Application Security Engineer Cyber - Financial Services - SGI

The Source
London, UK
17 days ago
Apply on www.reed.co.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Job source

Tech stack

JavaScript (Programming Language) Artificial Intelligence Amazon Web Services Application Firewall Business Logic Software System Penetration Testing Microsoft Azure C Sharp (Programming Language) Cyber Security Continuous Integration Web Development Github
+15 more
Identity and Access Management Intrusion Detection Systems Python (Programming Language) Open Web Application Security Windows PowerShell Secure Coding Software Engineering Cloud Platform System Software Security Information Technology Build Tools Virtual Agents Software Coding Static Application Security Testing Dynamic Application Security Testing

Job description

The successful candidate will have very strong application security, web application development experience and team leadership skills to join a growing Information Security team and assist with the operation of the AppSec function., In this position, you are a passionate and talented application security engineer with very deep understanding of OWASP, CWE 25, Data Protection, Access management, software vulnerabilities, best practices design and threat modelling skills, who can work in a dynamic environment. You must be dedicated to able to work with developers in producing secure code in short time frames and be willing to go beyond the standard routine. Your primary responsibilities includes:

  • Work as part of a team of software and security engineers to design/maintain and build best-in-class product security tools and services.
  • Technical point of contact for product teams as it relates to automation, CI/CD, and Product Application Security Operations
  • Using approved AI models and cyber harnesses to assess application code for business logic weaknesses, misconfiguration and vulnerabilities.
  • Build tools and automation scripts that enable developers to easily consume security services delivered by Security Engineering and Automation team
  • Responsible for security product QA and Testing
  • Build strong relationships with product development teams
  • Run software composition analysis (SCA) tools
  • To understand and explain penetration testing findings to the software engineering teams helping them to triage the findings and explaining how to mitigate the risks
  • To articulate business risk when assessing software vulnerabilities
  • Continuously improve the operations of SAST, DAST and IaC security tools
  • Continuously improve the operations of Web Application Firewalls (WAF) or IDS
  • Continuously improve the coverage of security tooling in Cloud environments e.g. Microsoft Azure & Amazon AWS

Requirements

  • Computer Science / Cyber Security Degree
  • Application Development background
  • Azure DevOps experience
  • Prior experience in using AI models and cyber harnesses to support security evaluation of application and software code.
  • GitHub, Copilot, Codex, OWASP Top 10 for Agentic AI, AI skills development and security triage.
  • Ability to code in at least one programming language e.g. Python/JavaScript/CSharp/Powershell
  • Prior experience working in a large organisation or Financial Services is an advantage
  • Excellent analytical skills with attention to details
  • CISSP/CSSLP/CEH/OSCP or similar certification
  • Presentation skills - ability to present complex solutions to a less technical audience
  • Team-player interpersonal skills, with the ability to communicate and collaborate effectively with different people in a variety of roles
  • Passionate about developing a career in Information Security
  • Excellent command of the English language, both written and spoken

What you’ll be like

  • Passionate about mastering and innovating best practice in business analysis
  • Inspiring and collaborative leader, model of agile leadership approach
  • Friendly, approachable, enjoys working with people from a variety of backgrounds
  • Capable of remaining positive when under pressure
  • Continuous improvement mind-set, challenges the status quo and seeks self improvement
  • Problem solver, comfortable taking the initiative in challenging and ambiguous circumstances

By applying for this role, you consent to SGI contacting you by telephone regarding recruitment services, market updates, and relevant business opportunities

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.reed.co.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

48 sec

Exploring alternative build tools and experimental web components

Sasha Shynkevich · LIVE

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

Videos

See all

Related articles

See all