Senior Cyber Security Analyst (OWASP / SAST /DAST ) in London

Senior Cyber Security Analyst (OWASP / SAST /DAST ) in London

London Full-Time 70000 - 90000 £ / year (est.) No working from home possible
Job Search Place Limited

At a Glance

  • Tasks: Join a top security team to protect enterprise platforms and embed security in app design.
  • Company: Leading banking client focused on application security and secure architecture.
  • Benefits: Flexible rate, dynamic work environment, and opportunities for professional growth.
  • Other info: Collaborate with engineers and architects in a highly technical environment.
  • Why this job: Make a real impact on security practices in modern applications and influence secure design.
  • Qualifications: 7-12+ years in cyber security with a focus on application security and DevSecOps.

The predicted salary is between 70000 - 90000 £ per year.

We are looking for a Cyber Security Analyst specialising in Application Security and Secure Architecture to join a high-performing security team responsible for protecting large-scale enterprise platforms. This role focuses on embedding security into application design and development, performing security risk assessments, and ensuring that modern applications and platforms are built following secure-by-design principles. You will work closely with software engineers, architects, DevOps teams and security engineers to ensure security is integrated throughout the technology lifecycle.

Key Responsibilities

  • Application Security & Secure SDLC – Perform application security assessments across modern enterprise platforms, review application architecture and ensure alignment with secure-by-design principles, embed security into the software development lifecycle (SDLC), support development teams in implementing secure coding practices aligned with OWASP guidelines.
  • Security Testing & DevSecOps – Define and review security testing activities including SAST, DAST and software composition analysis (SCA), work with engineering teams to integrate security scanning into CI/CD pipelines, analyse vulnerability scan results and support remediation of application security issues.
  • Threat Modelling & Security Risk Assessments – Conduct threat modelling exercises using frameworks such as STRIDE or MITRE ATT&CK, identify potential security threats, vulnerabilities and attack scenarios within applications and supporting infrastructure, perform structured security risk assessments and provide remediation recommendations.
  • Security Architecture & Secure Design – Review application and platform architectures to ensure appropriate security controls are implemented, translate high-level security policies into technical security requirements for development teams, work with architects to ensure applications are built following secure architecture patterns.
  • Security Advisory – Provide security expertise to engineering teams, project managers and technology leaders, support security decision-making during application design and implementation, contribute to security best practices, standards and guidelines.

Key Technical Skills

  • Strong experience in application security and secure software development including Secure Software Development Lifecycle (SSDLC) OWASP Top 10 and secure coding practices
  • Application security testing (SAST / DAST / SCA)
  • Threat modelling methodologies (STRIDE, MITRE ATT&CK)
  • Vulnerability management and remediation
  • Secure architecture and design reviews
  • DevSecOps and CI/CD security integration
  • API security and modern application architectures

Experience with Tools

  • SAST / DAST platforms
  • Code scanning tools
  • CI/CD pipelines (GitHub, GitLab, Jenkins etc.)
  • Container security platforms
  • Cloud security tooling

Technology Environment

  • Cloud platforms (AWS, Azure or GCP)
  • Containerised platforms (Docker / Kubernetes)
  • Microservices architectures
  • REST APIs and modern application frameworks
  • Identity and access management solutions

Ideal Candidate Background

  • 7-12+ years experience in cyber security, strong focus on application security, experience working closely with software engineering teams, experience performing security architecture reviews, experience in DevSecOps environments, strong communication skills and ability to explain security risks clearly.

Certifications (Optional)

  • Relevant certifications may include: CISSP, OSCP, CSSLP, GIAC, Security+ or similar.

What Makes This Role Interesting

You will work in a highly technical security environment, collaborating directly with engineers and architects to secure modern platforms at scale. This role offers the opportunity to influence secure architecture, application security practices and DevSecOps adoption across complex enterprise systems.

Senior Cyber Security Analyst (OWASP / SAST /DAST ) in London employer: Job Search Place Limited

As a Senior Cyber Security Analyst at our esteemed banking client, you will be part of a dynamic and innovative team dedicated to embedding security into application design and development. Our London, Paris, Brussels, and Amsterdam locations offer a collaborative work culture that prioritises employee growth through continuous learning and exposure to cutting-edge technologies. With flexible rates and a commitment to secure-by-design principles, we provide an environment where your expertise in application security can thrive, making a meaningful impact on enterprise platforms.

Job Search Place Limited

Contact Details:

Job Search Place Limited Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior Cyber Security Analyst (OWASP / SAST /DAST ) in London

Tip Number 1

Network like a pro! Attend industry meetups, webinars, and conferences related to cyber security. It's a great way to meet potential employers and get your name out there. Plus, you might just learn something new that could give you an edge in interviews!

Tip Number 2

Show off your skills! Create a portfolio showcasing your work in application security, threat modelling, and secure design. This can include case studies, projects, or even contributions to open-source tools. It’s a fantastic way to demonstrate your expertise beyond just a CV.

Tip Number 3

Prepare for those interviews! Research common interview questions for cyber security roles, especially around OWASP, SAST, and DAST. Practise your answers and be ready to discuss real-world scenarios where you've applied your knowledge. Confidence is key!

Tip Number 4

Don’t forget to apply through our website! We’ve got loads of opportunities that might just be the perfect fit for you. Plus, applying directly can sometimes give you a better chance of getting noticed by hiring managers.

We think you need these skills to ace Senior Cyber Security Analyst (OWASP / SAST /DAST ) in London

Application Security
Secure Software Development Lifecycle (SSDLC)
OWASP Top 10
Secure Coding Practices
SAST
DAST
Software Composition Analysis (SCA)

Some tips for your application 🫡

Tailor Your CV:Make sure your CV highlights your experience in application security and secure software development. Use keywords from the job description, like OWASP, SAST, and DAST, to show we’re on the same page.

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Share specific examples of how you've embedded security into the SDLC or conducted threat modelling. Let us see your passion for cyber security!

Showcase Your Technical Skills:Don’t forget to mention your experience with tools like CI/CD pipelines and cloud platforms. We want to know how you’ve used these in real-world scenarios to enhance application security.

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you don’t miss out on any important updates!

How to prepare for a job interview at Job Search Place Limited

Know Your OWASP Inside Out

Make sure you’re well-versed in the OWASP Top 10 vulnerabilities. Be ready to discuss how these apply to application security and share examples of how you've mitigated these risks in past projects.

Showcase Your Threat Modelling Skills

Prepare to talk about your experience with threat modelling frameworks like STRIDE or MITRE ATT&CK. Bring specific examples of how you've identified threats and vulnerabilities in previous roles, and be ready to suggest remediation strategies.

Demonstrate Your DevSecOps Knowledge

Familiarise yourself with integrating security into CI/CD pipelines. Be prepared to discuss tools you've used for SAST, DAST, and vulnerability management, and how you’ve collaborated with engineering teams to embed security practices.

Communicate Clearly About Security Risks

Practice explaining complex security concepts in simple terms. You’ll need to demonstrate your ability to communicate effectively with both technical and non-technical stakeholders, so think of examples where you’ve successfully done this.