At a Glance
- Tasks: Lead and mentor a team in application security while driving technology transformation.
- Company: Dynamic financial services firm undergoing a major tech transformation.
- Benefits: Competitive salary, great benefits, and opportunities for rapid career progression.
- Why this job: Join a transformative journey and make a real impact in application security.
- Qualifications: Experience in application security and team leadership required.
- Other info: Inclusive workplace committed to accessibility and diversity.
The predicted salary is between 100000 - 100000 £ per year.
An impressive financial services business is looking to hire a Lead Application Security Engineer to support this team with the risk and remediation activities. This business is going through a big technology transformation programme that is estimated to take 3 -5 years. The successful Lead Application Security Engineer will be part of this journey and have great technical exposure and the ability to rapidly progress. Working closely in one of the transformation projects, the successful Lead Application Security Engineer will work closely with the wider security and technology teams to define the strategy and roadmap of technology changes moving forward. This is very much a play-manager role with the Lead Application Security Engineer being hands on day to day but also providing support and guidance to the rest of the AppSec team.
Duties and Responsibilities
- Support the existing team, providing mentoring and fostering a collaborative team environment.
- Take a pragmatic risk-based approach to supporting the wider technology teams with the SDLC.
- Foster strong relationships with engineering, architecture, platform and platform management to provide practical risk appropriate guidance.
- Set the priorities for the AppSec team to ensure that the delivery of the AppSec services is impactful.
- Act as the SME for application security in the business and ensure that security controls are adopted early into the CI/CD pipelines.
- Own and run the DAST, SAST and other AppSec tooling to ensure effective coverage across all in scope applications.
- Create, roll out and maintain secure development practices and standards including threat modelling, secure coding practices for all applications and APIs.
- Collaborate with the Vulnerability Engineering Lead to support the identifications, triages, and remediation programs in alignment with risk appetite, appropriate prioritisation and agreed SLAs.
Your Background
- Experience in a similar role, in both responsibility and scale.
- Proven experience in Software Security Development or Application Security.
- Proven experience in leading/coaching a team.
- Hands-on experience with implementing and operating AppSec tooling e.g. SAT and DAST, secret management, and SCA.
- Extensive experience of integrating security into the CI/CD pipeline e.g. using AWS DevOps or GitHub.
- Strong history of secure coding practices, threat modelling and vulnerability management in production.
- Strong understanding of modern software development practices.
If this sounds like the role for you, hit the apply button NOW! We invite individuals from underrepresented groups to apply for any of our roles and are committed to supporting accessibility needs. Please click the apply button now or contact Abigail Moss for more information.
Lead Application Security Engineer in London employer: Spencer Rose
Contact Detail:
Spencer Rose Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Lead Application Security Engineer in London
✨Tip Number 1
Network like a pro! Reach out to your connections in the industry, attend meetups, and engage with professionals on LinkedIn. We all know that sometimes it’s not just what you know, but who you know that can help you land that Lead Application Security Engineer role.
✨Tip Number 2
Prepare for those interviews by brushing up on your technical skills and understanding the latest trends in application security. We recommend doing mock interviews with friends or using online platforms to get comfortable with common questions and scenarios.
✨Tip Number 3
Showcase your hands-on experience! When discussing your past roles, highlight specific projects where you’ve implemented AppSec tooling or led a team. We want to see how you’ve made an impact in previous positions, especially in areas like CI/CD integration.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who take the initiative to connect directly with us.
We think you need these skills to ace Lead Application Security Engineer in London
Some tips for your application 🫡
Tailor Your CV: Make sure your CV reflects the skills and experiences that match the Lead Application Security Engineer role. Highlight your experience with AppSec tooling and team leadership, as these are key for us.
Craft a Compelling Cover Letter: Use your cover letter to tell us why you're passionate about application security and how you can contribute to our technology transformation programme. Be genuine and let your personality shine through!
Showcase Your Technical Skills: Don’t shy away from detailing your hands-on experience with DAST, SAST, and secure coding practices. We want to see how you’ve integrated security into the CI/CD pipeline in your previous roles.
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you don’t miss out on any important updates during the process.
How to prepare for a job interview at Spencer Rose
✨Know Your Stuff
Make sure you brush up on your application security knowledge. Be ready to discuss your experience with DAST, SAST, and secure coding practices. The interviewers will want to see that you can not only talk the talk but also walk the walk when it comes to technical expertise.
✨Show Your Leadership Skills
Since this role involves team leadership, be prepared to share examples of how you've mentored or coached others in the past. Highlight your ability to foster a collaborative environment and how you've set priorities for your team to ensure impactful delivery.
✨Understand the Business Context
Familiarise yourself with the company's technology transformation programme. Show that you understand how application security fits into the bigger picture and be ready to discuss how you can contribute to the strategy and roadmap of technology changes.
✨Ask Insightful Questions
Prepare some thoughtful questions to ask at the end of your interview. This could be about their current security challenges, how they measure success in the AppSec team, or what tools they currently use. It shows you're genuinely interested and engaged in the role.