> Markdown version of [/jobs/ext/2727423-application-security-specialist](https://www.wearedevelopers.com/jobs/ext/2727423-application-security-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Specialist - **Company:** Experis - **Location:** London, UK - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** C (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Microsoft Azure, C Sharp (Programming Language), C++ (Programming Language), Cloud Computing Security, Cloud Engineering, Code Review, Cyber Security, Continuous Integration, Fuzz Testing, Python (Programming Language), Open Web Application Security, Secure Coding, Web Application Security, Software Engineering, Software Vulnerability Management, Data Processing, Software Security, GWAPT, Information Technology, Data Analytics, Tenable Nessus, Devsecops, Serverless Computing, Security Orchestration, Automation & Response, Static Application Security Testing, Microservices, Dynamic Application Security Testing - **Published:** September 5, 2026 - **Apply:** https://www.experis.co.uk/job/application-security-specialist-6017996/apply ## About the Role * 3-5 years' experience within Application Security, Secure Development, or Software Engineering with a security focus. * Hands-on experience conducting application security reviews and assessments. * Strong knowledge of application security principles and secure coding practices. * Experience working with SAST, DAST and Software Composition Analysis (SCA) tools. * Experience integrating security controls into CI/CD pipelines. * Strong understanding of OWASP Top 10 and common vulnerability classes. * Experience with API and web application security. * Knowledge of threat modelling techniques and methodologies. * Experience working closely with software engineering teams in enterprise environments. * Ability to read and understand code in languages such as Java, C, C++, C#, Python or similar. * Strong understanding of shift-left security and secure development lifecycle practices. Highly Desirable Skills: * Fuzz testing and advanced dynamic testing techniques. * Manual code review experience. * DevSecOps implementation and security automation. * Experience integrating SAST, DAST, SCA and secrets scanning tools. * Cloud-native, microservices and serverless architecture security. * Secure AI and data-driven application security. * OWASP SAMM, ASVS or other security maturity frameworks. * Experience building or supporting a Security Centre of Excellence. * Experience working within multinational or multi-entity organisations. * Delivery of developer-focused security training and workshops., * Degree or equivalent professional experience in: + Computer Science + Software Engineering + Cyber Security + Information Security + Or a related technical discipline. * Formal training, certification or demonstrable experience within Secure Development or Application Security., * CSSLP (Certified Secure Software Lifecycle Professional). * GWAPT or GWEB. * OSCP or equivalent Offensive Security certifications. * Microsoft Azure Security Engineer Associate. * AWS Security Specialty. * Google Professional Cloud Security Engineer. * DevSecOps or CI/CD related certifications. * ISO 27001 certifications. * NIST CSF and NIST SSDF knowledge. ## Description Join a growing Cyber, Risk & Security team and play a pivotal role in strengthening the security of products, platforms and services delivered across a complex European technology environment. As an Application Security Specialist, you'll be a key member of the Secure Development Centre of Excellence (CoE), partnering with engineering teams to embed security throughout the software development lifecycle. You'll drive a security-first culture, influence development standards, and help deliver secure, resilient applications for both internal and customer-facing solutions., Application Security & Assurance * Lead application security reviews for high-risk products and services. * Conduct and oversee SAST, DAST, fuzz testing and API security assessments. * Perform architecture, design and code security reviews. * Assess applications against OWASP Top 10 and other industry standards. * Translate findings into practical remediation plans and developer guidance., * Support the development of secure coding standards across technologies including Java, C and C++. * Embed security throughout the Software Development Lifecycle (SDLC). * Design and support secure CI/CD pipeline patterns. * Integrate SAST, DAST, SCA and security tooling into development workflows. * Support automation of security controls and assurance activities. Security Leadership & Developer Enablement * Act as a subject matter expert for Application Security across the organisation. * Deliver secure coding training, workshops and awareness sessions. * Mentor development teams and promote security-first engineering practices. * Drive adoption of secure development standards and methodologies. Threat & Vulnerability Management * Support application vulnerability management activities. * Assist development teams with vulnerability triage and remediation planning. * Identify recurring weaknesses and opportunities for continuous improvement. * Monitor emerging threats, vulnerabilities and industry trends. Secure AI Development * Support the adoption of secure development practices for AI-enabled applications. * Assist with controls relating to AI model security, data handling and misuse risks. * Help development teams securely adopt emerging technologies. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [ Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)