> Markdown version of [/jobs/ext/3562138-senior-application-security-engineer-devsecops-engineer](https://www.wearedevelopers.com/jobs/ext/3562138-senior-application-security-engineer-devsecops-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Application Security Engineer / DevSecOps Engineer - **Company:** Additional Resources - **Location:** London, UK - **Experience:** Expert - **Salary:** £80,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Agile Methodology, Airflow, Microsoft Azure, Cloud Computing Security, Encodings, Continuous Integration, Github, Python (Programming Language), Systems Development Life Cycle, Kusto Query Language, Secure Coding, Software Engineering, Systems Integration, Policy as Code, Scripting, Snowflake, Software Security, Kubernetes, Azure AKS, Data Management, Terraform, Devsecops, Security Orchestration, Automation & Response, Static Application Security Testing, Databricks, Dynamic Application Security Testing - **Published:** October 3, 2026 - **Apply:** https://find.jobs/jobs-near-me/apply/ats-redirect/?id=2999675644-2 ## About the Role * Hands-on experience embedding application security into the SDLC. * Experience with Microsoft Azure security controls and cloud security governance. * Experience with KQL. * Experience securing APIs, internet-facing services, Kubernetes, preferably AKS, and containerised environments. * Experience with SAST, DAST, IAST and SCA. * Knowledge of security automation, security-/policy-as-code and secure engineering practices. * Familiarity with GitHub and GitHub Actions. * Experience with Terraform and Python. * Understanding of cloud security governance.Experience with threat modelling in software engineering contexts. * Knowledge of ISO 27001 and its relevance to secure engineering. * Exposure to Agile working environments and DevSecOps practices * Ideally experience securing data platforms such as Databricks, Dagster or Snowflake * Eligible to work in the UK. ## Description Do you have a background in Application Security, DevSecOps or Product Security, with hands-on experience embedding application security into the SDLC? If so, this could be an opportunity worth considering.Join a well-established health research organisation and charity supporting large-scale medical research. You will work closely with engineering, architecture and cloud teams to integrate security throughout the software development lifecycle. Microsoft Azure and KQL experience are essential, alongside relevant experience in CI/CD, Kubernetes, API security, security-as-code and security automation. This is a hands-on application security role focused on secure design, application security testing and supporting development teams to build secure applications., * Working with engineering and architecture teams to promote secure development. * Implementing and maintaining application security testing solutions. * Integrating security controls into CI/CD pipelines. * Strengthening the security of GitHub Actions and similar CI/CD platforms. * Providing guidance on secure API design and externally accessible systems. * Supporting Azure cloud infrastructure, including Azure Kubernetes Service (AKS). * Developing security-as-code and policy-as-code. * Supporting the security of cloud-hosted data platforms. * Automating security processes through infrastructure-as-code and scripting. * Maintaining technical and security documentation. * Supporting development teams with security tooling and best practices. * Contributing to threat modelling and compliance activities. ## Related Videos - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Fully Orchestrating Databricks from Airflow](https://www.wearedevelopers.com/videos/336-fully-orchestrating-databricks-from-airflow) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [From Messy Queries to Scalable Systems - How Data Engineering actually works](https://www.wearedevelopers.com/videos/100203-from-messy-queries-to-scalable-systems-how-data-engineering-actually-works) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)