DevSecOps Engineer in London

DevSecOps Engineer in London

London Full-Time 70000 - 90000 £ / year (est.) No working from home possible
Muf

At a Glance

  • Tasks: Enhance application security and collaborate with IT teams to identify risks and implement controls.
  • Company: MUFG Investor Services, a leading financial institution with a global presence.
  • Benefits: Competitive salary, diverse work environment, and opportunities for professional growth.
  • Other info: Dynamic role with excellent career advancement opportunities in a trusted financial institution.
  • Why this job: Join a proactive team and make a real impact on application security in finance.
  • Qualifications: Experience in application security and software development, with knowledge of DAST/SAST tools.

The predicted salary is between 70000 - 90000 £ per year.

MUFG Investor Services is a trusted partner to many of the world’s largest public and private funds, providing asset servicing and operational solutions built for alternatives.

With over $1 trillion in client assets under administration, we offer fund administration, banking, payments, fund financing, foreign exchange overlay, corporate and regulatory services, custody, business consulting, and more.

Operating from 17 locations worldwide, we help clients mitigate risk, enhance efficiency, and navigate the operational complexities of today’s investment management landscape.

As a division of Mitsubishi UFJ Financial Group (MUFG), one of the world’s largest financial institutions with approximately $3 trillion in assets, we combine deep expertise with the strength and stability of a leading financial institution.

Job Description

We are seeking a proactive and collaborative Application Security Engineer who speaks the language of developers, thrives in the purple team space and is an automation advocate.

The successful candidate will work closely with engineering & IT teams to enhance the security of our applications, APIs, and infrastructure by implementing preventative controls and identifying risks through security testing.

You Will

  • Act as a security champion to foster the secure by design approach across the business.
  • Support the identification and analysis of web application security vulnerabilities across the business to reduce risk.
  • Oversee daily management of application security platforms to maintain comprehensive coverage, ensure compliance and remediation of findings.
  • Conduct threat modelling and review application architectures to identify potential risks early in the SDLC.
  • Implement application security controls and proactive measures to prevent security incidents.
  • Implement and manage SAST/SCA tooling across our application repositories to identify source code risks.
  • Scale automated DAST solutions across our applications to maximize testing coverage and provide visibility into runtime security posture.
  • Provide security guidance and remediation advice to engineers where applicable.
  • Carry out penetration testing on internally developed applications to identify security defects.
  • Review and assess the security of third‑party vendor applications through configuration and hardening reviews.
  • Validate remediation of security issues by the development team and 3rd parties.
  • Coordinate and arrange external penetration testing assessments to independently evaluate the security of our applications.
  • Build and maintain effective collaboration with development and IT teams.

Qualifications

You Have

Experienced in application security focusing on red, blue or purple team activities.

Experienced in software development or experience contributing to open‑source projects.

Experienced with DAST tools such as Burp Suite, OWASP ZAP or similar.

Experience with SAST/SCA tools such as Snyk, Veracode, Checkmarx or similar.

  • Well‑versed in analysis of open source and third‑party library vulnerabilities.
  • Well‑rounded knowledge of the Software Development Life Cycle (SDLC) and agile methodologies.
  • Hold a strong understanding and experience testing of both REST and Graph QL APIs.
  • Demonstrated experience with development tools including Git Lab/Git Hub, Datadog, Jira, Docker, and various IDEs.
  • Previously worked very closely with development and Dev Ops teams to resolve security issues.
  • Have performed security‑focused code reviews to identify code‑level issues.
  • Experience in creating custom security tooling or scripts.
  • Preferred
  • Experience in the financial sector or another heavily audited industry.
  • Experience with cloud services, particularly AWS services like WAF, Cognito etc.
  • Experience working with Infrastructure as Code, Kubernetes and Containers.
  • Experience with auth mechanisms like Open ID Connect, OAuth and identity providers.
  • Experience in creating custom CI/CD pipeline jobs to carry out security related reviews or scans.

We are an equal opportunity employer.

#J-18808-Ljbffr

DevSecOps Engineer in London employer: Muf

MUFG Investor Services is an exceptional employer, offering a dynamic work environment where innovation and collaboration thrive. With a strong commitment to employee growth, we provide extensive training opportunities and encourage a secure-by-design approach, ensuring that our team members are at the forefront of application security in the financial sector. Located in a global financial hub, employees benefit from a diverse culture and the stability of being part of one of the world's largest financial institutions.

Muf

Contact Details:

Muf Recruitment Team

We think you need these skills to ace DevSecOps Engineer in London

Application Security
Threat Modelling
SAST/SCA Tools
DAST Tools
Penetration Testing
Security Vulnerability Analysis
Software Development Life Cycle (SDLC)