×
Register Here to Apply for Jobs or Post Jobs. X

Senior Application Security Specialist

Job in Greater London, London, Greater London, W1B, England, UK
Listing for: Secure Source
Full Time position
Listed on 2026-09-01
Job specializations:
  • IT/Tech
    Cybersecurity, Security Management & Operations, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 70000 - 110000 GBP Yearly GBP 70000.00 110000.00 YEAR
Job Description & How to Apply Below
Location: Greater London

The Application Security Specialist exists to embed application security expertise across Europe’s products and services, supporting the Secure Development Practice and enabling a consistent ‘shift-left’ approach. The role is accountable for advancing application security capability, leading security reviews on higher-risk systems, and ensuring secure development practices are adopted across engineering teams. The post holder will act as a technical authority on application security, helping reduce vulnerability risk and improve security outcomes across both internal IT systems and customer-facing solutions.

  • Strong knowledge of application security principles and practices
  • Experience with SAST, DAST and software composition analysis tools
  • Knowledge of secure coding practices across languages such as Java, C, C++
  • Experience with CI/CD pipelines and Dev Sec Ops  integration
  • Threat modelling techniques and tools
  • Understanding of OWASP Top 10 and common vulnerability classes
  • Experience with API security and web application security
  • Understanding of fuzz testing and advanced testing techniques
  • Familiarity with secure AI development considerations
  • Knowledge of secure development frameworks such as SSDF
  • Understanding of vulnerability management processes
Experience Required Minimum
  • 3 to 5 years in application security, secure development or software engineering with a security focus
  • Hands-on experience conducting application security reviews
  • Experience implementing security in CI/CD processes
  • Experience working with development teams in an enterprise environment
  • Experience building or contributing to a security CoE or capability model
  • Experience working in a multi-entity, multinational environment
  • Experience integrating security into large-scale development programmes
  • Experience supporting secure AI or data-centric applications
Minimum Qualifications Required Minimum
  • Degree or equivalent professional experience in one of the following:
  • computer science
  • software engineering
  • cyber security
  • information security or related technical discipline
  • Evidence of formal or structured learning in secure development or application security (for example through certifications, formal training or demonstrable experience).
  • Recognised application security or secure development certification, such as:
  • CSSLP (Certified Secure Software Lifecycle Professional)
  • GIAC Web Application Penetration Tester (GWAPT) or GWEB
  • Offensive Security certifications (e.g. OSCP) where relevant to application testing
  • Cloud security certifications relevant to application hosting environments:
  • AWS Security Specialty
  • Microsoft Azure Security Engineer Associate
  • Google Professional Cloud Security Engineer
  • Dev Sec Ops  or CI/CD related certifications or formal training
  • ISO 27001 Lead Implementer or Lead Auditor, or demonstrable understanding of ISO control environments
  • Familiarity with NIST frameworks, particularly NIST CSF and NIST SSDF, demonstrated through training or experience
  • Relevant vendor certifications linked to SAST, DAST, SCA or pipeline tooling where used in the organisation
  • Evidence of continuous professional development in secure coding, software assurance or emerging technologies such as AI security
  • Strong software engineering foundation:
  • ability to read and understand code across at least one major language (Java, C, C++, C#, Python or similar)
  • understanding of common development frameworks and application architectures
  • Practical application security capability:
  • hands-on experience identifying and explaining common vulnerabilities
  • ability to guide remediation in a way developers can implement
  • understanding of how to embed security into design, build, test and deployment stages
  • familiarity with shift-left practices and developer workflows
  • ability to identify threats, abuse cases and attack surfaces
  • experience applying structured approaches such as STRIDE or similar
  • CI/CD and Dev Ops familiarity:
  • understanding of pipelines, build processes and release workflows
  • capability to integrate or advise on automated security testing within pipelines
  • Analytical and diagnostic capability:
  • ability to interpret scan results and distinguish false positives from real risk
  • ability to identify…
Position Requirements
10+ Years work experience
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary