Application Security Analyst in City of London
Application Security Analyst

Application Security Analyst in City of London

City of London Full-Time 36000 - 60000 £ / year (est.) No home office possible
H

At a Glance

  • Tasks: Enhance application security through testing, analysis, and collaboration with engineering teams.
  • Company: Leading tech firm focused on secure development practices.
  • Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
  • Why this job: Join a dynamic team to make a real impact on application security.
  • Qualifications: Experience in application security and familiarity with coding languages.
  • Other info: Exciting environment with strong focus on innovation and career advancement.

The predicted salary is between 36000 - 60000 £ per year.

London - UK Only Please

Key Responsibilities

  • Support and enhance the organisation's application security testing programme, leveraging approved enterprise tools for SAST, SCA, DAST, API security assessment, and penetration testing activities.
  • Conduct manual analysis and security review activities across web, API, and internal applications to validate automated findings and uncover additional weaknesses.
  • Triage, verify, and risk-rank vulnerabilities, partnering with engineering and application teams to ensure findings are accurately understood and remediation actions are practical and prioritised.
  • Monitor and drive remediation progress, tracking closure of vulnerabilities and supporting engineering teams with root-cause analysis to reduce repeat issues.
  • Contribute to secure development practices, helping to maintain secure coding standards, patterns, and reusable security controls or guardrails.
  • Operate and optimise AppSec tooling within CI/CD workflows, supporting the organisation's DevSecOps journey and enabling early, automated detection of security issues.
  • Provide hands-on guidance to developers, helping teams understand vulnerabilities, adopt secure patterns, and deliver applications that meet required security standards.
  • Maintain comprehensive application security metrics, dashboards, and reports, ensuring technical and non-technical stakeholders have clear visibility of risk, progress, and governance alignment.

Performance Objectives

  • Effectively run the application security toolset (SAST, SCA, DAST, API testing) within established SDLC and CI/CD processes, ensuring vulnerabilities are accurately identified, triaged, and communicated to engineering teams.
  • Strengthen collaboration with development teams, providing high-quality remediation guidance and driving a measurable reduction in recurring application security weaknesses.
  • Deliver clear, actionable AppSec reporting, maintaining dashboards and metrics that support governance, risk visibility, and informed decision-making for technical and leadership stakeholders.

Skills and Experience Specification

Essential

  • Hands-on experience in Application Security, DevSecOps, or security engineering, preferably within a large or complex technical environment.
  • Practical experience deploying, tuning, and operating SAST, SCA, DAST, and API security tools as part of a structured AppSec programme.
  • Strong understanding of secure coding fundamentals and common software weaknesses, including the OWASP Top 10 and MITRE CWE Top 25.
  • Demonstrated experience triaging, validating, and prioritising vulnerabilities, working directly with software engineers to support remediation.
  • Ability to read and interpret code in at least one common programming language (e.g., C#, JavaScript, Python).
  • Knowledge of CI/CD pipelines and the integration of security tooling into developer workflows (e.g., GitHub Actions, Azure DevOps).
  • Strong understanding of authentication and authorisation, including OAuth, OIDC, SSO, and role-based access control principles.
  • Experience producing and maintaining security metrics, dashboards, or reporting to support governance and visibility.

Desirable

  • Experience automating or contributing to DevSecOps tooling and pipelines, including scripting (e.g., Python, Bash).
  • Knowledge of software supply chain security, dependency management practices, and artefact repositories (e.g., Artifactory).
  • Exposure to cloud-native and containerised environments, including AWS/Azure, Kubernetes, microservices, and API-centric architectures.

Application Security Analyst in City of London employer: Hays Technology

As an Application Security Analyst in London, you will join a forward-thinking organisation that prioritises innovation and security. With a strong commitment to employee development, we offer extensive training opportunities and a collaborative work culture that encourages knowledge sharing and professional growth. Our focus on secure coding practices and integration of cutting-edge security tools within CI/CD workflows ensures that you will be at the forefront of application security, making a meaningful impact in a dynamic environment.
H

Contact Detail:

Hays Technology Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Application Security Analyst in City of London

✨Tip Number 1

Network like a pro! Reach out to folks in the industry on LinkedIn or at local meetups. A friendly chat can sometimes lead to job opportunities that aren't even advertised.

✨Tip Number 2

Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those related to application security. This gives potential employers a taste of what you can do.

✨Tip Number 3

Prepare for interviews by brushing up on common application security scenarios and tools. Practice explaining your thought process when tackling vulnerabilities – it shows your problem-solving skills!

✨Tip Number 4

Don't forget to apply through our website! We love seeing candidates who are genuinely interested in joining us. Plus, it makes tracking your application easier for both you and us.

We think you need these skills to ace Application Security Analyst in City of London

Application Security
DevSecOps
Security Engineering
SAST
SCA
DAST
API Security Assessment
Penetration Testing
Secure Coding Fundamentals
OWASP Top 10
MITRE CWE Top 25
Vulnerability Triage
CI/CD Pipelines
Authentication and Authorisation
Security Metrics Reporting

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the Application Security Analyst role. Highlight your hands-on experience with SAST, DAST, and other security tools. We want to see how your skills match our needs!

Showcase Your Projects: Include any relevant projects or experiences where you've triaged vulnerabilities or worked with development teams. This helps us understand your practical experience and how you can contribute to our AppSec programme.

Be Clear and Concise: When writing your cover letter, be clear and concise about why you're a great fit for the role. Use specific examples to demonstrate your understanding of secure coding practices and your ability to communicate with technical teams.

Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. It’s the easiest way for us to keep track of your application and ensure it reaches the right people!

How to prepare for a job interview at Hays Technology

✨Know Your Tools Inside Out

Make sure you’re familiar with the application security tools mentioned in the job description, like SAST, DAST, and API security assessment tools. Be ready to discuss your hands-on experience with these tools and how you've used them in past roles.

✨Understand Secure Coding Practices

Brush up on secure coding fundamentals and the OWASP Top 10 vulnerabilities. You might be asked to explain how you would address specific weaknesses, so having examples from your experience will really help you stand out.

✨Show Your Collaboration Skills

This role involves working closely with engineering teams, so be prepared to share examples of how you've successfully collaborated with developers in the past. Highlight any experiences where you provided remediation guidance or helped teams understand vulnerabilities.

✨Prepare for Technical Questions

Expect technical questions that may require you to read and interpret code. Brush up on at least one common programming language relevant to the role, and be ready to discuss how you would approach identifying and fixing vulnerabilities in code.

Application Security Analyst in City of London
Hays Technology
Location: City of London

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

H
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>