At a Glance
- Tasks: Secure applications by analysing code, supply chains, and threat modelling.
- Company: Join a leading global operator with a passion for excellence.
- Benefits: Enjoy hybrid working, eye care, flu vaccinations, and life assurance.
- Why this job: Make a real impact in application security while leveraging AI technology.
- Qualifications: Experience with security testing tools and knowledge of software development.
- Other info: Collaborative team environment with opportunities for mentorship and growth.
The predicted salary is between 36000 - 60000 Β£ per year.
As an Information Security Specialist, you will focus on securing the Company's applications through analysis of code, supply chains and threat modelling, ensuring the effectiveness of security measures.
The application security team deals with the security of closed sourced, open source and proprietary applications. It is our mission to ensure applications are developed and implemented in a secure manner, and potential risks are found and remediated efficiently through penetration testing.
You will work alongside our Software Development teams to ensure application-based vulnerabilities are understood and mitigated. It is important that you possess an understanding of Secure Development Lifecycles (SDL) and the assessment of code.
The role is part of the broader Information Security department, which is comprised of engineers and analysts from varying backgrounds. Collectively, the team utilises enterprise and bespoke tooling to identify and mitigate threats to the Business. We utilise AI to enhance our existing security processes and practices, embracing the advantages it brings. You will play a key role in our journey to leverage this powerful technology in strengthening our application security.
This role is eligible for inclusion in the Company's hybrid working from home policy.
Preferred Skills and Experience- Understanding of and demonstrable experience with automated, dynamic and static application security testing tools, as well as manual security testing to find vulnerabilities and logical issues.
- Knowledge and understanding of Open Web Application Security Project (OWASP) and its utilisation within threat modelling.
- Knowledge of software development and languages.
- Working knowledge of CI/CD pipelines and security tooling associated with them.
- Experience in conducting and reporting on web application penetration testing.
- Strong communication and documentation skills.
- Providing support to senior members of the team and mentoring junior members of the team.
- Taking an active role in the project process to ensure that information security aspects are considered up front and throughout the project lifecycle.
- Contributing to and continuously improving the Company's security testing methodologies, updating documentation where applicable.
- Performing manual and automated code reviews and escalating remediation where appropriate.
- Providing support to software development teams to ensure security is considered throughout the development lifecycle.
- Contributing to and continuously improving our supply chain assurance processes, identifying flaws and vulnerabilities.
- Performing risk assessments, threat modelling and design reviews to ensure effective security controls are in place.
- Identifying opportunities for converting manual tasks into automated processes.
- Eye care and Flu Vaccinations
- Life Assurance
Life at bet365: We are a unique global operator with passion and drive to be the best in the industry. Our values form the foundation of culture and shape the unique way that we work. People are our superpower and we support you to be the best you can be.
Information Security Specialist employer: bet365 Group
Contact Detail:
bet365 Group Recruiting Team
StudySmarter Expert Advice π€«
We think this is how you could land Information Security Specialist
β¨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups or webinars, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can refer you directly.
β¨Tip Number 2
Show off your skills! Create a portfolio showcasing your work in application security, including any projects or contributions to open-source software. This gives potential employers a tangible look at what you can do.
β¨Tip Number 3
Prepare for interviews by brushing up on common security scenarios and challenges. Practice explaining your thought process when it comes to threat modelling and vulnerability assessments. Confidence is key!
β¨Tip Number 4
Donβt forget to apply through our website! Itβs the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are genuinely interested in joining our team.
We think you need these skills to ace Information Security Specialist
Some tips for your application π«‘
Tailor Your CV: Make sure your CV is tailored to the Information Security Specialist role. Highlight your experience with application security, threat modelling, and any relevant tools you've used. We want to see how your skills align with our mission!
Showcase Your Skills: In your cover letter, donβt just list your skillsβshow us how youβve applied them in real-world scenarios. Talk about your experience with secure development lifecycles and penetration testing. We love seeing practical examples!
Be Clear and Concise: When writing your application, keep it clear and to the point. Use straightforward language and avoid jargon unless it's relevant. We appreciate a well-structured application that gets straight to the heart of your qualifications.
Apply Through Our Website: Donβt forget to apply through our website! Itβs the best way for us to receive your application and ensures youβre considered for the role. Plus, it shows youβre keen on joining our team at StudySmarter!
How to prepare for a job interview at bet365 Group
β¨Know Your Security Tools
Familiarise yourself with automated, dynamic, and static application security testing tools. Be ready to discuss your experience with these tools and how you've used them to identify vulnerabilities in past projects.
β¨Understand the SDL
Brush up on Secure Development Lifecycles (SDL) and be prepared to explain how youβve applied this knowledge in your previous roles. Highlight any specific instances where you ensured security was integrated throughout the development process.
β¨Showcase Your Communication Skills
Since strong communication is key, think of examples where you've effectively communicated security risks to non-technical stakeholders. This will demonstrate your ability to bridge the gap between technical and non-technical teams.
β¨Be Ready for Scenario Questions
Expect scenario-based questions related to threat modelling and risk assessments. Prepare to walk through your thought process on how you would approach identifying and mitigating potential security threats in a given situation.