At a Glance
- Tasks: Join a top security team to protect enterprise platforms and embed security in app design.
- Company: Leading banking client focused on innovative application security.
- Benefits: Flexible rate, dynamic work environment, and opportunities for professional growth.
- Other info: Collaborate with engineers and architects in a highly technical environment.
- Why this job: Make a real impact on security practices in modern applications and influence secure architecture.
- Qualifications: 7-12+ years in cyber security with a focus on application security and DevSecOps.
The predicted salary is between 70000 - 90000 £ per year.
We are looking for a Cyber Security Analyst specialising in Application Security and Secure Architecture to join a high-performing security team responsible for protecting large-scale enterprise platforms. This role focuses on embedding security into application design and development, performing security risk assessments, and ensuring that modern applications and platforms are built following secure-by-design principles. You will work closely with software engineers, architects, DevOps teams and security engineers to ensure security is integrated throughout the technology lifecycle.
Key Responsibilities
- Application Security & Secure SDLC – Perform application security assessments across modern enterprise platforms, review application architecture and ensure alignment with secure-by-design principles, embed security into the software development lifecycle (SDLC), support development teams in implementing secure coding practices aligned with OWASP guidelines.
- Security Testing & DevSecOps – Define and review security testing activities including SAST, DAST and software composition analysis (SCA), work with engineering teams to integrate security scanning into CI/CD pipelines, analyse vulnerability scan results and support remediation of application security issues.
- Threat Modelling & Security Risk Assessments – Conduct threat modelling exercises using frameworks such as STRIDE or MITRE ATT&CK, identify potential security threats, vulnerabilities and attack scenarios within applications and supporting infrastructure, perform structured security risk assessments and provide remediation recommendations.
- Security Architecture & Secure Design – Review application and platform architectures to ensure appropriate security controls are implemented, translate high-level security policies into technical security requirements for development teams, work with architects to ensure applications are built following secure architecture patterns.
- Security Advisory – Provide security expertise to engineering teams, project managers and technology leaders, support security decision-making during application design and implementation, contribute to security best practices, standards and guidelines.
Key Technical Skills
- Strong experience in application security and secure software development including Secure Software Development Lifecycle (SSDLC)
- OWASP Top 10 and secure coding practices
- Application security testing (SAST / DAST / SCA)
- Threat modelling methodologies (STRIDE, MITRE ATT&CK)
- Vulnerability management and remediation
- Secure architecture and design reviews
- DevSecOps and CI/CD security integration
- API security and modern application architectures
Experience with Tools
- SAST / DAST platforms
- Code scanning tools
- CI/CD pipelines (GitHub, GitLab, Jenkins etc.)
- Container security platforms
- Cloud security tooling
Technology Environment
- Cloud platforms (AWS, Azure or GCP)
- Containerised platforms (Docker / Kubernetes)
- Microservices architectures
- REST APIs and modern application frameworks
- Identity and access management solutions
Ideal Candidate Background
- 7–12+ years experience in cyber security, strong focus on application security, experience working closely with software engineering teams, experience performing security architecture reviews, experience in DevSecOps environments, strong communication skills and ability to explain security risks clearly.
Certifications (Optional)
- Relevant certifications may include: CISSP, OSCP, CSSLP, GIAC, Security+ or similar.
What Makes This Role Interesting
You will work in a highly technical security environment, collaborating directly with engineers and architects to secure modern platforms at scale. This role offers the opportunity to influence secure architecture, application security practices and DevSecOps adoption across complex enterprise systems.
Senior Cyber Security Analyst (OWASP / SAST /DAST ) employer: Salt Digital Recruitment
As a Senior Cyber Security Analyst at our esteemed banking client, you will join a dynamic and innovative team dedicated to embedding security into application design and development. Our London, Paris, Brussels, and Amsterdam locations foster a collaborative work culture that prioritises employee growth through continuous learning and exposure to cutting-edge technologies. With flexible rates and a focus on secure-by-design principles, we offer a rewarding environment where your expertise in application security will directly impact the safety of large-scale enterprise platforms.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Cyber Security Analyst (OWASP / SAST /DAST )
✨Tip Number 1
Network like a pro! Attend industry meetups, webinars, or conferences related to cyber security. It's a great way to meet potential employers and get your name out there. Plus, you might just learn something new that could give you an edge!
✨Tip Number 2
Show off your skills! Create a portfolio showcasing your work in application security, threat modelling, or secure design. This can be a game-changer during interviews, as it gives you a chance to demonstrate your expertise beyond just words.
✨Tip Number 3
Prepare for those tricky interview questions! Brush up on your knowledge of OWASP guidelines, SAST/DAST tools, and secure SDLC practices. Being able to discuss these topics confidently will show employers you're the real deal.
✨Tip Number 4
Don't forget to apply through our website! We make it easy for you to find roles that match your skills and interests. Plus, it shows you're serious about joining our team and helps us keep track of your application.
We think you need these skills to ace Senior Cyber Security Analyst (OWASP / SAST /DAST )
Some tips for your application 🫡
Tailor Your CV:Make sure your CV highlights your experience in application security and secure software development. Use keywords from the job description, like OWASP, SAST, and DAST, to show we’re on the same page.
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Share specific examples of how you've embedded security into the SDLC or conducted threat modelling. Let us see your passion for cyber security!
Showcase Your Technical Skills:Don’t forget to mention your experience with tools like CI/CD pipelines and cloud platforms. We want to know how you’ve used these in real-world scenarios to enhance application security.
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you don’t miss out on any important updates during the process!
How to prepare for a job interview at Salt Digital Recruitment
✨Know Your OWASP Inside Out
Make sure you’re well-versed in the OWASP Top 10 vulnerabilities. Be prepared to discuss how these apply to application security and share examples of how you've mitigated these risks in past projects.
✨Showcase Your Threat Modelling Skills
Familiarise yourself with threat modelling frameworks like STRIDE or MITRE ATT&CK. During the interview, be ready to walk through a threat modelling exercise you've conducted, highlighting your thought process and the outcomes.
✨Demonstrate Your DevSecOps Knowledge
Understand how security integrates into CI/CD pipelines. Be prepared to discuss specific tools you've used for SAST, DAST, and vulnerability management, and how you’ve collaborated with engineering teams to embed security practices.
✨Communicate Clearly About Security Risks
Practice explaining complex security concepts in simple terms. The ability to communicate risks effectively to non-technical stakeholders is crucial, so think of examples where you’ve successfully done this in your previous roles.