×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Lead Application Security​/DevSecOps Engineer

Job in Loughborough, Leicestershire, LE11, England, UK
Listing for: Faria Education Group
Full Time position
Listed on 2026-08-29
Job specializations:
  • Security
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 90000 - 150000 GBP Yearly GBP 90000.00 150000.00 YEAR
Job Description & How to Apply Below

Faria is a leader in international education systems & services, offering an integrated suite across learning, admissions, school-to-home, and online courses — trusted by 10,000+ schools and 4 million students across 155 countries.

Our product family includes Manage Bac (curriculum, assessment & reporting for international schools), Open Apply (admissions management & CRM, used by 600+ leading international and independent schools), Schools Buddy (co-curricular & activity management), and Vectare (school transport management).

We are looking for a Lead Security/Dev Sec Ops  Engineer on the Product Engineering team, with a great opportunity to be self-directed and level up security practices and capabilities. We expect this to be a hands‑on leadership role with a potential opportunity to build/upskill a small team. The person will report to the VP of Engineering and work in partnership with the vCISO, Dev Ops team, and engineering teams.

Key Responsibilities
  • Do an initial deep-dive assessment and evaluation to drive risk‑based prioritisation of the following responsibilities
  • Stand up and own the application security program across all five products — this is effectively greenfield.
  • Define and embed a secure SDLC (shift‑left): security requirements, design reviews, guardrails, and coding standards for an AI engineering reality.
  • Select, deploy, and ope rationalise App Sec tooling (SAST, DAST, SCA/dependency and secrets scanning) integrated into CI/CD.
  • Implement and ope rationalise secrets management: detection, rotation, and vault integration across CI/CD pipelines.
  • Build risk‑based vulnerability management: triage, prioritise, and drive remediation across teams and stacks. Lead remediation of some vulnerabilities as necessary in support of the software engineering team
  • Run threat modeling and security reviews for new architecture and significant features.
  • Improve cloud security posture across AWS (primary) and Azure, partnering with platform/infra.
  • Lead technical incident response for application‑layer incidents; coordinate with SOC and vCISO on cross‑domain incidents.
  • Build security awareness and a security‑champions network to upskill engineers.
  • Uphold student‑data privacy and regulatory obligations.
  • Contribute technical evidence and metrics to support the security roadmap and future hiring decisions
Requirements (must have)
  • 7+ years in application/product security, ideally including standing up or substantially maturing an App Sec program (ideally near‑zero to functioning).
  • Strong AI knowledge and curiosity in the space, with the aim of proactive protection, as well as approaching problem‑solving AI‑first
  • Comfortable as a founding, hands‑on, solo function — self‑directed and pragmatic under ambiguity
  • Breadth across stacks: able to work across Ruby on Rails, PHP/Laravel, .NET/C#, and Python (deep in one or two, competent across the rest).
  • Strong cloud security across AWS (primary) and Azure.
  • Deep grasp of common vulnerability classes and secure coding practices.
  • Hands‑on with App Sec tooling and Dev Sec Ops  / CI/CD integration.
  • Threat‑modeling experience.
  • Excellent communication and influencing skills — able to drive change in an engineering org, new to formal security.
Nice to have
  • Git Hub Advanced Security experience is a strong nice‑to‑have.
  • The candidate has worked with student data or PII‑heavy regulated environments (FERPA, COPPA, GDPR for UK/EU students).
  • Proven experience managing large vulnerability backlogs: ability to classify, deduplicate, and drive burn‑down across hundreds of repositories.

All qualified applicants will be considered for employment without regard to age, race, creed, color, national origin, ancestry, marital status, affectional or sexual orientation, gender identity or expression, disability, nationality, or sex. Faria operates a safer recruitment policy, and the successful applicant may be required to complete an enhanced DBS disclosure and an Enhanced Check for Regulated Activity.

Please note:

Only shortlisted candidates will be contacted due to a high volume of applicants.

What we offer
  • Compensation
    - Competitive compensation and opportunities for career development
  • Learning
    - We encourage…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary