Lead Application Security/DevSecOps Engineer

Faria Education Group
Loughborough, UK
1 day ago
Apply on faria.bamboohr.com
Prepare application

Role details

Contract type
Contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

PHP (Programming Language) Artificial Intelligence Amazon Web Services Microsoft Azure C Sharp (Programming Language) Cloud Computing Security Continuous Integration DevOps Github Python (Programming Language) Laravel Ruby on Rails
+6 more
Software Engineering Software Vulnerability Management Software Security Devsecops Static Application Security Testing Dynamic Application Security Testing

Job description

We are looking for a Lead Security/DevSecOps Engineer on the Product Engineering team, with a great opportunity to be self-directed and level up security practices and capabilities. We expect this to be a hands-on leadership role with a potential opportunity to build/upskill a small team. The person will report to the VP of Engineering and work in partnership with the vCISO, DevOps team, and engineering teams., * Do an initial deep-dive assessment and evaluation to drive risk-based prioritisation of the following responsibilities

  • Stand up and own the application security program across all five products - this is effectively greenfield.
  • Define and embed a secure SDLC (shift-left): security requirements, design reviews, guardrails, and coding standards for an AI engineering reality.
  • Select, deploy, and operationalise AppSec tooling (SAST, DAST, SCA/dependency and secrets scanning) integrated into CI/CD.
  • Implement and operationalise secrets management: detection, rotation, and vault integration across CI/CD pipelines.
  • Build risk-based vulnerability management: triage, prioritise, and drive remediation across teams and stacks. Lead remediation of some vulnerabilities as necessary in support of the software engineering team
  • Run threat modeling and security reviews for new architecture and significant features.
  • Improve cloud security posture across AWS (primary) and Azure, partnering with platform/infra.
  • Lead technical incident response for application-layer incidents; coordinate with SOC and vCISO on cross-domain incidents.
  • Build security awareness and a security-champions network to upskill engineers.
  • Uphold student-data privacy and regulatory obligations.
  • Contribute technical evidence and metrics to support the security roadmap and future hiring decisions

Requirements

  • 7+ years in application/product security, ideally including standing up or substantially maturing an AppSec program (ideally near-zero to functioning).
  • Strong AI knowledge and curiosity in the space, with the aim of proactive protection, as well as approaching problem-solving AI-first
  • Comfortable as a founding, hands-on, solo function - self-directed and pragmatic under ambiguity
  • Breadth across stacks: able to work across Ruby on Rails, PHP/Laravel, .NET/C#, and Python (deep in one or two, competent across the rest).
  • Strong cloud security across AWS (primary) and Azure.
  • Deep grasp of common vulnerability classes and secure coding practices.
  • Hands-on with AppSec tooling and DevSecOps / CI/CD integration.
  • Threat-modeling experience.
  • Excellent communication and influencing skills - able to drive change in an engineering org, new to formal security.

Nice to have

  • GitHub Advanced Security experience is a strong nice-to-have.
  • The candidate has worked with student data or PII-heavy regulated environments (FERPA, COPPA, GDPR for UK/EU students).
  • Proven experience managing large vulnerability backlogs: ability to classify, deduplicate, and drive burn-down across hundreds of repositories.

Benefits & conditions

  • Compensation - Competitive compensation and opportunities for career development
  • Learning - We encourage continued education, providing an online learning platform, unlimited book purchases, and diverse internal and external training programs.
  • Team - Friendly atmosphere, group activities, and corporate events
  • Equipment - MacBook Pro or another laptop of your specification, peripherals, and displays included

About the company

Faria is a leader in international education systems & services, offering an integrated suite across learning, admissions, school-to-home, and online courses - trusted by 10,000+ schools and 4 million students across 155 countries.

Our product family includes ManageBac (curriculum, assessment & reporting for international schools), OpenApply (admissions management & CRM, used by 600+ leading international and independent schools), SchoolsBuddy (co-curricular & activity management), and Vectare (school transport management)., For over 15 years, Faria Education Group has deeply understood the needs of schools, leveraging extensive experience in education. Our dedication to reaching every learner and inspiring every educator has supported over 10,000 schools and 4 million students across 155 countries. We are committed to driving transformative experiences for learners, educators, and families globally.

Our integrated SaaS solutions suite supports all aspects of curriculum management (Atlas), teaching and learning (ManageBac), admissions (OpenApply), and school-to-home communications (SchoolsBuddy). With an unwavering commitment to innovation, our technology meets rigorous data protection and security standards and provides first-class training and support.

Through our innovative online schools (Pamoja and Wolsey Hall), we provide comprehensive educational experiences with IB Diploma and Cambridge online courses, delivering high-quality education to schools and homes worldwide.

Join us in our commitment to transforming education and empowering communities worldwide.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on faria.bamboohr.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

9:43 min

Tracing the HTTP request lifecycle inside Laravel

Rumpel Christoph · LIVE

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all