Senior Application Security Consultant (SAST/DAST/OWASP )/DevSecOps Security - Banking - London
Secure SDLC | SAST | DAST | Threat Modelling | Cloud Security | CI/CD
Location: London (Hybrid - 8 days onsite per month)
Contract: 12 Months + extension
Rate: £500-£550 per day (Umbrella)
The Opportunity
We're looking for an experienced Senior Application Security Consultant/DevSecOps Security Architect to join a high-performing Cyber Security function within a large enterprise technology environment.
Working alongside software engineering, cloud, architecture and DevOps teams, you'll play a key role in embedding security throughout the Software Development Lifecycle, ensuring applications are designed, developed and deployed securely.
This is an excellent opportunity for someone passionate about Secure-by-Design, DevSecOps and modern Application Security within a large-scale cloud environment.
Key Responsibilities
- Lead application security reviews across business-critical applications and cloud platforms.
- Conduct security architecture and secure design reviews.
- Perform application security risk assessments and define security requirements.
- Lead Threat Modelling workshops using STRIDE, MITRE ATT&CK or similar methodologies.
- Embed Secure SDLC principles into engineering teams.
- Integrate security tooling into CI/CD pipelines and DevSecOps processes.
- Review and analyse SAST, DAST and Software Composition Analysis (SCA) findings.
- Work closely with development teams to prioritise vulnerability remediation.
- Define security testing requirements and support penetration testing activities.
- Produce security standards, technical guidance and best practice documentation.
- Act as the Application Security SME across multiple technology programmes.
Essential Skills
Application Security
- Secure Software Development Lifecycle (SSDLC)
- OWASP Top 10
- Secure Coding
- Secure Design Reviews
- API Security
- REST APIs
- Microservices Security
- Application Security Risk Assessments
Threat Modelling
- STRIDE
- MITRE ATT&CK
- Security Architecture
- Risk Assessments
DevSecOps
- CI/CD Security
- GitHub Actions
- GitLab
- Jenkins
- Azure DevOps
- Security Automation
- Shift Left Security
Security Testing
- SAST
- DAST
- SCA
- Vulnerability Management
- Penetration Testing
Cloud Security
- AWS, Azure or GCP
- Kubernetes
- Docker
- Container Security
- Cloud Security Best Practices
Security Tooling
Experience with one or more of:
- Checkmarx
- Fortify
- SonarQube
- Veracode
- Semgrep
- Burp Suite
- OWASP ZAP
- Snyk
- Trivy
- Prisma Cloud
- Aqua
- Wiz
Ideal Background
You'll ideally have:
- 8+ years in Cyber Security
- Strong Application Security or DevSecOps experience
- Experience working directly with software engineering teams
- Experience embedding security into CI/CD pipelines
- Strong knowledge of Secure SDLC
- Experience conducting Threat Modelling sessions
- Excellent stakeholder management and communication skills
- Previous experience within Banking, Financial Services, Insurance or another highly regulated enterprise environment
Contract Details
- 12-month contract
- £500-£550 per day (Umbrella)
- Hybrid working - 8 days onsite per month in London
- Immediate interview availability preferred
*Rates depend on experience and client requirements