> Markdown version of [/jobs/ext/3059362-lead-application-security-devsecops-engineer](https://www.wearedevelopers.com/jobs/ext/3059362-lead-application-security-devsecops-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Application Security/DevSecOps Engineer - **Company:** Faria Education Group - **Location:** Loughborough, UK - **Experience:** Expert - **Contract:** Contract - **Skills:** PHP (Programming Language), Artificial Intelligence, Amazon Web Services, Microsoft Azure, C Sharp (Programming Language), Cloud Computing Security, Continuous Integration, DevOps, Github, Python (Programming Language), Laravel, Ruby on Rails, Software Engineering, Software Vulnerability Management, Software Security, Devsecops, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 25, 2026 - **Apply:** https://faria.bamboohr.com/careers/272 ## About the Role * 7+ years in application/product security, ideally including standing up or substantially maturing an AppSec program (ideally near-zero to functioning). * Strong AI knowledge and curiosity in the space, with the aim of proactive protection, as well as approaching problem-solving AI-first * Comfortable as a founding, hands-on, solo function - self-directed and pragmatic under ambiguity * Breadth across stacks: able to work across Ruby on Rails, PHP/Laravel, .NET/C#, and Python (deep in one or two, competent across the rest). * Strong cloud security across AWS (primary) and Azure. * Deep grasp of common vulnerability classes and secure coding practices. * Hands-on with AppSec tooling and DevSecOps / CI/CD integration. * Threat-modeling experience. * Excellent communication and influencing skills - able to drive change in an engineering org, new to formal security. Nice to have * GitHub Advanced Security experience is a strong nice-to-have. * The candidate has worked with student data or PII-heavy regulated environments (FERPA, COPPA, GDPR for UK/EU students). * Proven experience managing large vulnerability backlogs: ability to classify, deduplicate, and drive burn-down across hundreds of repositories. ## Description We are looking for a Lead Security/DevSecOps Engineer on the Product Engineering team, with a great opportunity to be self-directed and level up security practices and capabilities. We expect this to be a hands-on leadership role with a potential opportunity to build/upskill a small team. The person will report to the VP of Engineering and work in partnership with the vCISO, DevOps team, and engineering teams., * Do an initial deep-dive assessment and evaluation to drive risk-based prioritisation of the following responsibilities * Stand up and own the application security program across all five products - this is effectively greenfield. * Define and embed a secure SDLC (shift-left): security requirements, design reviews, guardrails, and coding standards for an AI engineering reality. * Select, deploy, and operationalise AppSec tooling (SAST, DAST, SCA/dependency and secrets scanning) integrated into CI/CD. * Implement and operationalise secrets management: detection, rotation, and vault integration across CI/CD pipelines. * Build risk-based vulnerability management: triage, prioritise, and drive remediation across teams and stacks. Lead remediation of some vulnerabilities as necessary in support of the software engineering team * Run threat modeling and security reviews for new architecture and significant features. * Improve cloud security posture across AWS (primary) and Azure, partnering with platform/infra. * Lead technical incident response for application-layer incidents; coordinate with SOC and vCISO on cross-domain incidents. * Build security awareness and a security-champions network to upskill engineers. * Uphold student-data privacy and regulatory obligations. * Contribute technical evidence and metrics to support the security roadmap and future hiring decisions ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Laravel Core - Demystify The Beast](https://www.wearedevelopers.com/videos/98-the-laravel-core-demystify-the-beast) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [API Platform: From Rest & GraphQL APIs to state-of-the-art standards in seconds](https://www.wearedevelopers.com/videos/1968-api-platform-from-rest-graphql-apis-to-state-of-the-art-standards-in-seconds) ## Related Articles - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs)