Security Architect - DevSecOps Application Security
Job in
St James's, Greater London, SW1A 2DX, England, UK
Listed on 2026-09-27
Listing for:
Hackajob Ltd
Full Time
position Listed on 2026-09-27
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Job Description & How to Apply Below
Location: St James's
Colt provides network, voice and data centre services to thousands of businesses around the world, allowing them to focus on delivering their business goals instead of the underlying infrastructure. Why we need this role We are looking for a Security Architect specialising in Application Security and Dev Sec Ops to join the Security and Resilience Security Architecture team. This role will act as a subject matter expert for secure software development and Dev Sec Ops practices, supporting the integration of security controls into Colts development pipelines and ensuring applications are secure by design and by default.
The successful candidate will work closely with Engineering, Dev Ops, Cloud, SOC and Risk teams to embed security throughout the software development lifecycle, ensuring that Colts applications and services are designed, built and tested with security as a core requirement. The role combines:
Application security architecture and design Dev Sec Ops pipeline integration and tooling Security assurance and governance across internally developed applications You will play an important role in supporting:
Secure software development practices across Colt Security integration into CI/CD pipelines (Git Lab) Reduction of vulnerabilities through automated scanning and testing Assurance of internet-facing applications through structured penetration testing activities What you will do Provide security architecture expertise for application security and Dev Sec Ops , supporting standards and best practices across the software development lifecycle Contribute to the target architecture for secure software development, aligned to Colts Secure by Design principles Support the integration of security controls into CI/CD pipelines (Git Lab), including automated testing and policy enforcement Design and implement application security controls, including:
Static Application Security Testing (SAST) Dynamic Application Security Testing (DAST) Software Composition Analysis (SCA) / dependency scanning Secrets and credentials scanning Work with engineering teams to ensure consistent adoption of Dev Sec Ops practices and secure coding approaches Support security architecture reviews and assurance activities for internally developed applications and services Identify and help reduce risks related to application vulnerabilities, insecure coding practices and exposed credentials Support the coordination and execution of third-party penetration testing of Colts internet-facing applications Assist in defining test scope, tracking execution and ensuring remediation of findings is properly managed Provide guidance to engineering teams on remediation and prioritisation of vulnerabilities Contribute to the development and maintenance of secure coding standards and architectural patterns Ensure alignment with regulatory requirements such as TSA, DORA and ISO
27001 in application design and deployment Promote a security-first culture within development teams, including awareness and best practices Maintain awareness of emerging risks and technologies, including basic AI/LLM-related application risks, and support translation into practical controls where required Produce and maintain architecture artefacts, standards and guidance documentation What we're looking for Must haves: 5 years of experience in information security, with a strong focus on application security and Dev Sec Ops Strong understanding of secure software development practices and common application security risks (e.g. OWASP Top 10) Hands-on experience working with or integrating Dev Sec Ops tooling within CI/CD environments (e.g. Git Lab pipelines)
Experience with application security testing tools and practices, including: SAST, DAST, SCA / dependency scanning and Secrets / credentials scanning. Experience contributing to security design reviews for applications and APIs Experience supporting or participating in penetration testing activities, including remediation tracking Strong understanding of modern application architectures (e.g. APIs, microservices, cloud-native applications) Knowledge of authentication and session management concepts within applications Experience performing or supporting risk assessments aligned to recognised frameworks Ability to translate technical vulnerabilities into business-aligned risk and remediation actions Strong collaboration skills with engineering and development teams Strong communication skills (technical and…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×