience with threat modeling tools (e.g., Threat Dragon, IriusRisk)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.collegerecruiter.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · World Congress 2026 Europe

Videos

See all

Related articles

See all