Application Security Consultant in London

Application Security Consultant in London

London Full-Time 56700 - 69300 £ / year (est.) Home office (partial)
Ricoh

At a Glance

  • Tasks: Lead application security reviews and guide teams on secure development practices.
  • Company: Ricoh, a global leader in digital services with a people-first culture.
  • Benefits: Flexible working, career development, and opportunities to make a positive impact.
  • Other info: Be part of a diverse community committed to innovation and sustainability.
  • Why this job: Join a team that values your voice and supports your growth in cybersecurity.
  • Qualifications: Experience in application security and strong coding skills in major programming languages.

The predicted salary is between 56700 - 69300 £ per year.

About Ricoh: A global leader in digital services, recognised for innovation, sustainability and a people-first culture. We feature in the Gartner Magic Quadrant, are listed in the Global 100 Most Sustainable Companies, and have been named one of Forbes’ World’s Best Employers 2025. At Ricoh, we believe people do their best work when they feel valued and supported. We create inclusive workplaces where you can grow, contribute, and make a positive impact while helping to build a more sustainable future.

Our purpose is centred on understanding and improving how people work. By focusing on real working experiences, we support individuals to develop their skills, realise their potential and do work that feels meaningful.

We're looking for an Application Security Consultant to join our Cyber, Risk & Security team and play a key role in strengthening application security across Ricoh Europe. This is an opportunity to work at the intersection of software engineering, cybersecurity and risk, helping our teams adopt a genuine shift-left approach and making security part of the development lifecycle from design through to deployment.

What you will be doing:

  • Lead application security reviews for high-risk products and services.
  • Conduct and oversee SAST, DAST, API security, fuzz testing and architecture-level assessments.
  • Assess applications against the OWASP Top 10 and other relevant security standards.
  • Identify vulnerabilities, understand their root causes and translate findings into practical remediation plans.
  • Provide secure design and coding guidance throughout the development lifecycle.
  • Help establish and evolve a pan-European Application Security capability within our Secure Development Centre of Excellence.
  • Develop and promote consistent application security methodologies, standards and best practices.
  • Support secure coding standards across technologies including Java, C, C++ and other relevant languages.
  • Integrate security controls and automated testing into CI/CD pipelines, including SAST, DAST and SCA.
  • Support threat modelling and vulnerability management across products and services.
  • Work closely with developers, architects, DevOps teams and product owners to embed security into their everyday workflows.
  • Deliver security awareness sessions, secure coding workshops and practical training for development teams.
  • Help shape our approach to secure AI development, including risks around AI models, data handling and misuse.
  • Monitor emerging application security threats and recommend improvements to our processes, tooling and development practices.

This is more than finding vulnerabilities. We're looking for someone who can go beyond identifying a security issue and explain why it matters, how it happened and what we can do differently next time. You'll need to be comfortable challenging established practices while building strong relationships with engineering teams. Your ability to translate complex security concepts into practical, developer-friendly guidance will be just as important as your technical expertise.

You will ideally have:

  • Extensive experience in application security, secure development or software engineering with a security focus.
  • Hands-on experience conducting application security reviews.
  • Strong knowledge of application security principles and common vulnerability classes.
  • Experience with SAST, DAST and Software Composition Analysis (SCA) tools.
  • Experience implementing security within CI/CD and DevSecOps environments.
  • The ability to read and understand code in at least one major language such as Java, C, C++, C#, Python or similar.
  • Knowledge of secure software development lifecycles and shift-left security practices.
  • Experience with threat modelling, such as STRIDE or similar approaches.
  • Understanding of application, API and web security.
  • Experience interpreting security findings, identifying false positives and prioritising genuine risk.
  • The ability to communicate technical vulnerabilities clearly and turn them into actionable recommendations.
  • Strong stakeholder management skills, with confidence working with engineers, architects and product owners.
  • An understanding of how technical vulnerabilities translate into business, regulatory, financial and reputational risk.

Desired:

  • Experience with fuzz testing, advanced dynamic testing or manual code review.
  • Experience securing APIs, microservices or distributed systems.
  • Experience integrating SAST, DAST, SCA or secrets scanning into CI/CD pipelines.
  • Knowledge of secure architecture patterns across cloud-native, microservices or serverless environments.
  • Aware of AI security, including model, data and prompt/model manipulation risks.
  • Experience delivering developer-focused security training or workshops.
  • Knowledge of frameworks such as OWASP SAMM, ASVS, NIST CSF or NIST SSDF.
  • Relevant application security, cloud security or offensive security certifications.
  • Experience working across multiple teams, countries or business entities.

In return for your commitment, you can expect:

  • A supportive and fulfilling work environment.
  • Access to learning pathways, mentoring and career opportunities across functions and countries.
  • Opportunities to make a difference through volunteering, sustainability initiatives and community programmes.
  • Fair rewards, flexible working, wellbeing resources and real recognition.

We are an equal opportunities employer. We believe that diverse perspectives make us stronger, and we welcome applications from people of all backgrounds, identities, and experiences. Our hiring decisions are based on skills, experience and potential, and we are committed to creating a fair and inclusive recruitment process.

Ready to love what you do? Apply now and help us shape what comes next.

Application Security Consultant in London employer: Ricoh

Ricoh is an exceptional employer that prioritises a people-first culture, fostering an inclusive environment where employees can thrive and make a meaningful impact. With a strong commitment to sustainability and innovation, Ricoh offers ample opportunities for personal and professional growth, ensuring that every team member feels valued and supported in their journey. Join us in Ireland, where your ideas are welcomed, and you can contribute to shaping a better future while enjoying a fulfilling career.

Ricoh

Contact Details:

Ricoh Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Application Security Consultant in London

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Ricoh, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Ricoh

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Ricoh. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Application Security Consultant in London

Application Security
Secure Development
SAST
DAST
API Security
Fuzz Testing
Threat Modelling

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Ricoh insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Ricoh that you’re committed to staying ahead in the game.

How to prepare for a job interview at Ricoh

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Ricoh to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Ricoh.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.