> Markdown version of [/jobs/ext/2239195-application-security-architect-manchester](https://www.wearedevelopers.com/jobs/ext/2239195-application-security-architect-manchester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Architect (Manchester) - **Company:** Insight - **Location:** Manchester, UK - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Automation of Tests, Microsoft Azure, Burp Suite, Cloud Computing Security, Static Program Analysis, Cyber Security, Continuous Integration, DevOps, Dynamic Program Analysis, Github, Octopus Deploy, Open Web Application Security, Systems Development Life Cycle, Fortify (Software), Secure Coding, Software Engineering, Software Security, Veracode, Cloudformation, Kubernetes, Checkmarx, Teamcity, Terraform, Prisma Cloud Platform, Devsecops, Docker, Static Application Security Testing, Microservices, Dynamic Application Security Testing - **Published:** August 26, 2026 - **Apply:** https://www.collegerecruiter.com/job/2815089786-application-security-architect-manchester ## About the Role Insight Investment is looking for an Application Security Architect to join our Cyber Security team in Manchester. This role focuses on embedding security into the software development lifecycle and driving DevSecOps practices across engineering teams. The ideal candidate will have a strong technical background in application security, secure coding, and automation within CI/CD pipelines., * Strong understanding of application security principles (e.g., OWASP Top 10, CWE) * Hands-on experience with one of each or more security tools: * Static Analysis (SAST): Veracode (preferable), Checkmarx, Fortify, etc * Dynamic Analysis (DAST): Veracode (preferable), Burp Suite, OWASP ZAP, etc * Software Composition Analysis (SCA): Veracode (preferable), Snyk, Black Duck, etc * Container Security: Aqua Security (preferable), Prisma Cloud, etc * Familiarity with CI/CD tools (e.g., Github Actions, Teamcity, Octopus, Azure DevOps) * Knowledge of containerised environments and their security best practices (Docker, Kubernetes) * Knowledge of cloud security (Azure) and infrastructure-as-code (Terraform, CloudFormation) * (Preferable) Experience with threat modeling tools (e.g., Threat Dragon, IriusRisk) ## Description Insight Investment is looking for an Application Security Architect to join our Cyber Security team in Manchester. This role focuses on embedding security into the software development lifecycle and driving DevSecOps practices across engineering teams. The ideal candidate will have a strong technical background in application security, secure coding, and automation within CI/CD pipelines. Role Responsibilities * Collaborate with development, DevOps, and architecture teams to integrate security into the SDLC * Design and implement secure coding practices and threat modelling processes * Lead the integration of security tools into CI/CD pipelines (e.g., SAST, DAST, SCA, IAST) * Conduct security assessments of applications, APIs, and microservices * Develop and maintain security standards, guidelines, and automation scripts * Provide guidance on secure design patterns and architecture decisions * Promote a DevSecOps culture and continuous security improvement across development and architecture team Experience Required * Strong understanding of application security principles (e.g., OWASP Top 10, CWE) * Hands-on experience with one of each or more security tools: * Static Analysis (SAST): Veracode (preferable), Checkmarx, Fortify, etc * Dynamic Analysis (DAST): Veracode (preferable), Burp Suite, OWASP ZAP, etc * Software Composition Analysis (SCA): Veracode (preferable), Snyk, Black Duck, etc * Container Security: Aqua Security (preferable), Prisma Cloud, etc * Familiarity with CI/CD tools (e.g., Github Actions, Teamcity, Octopus, Azure DevOps) * Knowledge of containerised environments and their security best practices (Docker, Kubernetes) * Knowledge of cloud security (Azure) and infrastructure-as-code (Terraform, CloudFormation) * (Preferable) Experience with threat modeling tools (e.g., Threat Dragon, IriusRisk) Insight is committed to being an inclusive employer and encourages applications from all suitably qualified applicants irrespective of background, circumstances, age, disability, gender identity, ethnicity, religion or belief and sexual orientation. If you are a candidate with a disability, or are assisting a candidate with a disability, and require an accommodation to apply for one of our jobs, please email us at ## Related Videos - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)