about the company
Our client is a global financial technology and financial messaging organisation supporting critical financial services and institutions worldwide. The organisation operates within a highly regulated, security-critical technology environment where cybersecurity, application security, resilience and secure software development are fundamental to business operations.
With continued investment in cloud-native technologies, APIs, microservices, containers and DevSecOps, the organisation is strengthening its Application Security capability to ensure security is embedded throughout the software development lifecycle.
You will join an international and diverse technology security environment, working alongside experienced cybersecurity, engineering, architecture and technology professionals across global teams.
...
about the job
We are looking for a Senior Application Security Specialist to strengthen the organisation's Application Security, Product Security and Security Architecture capabilities.
This is a hands-on Application Security / DevSecOps / Security Architecture role where you will act as a trusted security partner to software engineering, Agile, DevOps and DevSecOps teams, helping them build and operate secure applications and services.
You will be responsible for embedding security-by-design and shift-left security practices throughout the Software Development Lifecycle (SDLC), from architecture and design through development, testing, deployment and operations.
Key responsibilities include:
- Partner with Agile, Software Engineering, DevOps and DevSecOps teams to integrate security into application design and development.
- Conduct Application Security and Security Architecture reviews, identifying security weaknesses and recommending practical remediation.
- Perform Threat Modelling, Risk Analysis and Security Risk Assessments to identify threats, vulnerabilities, business impact and appropriate security controls.
- Define and communicate security requirements based on business requirements, technology architecture, security policies, threats and risk appetite.
- Provide security guidance across the Software Development Lifecycle (SDLC), including secure design, secure coding, security testing, deployment and operations.
- Establish and promote Secure by Design, Shift-Left Security and DevSecOps practices.
- Support the integration and adoption of SAST, DAST, SCA, API Security Testing and Container Security within CI/CD pipelines.
- Assess application and API security risks across cloud-native, microservices, containerised and orchestrated environments.
- Research emerging cybersecurity threats, vulnerabilities and security alerts, assessing their potential impact and recommending remediation.
- Develop and improve security standards, guidelines, processes and security automation capabilities.
- Identify opportunities to improve security testing, security automation and software delivery processes.
- Work closely with engineering and technology teams to strengthen application security controls without compromising delivery velocity.
- Promote a strong security culture across technology and engineering teams.
- Coach and share Application Security and secure development knowledge with colleagues and technical stakeholders.
Key Technical Skills
Candidates with experience in the following areas will be highly relevant:
Application Security | Product Security | Security Architecture | Threat Modelling | Risk Assessment | Secure SDLC | DevSecOps | Security-by-Design | Shift-Left Security | OWASP Top 10 | SAST | DAST | SCA | API Security | API Testing | Container Security | Cloud Security | CI/CD Security | Vulnerability Management
Experience with AWS, Azure, GCP, Kubernetes, Docker, microservices or other cloud-native technologies will be advantageous.
about the manager/team
You will join an international Application Security and IT Security team working closely with software engineering, architecture, DevOps and DevSecOps teams.
The team operates in a highly collaborative and technically complex environment, where security is embedded into technology delivery rather than treated as a separate function.
You will work with experienced cybersecurity professionals and technical SMEs across different countries and disciplines, with opportunities to contribute ideas, introduce new security approaches and influence how security is implemented across critical applications and services.
The ideal candidate is a hands-on Application Security professional who can combine strong technical security knowledge with the ability to influence developers, engineers, architects and business stakeholders.