Senior Application Security Engineer / DevSecOps Engineer

Additional Resources
London, UK
3 days ago
Apply on find.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
£80,000.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Agile Methodology Airflow Microsoft Azure Cloud Computing Security Encodings Continuous Integration Github Python (Programming Language) Systems Development Life Cycle Kusto Query Language Secure Coding
+15 more
Software Engineering Systems Integration Policy as Code Scripting Snowflake Software Security Kubernetes Azure AKS Data Management Terraform Devsecops Security Orchestration, Automation & Response Static Application Security Testing Databricks Dynamic Application Security Testing

Job description

Do you have a background in Application Security, DevSecOps or Product Security, with hands-on experience embedding application security into the SDLC? If so, this could be an opportunity worth considering.Join a well-established health research organisation and charity supporting large-scale medical research.

You will work closely with engineering, architecture and cloud teams to integrate security throughout the software development lifecycle.

Microsoft Azure and KQL experience are essential, alongside relevant experience in CI/CD, Kubernetes, API security, security-as-code and security automation.

This is a hands-on application security role focused on secure design, application security testing and supporting development teams to build secure applications., * Working with engineering and architecture teams to promote secure development.

  • Implementing and maintaining application security testing solutions.
  • Integrating security controls into CI/CD pipelines.
  • Strengthening the security of GitHub Actions and similar CI/CD platforms.
  • Providing guidance on secure API design and externally accessible systems.
  • Supporting Azure cloud infrastructure, including Azure Kubernetes Service (AKS).
  • Developing security-as-code and policy-as-code.
  • Supporting the security of cloud-hosted data platforms.
  • Automating security processes through infrastructure-as-code and scripting.
  • Maintaining technical and security documentation.
  • Supporting development teams with security tooling and best practices.
  • Contributing to threat modelling and compliance activities.

Requirements

  • Hands-on experience embedding application security into the SDLC.
  • Experience with Microsoft Azure security controls and cloud security governance.
  • Experience with KQL.
  • Experience securing APIs, internet-facing services, Kubernetes, preferably AKS, and containerised environments.
  • Experience with SAST, DAST, IAST and SCA.
  • Knowledge of security automation, security-/policy-as-code and secure engineering practices.
  • Familiarity with GitHub and GitHub Actions.
  • Experience with Terraform and Python.
  • Understanding of cloud security governance.Experience with threat modelling in software engineering contexts.
  • Knowledge of ISO 27001 and its relevance to secure engineering.
  • Exposure to Agile working environments and DevSecOps practices
  • Ideally experience securing data platforms such as Databricks, Dagster or Snowflake
  • Eligible to work in the UK.

Benefits & conditions

This is a full-time permanent role predominantly remote / hybrid in London offerings benefits and a salary of £80,000 which can be negotiable for right candidate., * £80,000 DOE, negotiable

  • Predominantly remote / hybrid working
  • London office
  • Full-time permanent position
  • Excellent benefits package

About the company

It is important you are aware of your individual rights and the provisions the company has put in place to protect your data.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on find.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

2:19 min

Introduction to Apache Airflow for advanced orchestration

Alan Mazankiewicz · LIVE

1:33 min

Integrating internal APIs and maintaining data sovereignty

Mahran Meißner Mahran Meißner · World Congress 2026 Europe

52 sec

Defining application, pipeline, and security operations roles

Aarno Aukia · LIVE

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

Videos

See all

Related articles

See all