Senior Application Security Specialist in Slough

Senior Application Security Specialist in Slough

Slough Full-Time No working from home possible
Secure Source

The Application Security Specialist exists to embed application security expertise across Europe’s products and services, supporting the Secure Development Practice and enabling a consistent ‘shift-left’ approach. The role is accountable for advancing application security capability, leading security reviews on higher-risk systems, and ensuring secure development practices are adopted across engineering teams. The post holder will act as a technical authority on application security, helping reduce vulnerability risk and improve security outcomes across both internal IT systems and customer-facing solutions.

  • Strong knowledge of application security principles and practices
  • Experience with SAST, DAST and software composition analysis tools
  • Knowledge of secure coding practices across languages such as Java, C, C++
  • Experience with CI/CD pipelines and DevSecOps integration
  • Threat modelling techniques and tools
  • Understanding of OWASP Top 10 and common vulnerability classes
  • Experience with API security and web application security
  • Understanding of fuzz testing and advanced testing techniques
  • Familiarity with secure AI development considerations
  • Knowledge of secure development frameworks such as SSDF
  • Understanding of vulnerability management processes

Experience Required

Minimum

  • 3 to 5 years in application security, secure development or software engineering with a security focus
  • Hands-on experience conducting application security reviews
  • Experience implementing security in CI/CD processes
  • Experience working with development teams in an enterprise environment

Desirable

  • Experience building or contributing to a security CoE or capability model
  • Experience working in a multi-entity, multinational environment
  • Experience integrating security into large-scale development programmes
  • Experience supporting secure AI or data-centric applications

Minimum Qualifications Required

Minimum

  • Degree or equivalent professional experience in one of the following:
  • computer science
  • software engineering
  • cyber security
  • information security or related technical discipline
  • Evidence of formal or structured learning in secure development or application security (for example through certifications, formal training or demonstrable experience).

Desirable

  • Recognised application security or secure development certification, such as:
  • CSSLP (Certified Secure Software Lifecycle Professional)
  • GIAC Web Application Penetration Tester (GWAPT) or GWEB
  • Offensive Security certifications (e.g. OSCP) where relevant to application testing
  • Cloud security certifications relevant to application hosting environments:
  • AWS Security Specialty
  • Microsoft Azure Security Engineer Associate
  • Google Professional Cloud Security Engineer
  • DevSecOps or CI/CD related certifications or formal training
  • ISO 27001 Lead Implementer or Lead Auditor, or demonstrable understanding of ISO control environments
  • Familiarity with NIST frameworks, particularly NIST CSF and NIST SSDF, demonstrated through training or experience
  • Relevant vendor certifications linked to SAST, DAST, SCA or pipeline tooling where used in the organisation
  • Evidence of continuous professional development in secure coding, software assurance or emerging technologies such as AI security

Minimum Skills Required

Minimum

  • Strong software engineering foundation:
  • ability to read and understand code across at least one major language (Java, C, C++, C#, Python or similar)
  • understanding of common development frameworks and application architectures
  • Practical application security capability:
  • hands-on experience identifying and explaining common vulnerabilities
  • ability to guide remediation in a way developers can implement
  • Secure development lifecycle knowledge:
  • understanding of how to embed security into design, build, test and deployment stages
  • familiarity with shift-left practices and developer workflows
  • Threat modelling capability:
  • ability to identify threats, abuse cases and attack surfaces
  • experience applying structured approaches such as STRIDE or similar
  • CI/CD and DevOps familiarity:
  • understanding of pipelines, build processes and release workflows
  • capability to integrate or advise on automated security testing within pipelines
  • Analytical and diagnostic capability:
  • ability to interpret scan results and distinguish false positives from real risk
  • ability to identify systemicissues rather than isolated defects
  • Communication and influence:
  • ability to translate security issues into actionable developer guidance
  • confidence in engaging engineers, architects and product owners
  • Risk awareness:
  • ability to link technical vulnerabilities to business risk and prioritisation

Desirable

  • Advanced application security techniques:
  • experience with fuzz testing, advanced dynamic testing or manual code review
  • experience testing APIs, microservices and distributed systems
  • DevSecOps implementation:
  • experience designing or implementing security controls within CI/CD pipelines
  • hands-on experience integrating SAST, DAST, SCA and secrets scanning tools
  • Secure architecture understanding:
  • familiarity with secure design patterns and common failure modes in modern architectures (cloud-native, microservices, serverless)
  • Secure AI and data-driven systems awareness:
  • understanding of risks associated with AI models, data pipelines and prompt or model manipulation
  • Training and enablement capability:
  • ability to design or deliver developer-focused training or workshops
  • ability to simplify complex security concepts without diluting technical accuracy
  • Broader security framework awareness:
  • working knowledge of OWASP SAMM, ASVS or similar maturity models
  • familiarity with threat intelligence inputs and how they influence application risk
  • Tooling depth:
  • experience selecting, tuning or optimising security tools for development environments
  • understanding of strengths and limitations of common tooling categories
  • Multi-environment experience:
  • exposure to both internal enterprise IT systems and externally facing customer solutions
  • Ability to operate in federated organisations:
  • comfort working across multiple teams, geographies and delivery models with varying levels of maturity
Secure Source

Contact Details:

Secure Source Recruitment Team