> Markdown version of [/jobs/ext/351409-senior-cybersecurity-developer-application-security-architect-equity-only](https://www.wearedevelopers.com/jobs/ext/351409-senior-cybersecurity-developer-application-security-architect-equity-only). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cybersecurity Developer / Application Security Architect (Equity Only) - **Company:** HolistiQ Holdings - **Location:** UK (Remote available) - **Experience:** Expert - **Salary:** £54,940.0 - £120,782.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), .NET Framework, Application Programming Interfaces (APIs), Amazon Web Services, Amazon S3, Software System Penetration Testing, User Authentication, Microsoft Azure, C Sharp (Programming Language), C++ (Programming Language), Software as a Service, Cloud Computing, Cloud Computing Security, Cyber Security, DevOps, Digital Assets, Distributed Systems, Payment Systems, Fraud Prevention and Detection, Github, Identity and Access Management, Information Systems Security Architecture Professional, Key Management, PostgreSQL, Microsoft SQL Server, OAuth, Open Web Application Security, Systems Development Life Cycle, Role-Based Access Control, Openid Connect, Swagger, JSON Web Token, Secure Coding, Software Engineering, Openapi, .NET Core, Software Security, Asp.net Web Api, Backend, Xunit, Specflow, Gitlab-ci, Playwright, Cosmos DB, Unreal Engine, Api Gateway, Restful APIs, Marketplace, Devsecops, Atlassian Bamboo, Docker, Static Application Security Testing, Vulnerability Analysis, Microservices, Dynamic Application Security Testing - **Published:** June 18, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=2e55f9fa9358eda5 ## About the Role Do you have experience in SDLC?, * Minimum 8 years' experience in software development, cybersecurity, application security, or security architecture * Proven experience securing production applications, APIs, cloud-native environments, and distributed systems * Experience conducting vulnerability assessments, penetration testing, threat modelling, and security reviews * Strong understanding of Secure Software Development Lifecycle (SSDLC) Application Security * OWASP Top 10 * OAuth2, OpenID Connect, JWT * Authentication and Authorisation Systems * Role-Based Access Control (RBAC) * API Security * Secure Coding Practices * Threat Modelling * Fraud Prevention and Abuse Detection * Identity and Access Management (IAM) Cloud Security & DevSecOps * AWS Security (API Gateway, Cognito, Lambda, S3, RDS/Aurora) * Azure Security (DevOps, App Services, KeyVault, Cosmos DB) * Docker Security * Kubernetes Security * GitHub Security Workflows * GitLab CI/CD or Azure Pipelines * DevSecOps Methodologies * Secrets Management * Infrastructure Security Backend & Technical Knowledge * C# .NET / .NET Core / .NET 6-8 * Java (Spring or similar) * ASP.NET Web API * REST APIs (Swagger/OpenAPI) * Microservices Architecture * PostgreSQL * SQL Server Security Testing & Automation * Playwright * SpecFlow * xUnit * Security Testing Automation * Vulnerability Scanning * SAST and DAST Tooling * TDD and Secure Development Practices Security Governance & Compliance * Cyber Essentials * Cyber Essentials Plus * ISO 27001 * GDPR * UK Data Protection Act 2018 * Security Policies and Governance Frameworks * Incident Response Planning * Security Monitoring and Audit Controls Highly Desirable Experience * Marketplace Platforms * SaaS Products * E-Commerce Systems * Payment Platforms * Loyalty and Rewards Programmes * Digital Wallets * Platform Credits and Cashback Systems * Subscription-Based Platforms * Fraud Detection Systems Gaming & Interactive Systems (Advantageous) * Unity Engine (C#) * Unreal Engine (C++) * Multiplayer Systems Security * Virtual Economies and Reward Systems * Anti-Fraud and Anti-Cheat Concepts * Gamification Systems and Engagement Mechanics * Digital Asset and Transaction Security ## Description We are not looking for someone to simply monitor systems, produce reports, or tick compliance boxes. We are looking for someone who thinks differently. Someone who naturally questions how systems can be exploited, how trust can be broken, and how vulnerabilities can be eliminated before they become problems. Someone who can think like an attacker, build like an engineer, and lead like an architect. As our ecosystem continues to grow, security will be embedded into every product, feature, transaction, reward system, customer interaction, and business partnership. We believe security is not an afterthought-it is a competitive advantage. Role Overview This is a strategic technical leadership opportunity for an experienced Cybersecurity Developer / Application Security Architect who wants to play a key role in shaping the future of multiple products and platforms. You will work alongside our senior engineering team to design secure architectures, challenge assumptions, identify weaknesses before others do, and build secure, scalable, and resilient systems from day one. The successful candidate will become part of our core leadership team, helping define security strategy, governance frameworks, technical standards, and long-term product architecture across the HolistiQ ecosystem. ## Related Videos - [pytest: Simple, rapid and fun testing with Python](https://www.wearedevelopers.com/videos/213-pytest-simple-rapid-and-fun-testing-with-python) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london)