Application Security Specialist focusing on security in software development lifecycle at Insight Investment in Manchester, driving DevSecOps practices across teams.
Responsibilities
Collaborate with development, DevOps, and architecture teams to integrate security into the SDLC
Design and implement secure coding practices and threat modelling processes
Lead the integration of security tools into CI/CD pipelines (e.g., SAST, DAST, SCA, IAST)
Conduct security assessments of applications, APIs, and microservices
Develop and maintain security standards, guidelines, and automation scripts
Provide guidance on secure design patterns and architecture decisions
Promote a DevSecOps culture and continuous security improvement across development and architecture team
Requirements
Strong understanding of application security principles (e.g., OWASP Top 10, CWE).
Experience with secure coding in languages such as Java, Python, JavaScript, or .NET. (.NET and Python are preferable)
Hands-on experience with one of each or more security tools:
Static Analysis (SAST): Veracode (preferable), Checkmarx, Fortify, etc.
Dynamic Analysis (DAST): Veracode (preferable), Burp Suite, OWASP ZAP, etc.
Software Composition Analysis (SCA): Veracode (preferable), Snyk, Black Duck, etc.
Container Security: Aqua Security (preferable), Prisma Cloud, etc.
Protective Security Officer supporting information security and physical security processes at Telia. Collaborating with clients and team members for effective security management.
Application Security Lead at Mastercard enhancing application security and collaborating with development teams. Leading initiatives, guiding secure coding practices, and fortifying cybersecurity posture.
Senior Cloud Security Architect for Texas state government project. Designing secure cloud architectures and integrating security in DevSecOps pipelines.
Product Manager responsible for managing Microsoft Security Services portfolio at Softchoice. Engaging with customers, Microsoft and stakeholders to drive market success and growth.
Linux Network Security Engineer at Booz Allen Hamilton architecting and deploying Endace packet capture systems across a distributed enterprise. Integrating with analytics ecosystems and ensuring optimal performance.
Information System Security Officer detecting and documenting security configurations for government solutions. Collaborating with teams to provide secure and effective solutions against advanced cyber threats.
IT Infrastructure and Security Administrator overseeing management and maintenance of IT systems at Avive Solutions. Focused on user devices, networks, and authentication systems.
Systems Administrator managing IT support and compliance activities in a tech - oriented company. Leading infrastructure design and security measures while collaborating with managed service providers.
OT Cybersecurity Engineer enhancing cybersecurity in industrial environments. Ensuring compliance with cybersecurity standards and collaborating across engineering, IT, and product teams.
Cyber Security Expert supporting project teams with structured risk assessments and compliance documentation at Nordex wind farms. Collaborating closely with Information Security to ensure secure operations.