Senior Application Security Engineer / DevSecOps Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+15 more
Job description
Do you have a background in Application Security, DevSecOps or Product Security, with hands-on experience embedding application security into the SDLC? If so, this could be an opportunity worth considering.Join a well-established health research organisation and charity supporting large-scale medical research.
You will work closely with engineering, architecture and cloud teams to integrate security throughout the software development lifecycle.
Microsoft Azure and KQL experience are essential, alongside relevant experience in CI/CD, Kubernetes, API security, security-as-code and security automation.
This is a hands-on application security role focused on secure design, application security testing and supporting development teams to build secure applications., * Working with engineering and architecture teams to promote secure development.
- Implementing and maintaining application security testing solutions.
- Integrating security controls into CI/CD pipelines.
- Strengthening the security of GitHub Actions and similar CI/CD platforms.
- Providing guidance on secure API design and externally accessible systems.
- Supporting Azure cloud infrastructure, including Azure Kubernetes Service (AKS).
- Developing security-as-code and policy-as-code.
- Supporting the security of cloud-hosted data platforms.
- Automating security processes through infrastructure-as-code and scripting.
- Maintaining technical and security documentation.
- Supporting development teams with security tooling and best practices.
- Contributing to threat modelling and compliance activities.
Requirements
- Hands-on experience embedding application security into the SDLC.
- Experience with Microsoft Azure security controls and cloud security governance.
- Experience with KQL.
- Experience securing APIs, internet-facing services, Kubernetes, preferably AKS, and containerised environments.
- Experience with SAST, DAST, IAST and SCA.
- Knowledge of security automation, security-/policy-as-code and secure engineering practices.
- Familiarity with GitHub and GitHub Actions.
- Experience with Terraform and Python.
- Understanding of cloud security governance.Experience with threat modelling in software engineering contexts.
- Knowledge of ISO 27001 and its relevance to secure engineering.
- Exposure to Agile working environments and DevSecOps practices
- Ideally experience securing data platforms such as Databricks, Dagster or Snowflake
- Eligible to work in the UK.
Benefits & conditions
This is a full-time permanent role predominantly remote / hybrid in London offerings benefits and a salary of £80,000 which can be negotiable for right candidate., * £80,000 DOE, negotiable
- Predominantly remote / hybrid working
- London office
- Full-time permanent position
- Excellent benefits package
About the company
It is important you are aware of your individual rights and the provisions the company has put in place to protect your data.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Why Upskilling And Reskilling is Important For Developers
The 12 Best Jobs for Software Engineers
Fully Remote Software Engineer Jobs
The Most Popular IT Jobs on the Market