Application Security Specialist
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+19 more
Job description
Join a growing Cyber, Risk & Security team and play a pivotal role in strengthening the security of products, platforms and services delivered across a complex European technology environment. As an Application Security Specialist, you’ll be a key member of the Secure Development Centre of Excellence (CoE), partnering with engineering teams to embed security throughout the software development lifecycle. You’ll drive a security-first culture, influence development standards, and help deliver secure, resilient applications for both internal and customer-facing solutions., Application Security & Assurance
- Lead application security reviews for high-risk products and services.
- Conduct and oversee SAST, DAST, fuzz testing and API security assessments.
- Perform architecture, design and code security reviews.
- Assess applications against OWASP Top 10 and other industry standards.
- Translate findings into practical remediation plans and developer guidance., * Support the development of secure coding standards across technologies including Java, C and C++.
- Embed security throughout the Software Development Lifecycle (SDLC).
- Design and support secure CI/CD pipeline patterns.
- Integrate SAST, DAST, SCA and security tooling into development workflows.
- Support automation of security controls and assurance activities.
Security Leadership & Developer Enablement
- Act as a subject matter expert for Application Security across the organisation.
- Deliver secure coding training, workshops and awareness sessions.
- Mentor development teams and promote security-first engineering practices.
- Drive adoption of secure development standards and methodologies.
Threat & Vulnerability Management
- Support application vulnerability management activities.
- Assist development teams with vulnerability triage and remediation planning.
- Identify recurring weaknesses and opportunities for continuous improvement.
- Monitor emerging threats, vulnerabilities and industry trends.
Secure AI Development
- Support the adoption of secure development practices for AI-enabled applications.
- Assist with controls relating to AI model security, data handling and misuse risks.
- Help development teams securely adopt emerging technologies.
Requirements
- 3-5 years’ experience within Application Security, Secure Development, or Software Engineering with a security focus.
- Hands-on experience conducting application security reviews and assessments.
- Strong knowledge of application security principles and secure coding practices.
- Experience working with SAST, DAST and Software Composition Analysis (SCA) tools.
- Experience integrating security controls into CI/CD pipelines.
- Strong understanding of OWASP Top 10 and common vulnerability classes.
- Experience with API and web application security.
- Knowledge of threat modelling techniques and methodologies.
- Experience working closely with software engineering teams in enterprise environments.
- Ability to read and understand code in languages such as Java, C, C++, C#, Python or similar.
- Strong understanding of shift-left security and secure development lifecycle practices.
Highly Desirable Skills:
- Fuzz testing and advanced dynamic testing techniques.
- Manual code review experience.
- DevSecOps implementation and security automation.
- Experience integrating SAST, DAST, SCA and secrets scanning tools.
- Cloud-native, microservices and serverless architecture security.
- Secure AI and data-driven application security.
- OWASP SAMM, ASVS or other security maturity frameworks.
- Experience building or supporting a Security Centre of Excellence.
- Experience working within multinational or multi-entity organisations.
- Delivery of developer-focused security training and workshops., * Degree or equivalent professional experience in:
- Computer Science
- Software Engineering
- Cyber Security
- Information Security
- Or a related technical discipline.
- Formal training, certification or demonstrable experience within Secure Development or Application Security., * CSSLP (Certified Secure Software Lifecycle Professional).
- GWAPT or GWEB.
- OSCP or equivalent Offensive Security certifications.
- Microsoft Azure Security Engineer Associate.
- AWS Security Specialty.
- Google Professional Cloud Security Engineer.
- DevSecOps or CI/CD related certifications.
- ISO 27001 certifications.
- NIST CSF and NIST SSDF knowledge.
Benefits & conditions
- Competitive salary
- Annual bonus
- Car allowance
- Hybrid working
- Comprehensive benefits package
- Ongoing training and professional development
- Industry-recognised certification support
- Exposure to enterprise-scale application security programmes
- Opportunity to work with modern cloud, DevSecOps and AI technologies
- Clear career progression within a growing cyber security function
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
The 12 Best Jobs for Software Engineers
Why Upskilling And Reskilling is Important For Developers
Is Software Engineering Over-Saturated?
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.