At a Glance
- Tasks: Join a top security team to protect enterprise platforms and embed security in app design.
- Company: Leading banking client focused on innovative application security.
- Benefits: Flexible rate, remote work options, and a chance to influence security practices.
- Other info: Collaborate with engineers and architects in a dynamic, technical environment.
- Why this job: Make a real impact on secure architecture and modern application security.
- Qualifications: 7-12+ years in cyber security with a focus on application security.
The predicted salary is between 70000 - 90000 £ per year.
We are looking for a Cyber Security Analyst specialising in Application Security and Secure Architecture to join a high-performing security team responsible for protecting large-scale enterprise platforms. This role focuses on embedding security into application design and development, performing security risk assessments, and ensuring that modern applications and platforms are built following secure-by-design principles. You will work closely with software engineers, architects, DevOps teams and security engineers to ensure security is integrated throughout the technology lifecycle.
Key Responsibilities
- Application Security & Secure SDLC – Perform application security assessments across modern enterprise platforms, review application architecture and ensure alignment with secure-by-design principles, embed security into the software development lifecycle (SDLC), support development teams in implementing secure coding practices aligned with OWASP guidelines.
- Security Testing & DevSecOps – Define and review security testing activities including SAST, DAST and software composition analysis (SCA), work with engineering teams to integrate security scanning into CI/CD pipelines, analyse vulnerability scan results and support remediation of application security issues.
- Threat Modelling & Security Risk Assessments – Conduct threat modelling exercises using frameworks such as STRIDE or MITRE ATT&CK, identify potential security threats, vulnerabilities and attack scenarios within applications and supporting infrastructure, perform structured security risk assessments and provide remediation recommendations.
- Security Architecture & Secure Design – Review application and platform architectures to ensure appropriate security controls are implemented, translate high-level security policies into technical security requirements for development teams, work with architects to ensure applications are built following secure architecture patterns.
- Security Advisory – Provide security expertise to engineering teams, project managers and technology leaders, support security decision-making during application design and implementation, contribute to security best practices, standards and guidelines.
Key Technical Skills
- Strong experience in application security and secure software development including Secure Software Development Lifecycle (SSDLC)
- OWASP Top 10 and secure coding practices
- Application security testing (SAST / DAST / SCA)
- Threat modelling methodologies (STRIDE, MITRE ATT&CK)
- Vulnerability management and remediation
- Secure architecture and design reviews
- DevSecOps and CI/CD security integration
- API security and modern application architectures
Experience with Tools
- SAST / DAST platforms
- Code scanning tools
- CI/CD pipelines (GitHub, GitLab, Jenkins etc.)
- Container security platforms
- Cloud security tooling
Technology Environment
- Cloud platforms (AWS, Azure or GCP)
- Containerised platforms (Docker / Kubernetes)
- Microservices architectures
- REST APIs and modern application frameworks
- Identity and access management solutions
Ideal Candidate Background
- 7–12+ years experience in cyber security, strong focus on application security, experience working closely with software engineering teams, experience performing security architecture reviews, experience in DevSecOps environments, strong communication skills and ability to explain security risks clearly.
Certifications (Optional)
- Relevant certifications may include: CISSP, OSCP, CSSLP, GIAC, Security+ or similar.
What Makes This Role Interesting
You will work in a highly technical security environment, collaborating directly with engineers and architects to secure modern platforms at scale. This role offers the opportunity to influence secure architecture, application security practices and DevSecOps adoption across complex enterprise systems.
Senior Cyber Security Analyst (OWASP / SAST /DAST ) in London employer: Salt Digital Recruitment
As a Senior Cyber Security Analyst at our esteemed banking client, you will thrive in a dynamic and collaborative work culture that prioritises innovation and security excellence. With flexible working arrangements in vibrant cities like London, Paris, Brussels, and Amsterdam, we offer competitive benefits, continuous professional development opportunities, and the chance to make a significant impact on secure application design and architecture. Join us to be part of a high-performing team dedicated to embedding security into every aspect of technology.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Cyber Security Analyst (OWASP / SAST /DAST ) in London
✨Tip Number 1
Network like a pro! Attend industry meetups, webinars, and conferences related to cyber security. It's a great way to meet potential employers and get your name out there. Plus, you might just learn something new that could give you an edge!
✨Tip Number 2
Show off your skills! Create a portfolio showcasing your work in application security, threat modelling, and secure design. This can be a game-changer during interviews, as it gives you tangible proof of what you can do.
✨Tip Number 3
Prepare for those interviews! Research common interview questions for cyber security roles, especially around OWASP, SAST, and DAST. Practising your responses will help you feel more confident and ready to impress.
✨Tip Number 4
Don't forget to apply through our website! We often have exclusive job listings that you won't find elsewhere. Plus, applying directly shows your interest in being part of our community at StudySmarter.
We think you need these skills to ace Senior Cyber Security Analyst (OWASP / SAST /DAST ) in London
Some tips for your application 🫡
Tailor Your CV:Make sure your CV highlights your experience in application security and secure software development. We want to see how your skills align with the key responsibilities mentioned in the job description, so don’t hold back on showcasing your relevant projects!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you’re passionate about cyber security and how your background makes you a perfect fit for our team. We love seeing enthusiasm and a clear understanding of the role.
Showcase Your Technical Skills:Be sure to include any specific tools and methodologies you’ve worked with, like SAST, DAST, or threat modelling frameworks. We’re looking for candidates who can hit the ground running, so let us know what you bring to the table!
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows you’re keen on joining our team at StudySmarter!
How to prepare for a job interview at Salt Digital Recruitment
✨Know Your OWASP Inside Out
Make sure you’re well-versed in the OWASP Top 10 and secure coding practices. Be ready to discuss how these principles apply to real-world scenarios, especially in banking applications. This will show your depth of knowledge and practical application.
✨Demonstrate Your Threat Modelling Skills
Prepare to talk about your experience with threat modelling frameworks like STRIDE or MITRE ATT&CK. Bring examples of how you've identified vulnerabilities and proposed remediation strategies in past projects. This will highlight your analytical skills and proactive approach.
✨Showcase Your DevSecOps Experience
Be ready to discuss how you’ve integrated security into CI/CD pipelines. Mention specific tools you’ve used for SAST, DAST, and vulnerability management. This will demonstrate your hands-on experience and understanding of modern development practices.
✨Communicate Clearly About Security Risks
Practice explaining complex security concepts in simple terms. You’ll likely need to communicate with non-technical stakeholders, so being able to articulate risks and solutions clearly is crucial. Think of examples where you successfully communicated security issues to teams.