At a Glance
- Tasks: Enhance application security through testing, analysis, and collaboration with engineering teams.
- Company: Join a leading tech firm focused on secure development practices.
- Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
- Other info: Be part of a collaborative team with excellent career advancement opportunities.
- Why this job: Make a real impact by securing applications and driving innovation in a dynamic environment.
- Qualifications: Experience in application security and familiarity with coding languages like C#, JavaScript, or Python.
The predicted salary is between 36000 - 60000 ÂŁ per year.
Key Responsibilities
- Support and enhance the organisation's application security testing programme, leveraging approved enterprise tools for SAST, SCA, DAST, API security assessment, and penetration testing activities.
- Conduct manual analysis and security review activities across web, API, and internal applications to validate automated findings and uncover additional weaknesses.
- Triage, verify, and risk‑rank vulnerabilities, partnering with engineering and application teams to ensure findings are accurately understood and remediation actions are practical and prioritised.
- Monitor and drive remediation progress, tracking closure of vulnerabilities and supporting engineering teams with root‑cause analysis to reduce repeat issues.
- Contribute to secure development practices, helping to maintain secure coding standards, patterns, and reusable security controls or guardrails.
- Operate and optimise AppSec tooling within CI/CD workflows, supporting the organisation's DevSecOps journey and enabling early, automated detection of security issues.
- Provide hands‑on guidance to developers, helping teams understand vulnerabilities, adopt secure patterns, and deliver applications that meet required security standards.
- Maintain comprehensive application security metrics, dashboards, and reports, ensuring technical and non‑technical stakeholders have clear visibility of risk, progress, and governance alignment.
Performance Objectives
- Effectively run the application security toolset (SAST, SCA, DAST, API testing) within established SDLC and CI/CD processes, ensuring vulnerabilities are accurately identified, triaged, and communicated to engineering teams.
- Strengthen collaboration with development teams, providing high‑quality remediation guidance and driving a measurable reduction in recurring application security weaknesses.
- Deliver clear, actionable AppSec reporting, maintaining dashboards and metrics that support governance, risk visibility, and informed decision‑making for technical and leadership stakeholders.
Skills and Experience Specification
Essential
- Hands‑on experience in Application Security, DevSecOps, or security engineering, preferably within a large or complex technical environment.
- Practical experience deploying, tuning, and operating SAST, SCA, DAST, and API security tools as part of a structured AppSec programme.
- Strong understanding of secure coding fundamentals and common software weaknesses, including the OWASP Top 10 and MITRE CWE Top 25.
- Demonstrated experience triaging, validating, and prioritising vulnerabilities, working directly with software engineers to support remediation.
- Ability to read and interpret code in at least one common programming language (e.g., C#, JavaScript, Python).
- Knowledge of CI/CD pipelines and the integration of security tooling into developer workflows (e.g., GitHub Actions, Azure DevOps).
- Strong understanding of authentication and authorisation, including OAuth, OIDC, SSO, and role‑based access control principles.
- Experience producing and maintaining security metrics, dashboards, or reporting to support governance and visibility.
Desirable
- Experience automating or contributing to DevSecOps tooling and pipelines, including scripting (e.g., Python, Bash).
- Knowledge of software supply chain security, dependency management practices, and artefact repositories (e.g., Artifactory).
- Exposure to cloud‑native and containerised environments, including AWS/Azure, Kubernetes, microservices, and API‑centric architectures.
Application Security Analyst employer: Hays Technology
Contact Detail:
Hays Technology Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Application Security Analyst
✨Tip Number 1
Network like a pro! Reach out to folks in the industry on LinkedIn or at local meetups. A friendly chat can lead to opportunities that aren’t even advertised yet.
✨Tip Number 2
Show off your skills! Create a portfolio showcasing your application security projects or contributions. This gives potential employers a taste of what you can do and sets you apart from the crowd.
✨Tip Number 3
Prepare for interviews by brushing up on common application security scenarios. Be ready to discuss how you’ve tackled vulnerabilities in the past and how you’d approach challenges in this role.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love hearing from passionate candidates like you!
We think you need these skills to ace Application Security Analyst
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience in application security and the specific tools mentioned in the job description. We want to see how your skills align with our needs!
Showcase Your Technical Skills: Don’t hold back on detailing your hands-on experience with SAST, DAST, and other security tools. We love seeing practical examples of how you've triaged vulnerabilities or improved security practices in past roles.
Be Clear and Concise: When writing your application, keep it straightforward and to the point. Use bullet points where possible to make it easy for us to see your key achievements and skills at a glance.
Apply Through Our Website: We encourage you to submit your application through our website. It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it’s super easy!
How to prepare for a job interview at Hays Technology
✨Know Your Tools Inside Out
Make sure you’re familiar with the application security tools mentioned in the job description, like SAST, DAST, and API security assessment tools. Be ready to discuss your hands-on experience with these tools and how you've used them in past roles.
✨Understand Secure Coding Practices
Brush up on secure coding fundamentals and the OWASP Top 10 vulnerabilities. You might be asked to explain how you would address specific weaknesses, so having examples from your experience will really help you stand out.
✨Show Your Collaboration Skills
This role emphasises working closely with engineering teams. Prepare examples of how you’ve successfully collaborated with developers in the past, especially when it comes to triaging and remediating vulnerabilities.
✨Prepare for Technical Questions
Expect to dive deep into technical discussions, including reading and interpreting code. Brush up on at least one programming language relevant to the role, and be ready to demonstrate your understanding of authentication and authorisation principles.