Senior Application Security Consultant (SAST/DAST/OWASP )

Senior Application Security Consultant (SAST/DAST/OWASP )

Full-Time 63000 - 77000 £ / year (est.) Home office (partial)
X

At a Glance

  • Tasks: Lead application security reviews and embed security in the Software Development Lifecycle.
  • Company: Join a leading enterprise technology firm in the banking sector.
  • Benefits: Competitive daily rate, hybrid work model, and potential for contract extension.
  • Other info: Immediate interview availability and excellent career growth opportunities.
  • Why this job: Make a real impact on application security in a dynamic, cloud-based environment.
  • Qualifications: 8+ years in Cyber Security with strong DevSecOps and application security experience.

The predicted salary is between 63000 - 77000 £ per year.

Senior Application Security Consultant (SAST/DAST/OWASP )/ Dev Sec Ops Security - Banking - London

Secure SDLC | SAST | DAST | Threat Modelling | Cloud Security | CI/CD

Location

London (Hybrid - 8 days onsite per month)

Contract

12 Months + extension

Rate

£500-£550 per day (Umbrella)

The Opportunity

We're looking for an experienced

Senior Application Security Consultant / Dev Sec Ops Security Architect to join a high-performing Cyber Security function within a large enterprise technology environment.

Working alongside software engineering, cloud, architecture and Dev Ops teams, you'll play a key role in embedding security throughout the Software Development Lifecycle, ensuring applications are designed, developed and deployed securely.

This is an excellent opportunity for someone passionate about Secure-by-Design, Dev Sec Ops and modern Application Security within a large-scale cloud environment.

Key Responsibilities

  • Lead application security reviews across business-critical applications and cloud platforms.
  • Conduct security architecture and secure design reviews.
  • Perform application security risk assessments and define security requirements.
  • Lead Threat Modelling workshops using STRIDE, MITRE ATT&CK or similar methodologies.
  • Embed Secure SDLC principles into engineering teams.
  • Integrate security tooling into CI/CD pipelines and Dev Sec Ops processes.
  • Review and analyse SAST, DAST and Software Composition Analysis (SCA) findings.
  • Work closely with development teams to prioritise vulnerability remediation.
  • Define security testing requirements and support penetration testing activities.
  • Produce security standards, technical guidance and best practice documentation.
  • Act as the Application Security SME across multiple technology programmes.

Essential Skills

  • Application Security
  • Secure Software Development Lifecycle (SSDLC)
  • OWASP Top 10
  • Secure Coding
  • Secure Design Reviews
  • API Security
  • REST APIs
  • Microservices Security
  • Application Security Risk Assessments
  • Threat Modelling
  • STRIDE
  • MITRE ATT&CK
  • Security Architecture
  • Risk Assessments
  • Dev Sec Ops
  • CI/CD Security
  • Git Hub Actions
  • Git Lab
  • Jenkins
  • Azure Dev Ops
  • Security Automation
  • Shift Left Security
  • Security Testing
  • SAST
  • DAST
  • SCA
  • Vulnerability Management
  • Penetration Testing
  • Cloud Security
  • AWS, Azure or GCP
  • Kubernetes
  • Docker
  • Container Security
  • Cloud Security Best Practices
  • Security Tooling

Experience with one or more of

  • Checkmarx
  • Fortify
  • Sonar Qube
  • Veracode
  • Semgrep
  • Burp Suite
  • OWASP ZAP
  • Snyk
  • Trivy
  • Prisma Cloud
  • Aqua
  • Wiz
  • Ideal Background

You’ll ideally have

  • 8+ years in Cyber Security
  • Strong Application Security or Dev Sec Ops experience
  • Experience working directly with software engineering teams Experience embedding security into CI/CD pipelines
  • Strong knowledge of Secure SDLC
  • Experience conducting Threat Modelling sessions
  • Excellent stakeholder management and communication skills
  • Previous experience within Banking, Financial Services, Insurance or another highly regulated enterprise environment
  • Contract Details
  • 12-month contract
  • £500-£600 per day (Umbrella)
  • Hybrid working - 8 days onsite per month in London
  • Immediate interview availability preferred
  • *Rates depend on experience and client requirements
  • #J-18808-Ljbffr

Senior Application Security Consultant (SAST/DAST/OWASP ) employer: Xpand Group

Xpand Group is an exceptional employer that fosters a collaborative and innovative work culture, making it an ideal place for professionals looking to make a significant impact in the retail sector. With a strong emphasis on employee growth and development, team members are encouraged to enhance their skills through continuous learning opportunities while working on cutting-edge planning solutions for a leading consumer brand. The hybrid work model offers flexibility, allowing employees to balance their professional and personal lives effectively.

X

Contact Details:

Xpand Group Recruitment Team

We think you need these skills to ace Senior Application Security Consultant (SAST/DAST/OWASP )

Application Security
Secure Software Development Lifecycle (SSDLC)
OWASP Top 10
Secure Coding
Secure Design Reviews
API Security
Threat Modelling