At a Glance
- Tasks: Join a dynamic team to enhance application security and develop innovative security tools.
- Company: Global investment manager with a commitment to client success and societal prosperity.
- Benefits: Hybrid work model, competitive salary, and opportunities for professional growth.
- Other info: Collaborative environment with a focus on continuous improvement and career advancement.
- Why this job: Make a real impact in cybersecurity while working with cutting-edge technologies.
- Qualifications: Degree in Computer Science/Cyber Security and experience in application development.
The predicted salary is between 63000 - 77000 £ per year.
- Application Security Engineer (Cyber) - Financial Services
- Contract - Inside I35
- London - Hybrid
- Who we're looking for
Our clients Cyber Security team is looking for a Cybersecurity engineer with expertise in Application Security domain, who will be responsible to define consistent Secure Software Development Lifecycle practices for all technology projects throughout the planning and delivery cycles that assure application security vulnerabilities are mitigated to tolerable levels.
The successful candidate will have very strong application security, web application development experience and team leadership skills to join a growing Information Security team and assist with the operation of the App Sec function.
About Us
Our client is a global investment manager.
They help institutions, intermediaries and individuals around the world invest money to meet their goals, fulfil their ambitions, and prepare for the future.
They have around 5,000 people on six continents, have been around for over 200 years but keep adapting as society and technology changes.
What doesn't change is the commitment to helping clients, and society, prosper.
What you'll do
In this position, you are a passionate and talented application security engineer with very deep understanding of OWASP, CWE 25, Data Protection, Access management, software vulnerabilities, best practices design and threat modelling skills, who can work in a dynamic environment.
You must be dedicated to able to work with developers in producing secure code in short time frames and be willing to go beyond the standard routine.
Your primary responsibilities includes
- Work as part of a team of software and security engineers to design/maintain and build best-in-class product security tools and services.
- Technical point of contact for product teams as it relates to automation, CI/CD, and Product Application Security Operations
- Using approved AI models and cyber harnesses to assess application code for business logic weaknesses, misconfiguration and vulnerabilities.
- Build tools and automation scripts that enable developers to easily consume security services delivered by Security Engineering and Automation team
- Responsible for security product QA and Testing
- Build strong relationships with product development teams
- Run software composition analysis (SCA) tools
- To understand and explain penetration testing findings to the software engineering teams helping them to triage the findings and explaining how to mitigate the risks
- To articulate business risk when assessing software vulnerabilities
- Continuously improve the operations of SAST, DAST and Ia C security tools
- Continuously improve the operations of Web Application Firewalls (WAF) or IDS
- Continuously improve the coverage of security tooling in Cloud environments e. g. Microsoft Azure & Amazon AWS
- The knowledge, experience and qualifications you need
- Computer Science / Cyber Security Degree
- Application Development background
- Azure Dev Ops experience
- Prior experience in using AI models and cyber harnesses to support security evaluation of application and software code.
- Git Hub, Copilot, Codex, OWASP Top 10 for Agentic AI, AI skills development and security triage.
- Ability to code in at least one programming language e. g. Python/Java Script/CSharp/Powershell
- Prior experience working in a large organisation or Financial Services is an advantage
- Excellent analytical skills with attention to details
- CISSP/CSSLP/CEH/OSCP or similar certification
- Presentation skills - ability to present complex solutions to a less technical audience
- Team-player interpersonal skills, with the ability to communicate and collaborate effectively with different people in a variety of roles
- Passionate about developing a career in Information Security
- Excellent command of the English language, both written and spoken
- What you'll be like
- Passionate about mastering and innovating best practice in business analysis
- Inspiring and collaborative leader, model of agile leadership approach
- Friendly, approachable, enjoys working with people from a variety of backgrounds
- Capable of remaining positive when under pressure
- Continuous improvement mind-set, challenges the status quo and seeks self improvement
- Problem solver, comfortable taking the initiative in challenging and ambiguous circumstances
- #J-18808-Ljbffr
Application Security Engineer (Cyber) employer: Source Technology Limited
Source Technology Limited is an exceptional employer that fosters a collaborative and innovative work culture, making it an ideal place for professionals looking to thrive in the tech industry. With a strong emphasis on employee growth and development, team members are encouraged to enhance their skills through continuous learning opportunities while working on cutting-edge cloud technologies. Located in the United Kingdom, the company offers a dynamic environment where creativity and technical expertise are valued, ensuring that employees can make a meaningful impact in their roles.
StudySmarter Expert Advice🤫
We think this is how you could land Application Security Engineer (Cyber)
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Source Technology Limited, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Source Technology Limited
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Source Technology Limited. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Application Security Engineer (Cyber)
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Source Technology Limited insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Source Technology Limited that you’re committed to staying ahead in the game.
How to prepare for a job interview at Source Technology Limited
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Source Technology Limited to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Source Technology Limited.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.