Back to all jobs

Senior Application Security Consultant (SAST/DAST/OWASP )

Ref: JO-2607-362514

  • Environment: Remote
  • Contract Type: Contract
  • Starts: ASAP
  • Duration: 12 Months
Apply Report issue

Senior Application Security Consultant (SAST/DAST/OWASP )/ DevSecOps Security – Banking – London

Secure SDLC | SAST | DAST | Threat Modelling | Cloud Security | CI/CD

Location: London (Hybrid – 8 days onsite per month)

Contract: 12 Months + extension

Rate: £500-£550 per day (Umbrella)

The Opportunity

We’re looking for an experienced Senior Application Security Consultant / DevSecOps Security Architect to join a high-performing Cyber Security function within a large enterprise technology environment.

Working alongside software engineering, cloud, architecture and DevOps teams, you’ll play a key role in embedding security throughout the Software Development Lifecycle, ensuring applications are designed, developed and deployed securely.

This is an excellent opportunity for someone passionate about Secure-by-Design, DevSecOps and modern Application Security within a large-scale cloud environment.

Key Responsibilities

  • Lead application security reviews across business-critical applications and cloud platforms.
  • Conduct security architecture and secure design reviews.
  • Perform application security risk assessments and define security requirements.
  • Lead Threat Modelling workshops using STRIDE, MITRE ATT&CK or similar methodologies.
  • Embed Secure SDLC principles into engineering teams.
  • Integrate security tooling into CI/CD pipelines and DevSecOps processes.
  • Review and analyse SAST, DAST and Software Composition Analysis (SCA) findings.
  • Work closely with development teams to prioritise vulnerability remediation.
  • Define security testing requirements and support penetration testing activities.
  • Produce security standards, technical guidance and best practice documentation.
  • Act as the Application Security SME across multiple technology programmes.

Essential Skills

Application Security

  • Secure Software Development Lifecycle (SSDLC)
  • OWASP Top 10
  • Secure Coding
  • Secure Design Reviews
  • API Security
  • REST APIs
  • Microservices Security
  • Application Security Risk Assessments

Threat Modelling

  • STRIDE
  • MITRE ATT&CK
  • Security Architecture
  • Risk Assessments

DevSecOps

  • CI/CD Security
  • GitHub Actions
  • GitLab
  • Jenkins
  • Azure DevOps
  • Security Automation
  • Shift Left Security

Security Testing

  • SAST
  • DAST
  • SCA
  • Vulnerability Management
  • Penetration Testing

Cloud Security

  • AWS, Azure or GCP
  • Kubernetes
  • Docker
  • Container Security
  • Cloud Security Best Practices

Security Tooling

Experience with one or more of:

  • Checkmarx
  • Fortify
  • SonarQube
  • Veracode
  • Semgrep
  • Burp Suite
  • OWASP ZAP
  • Snyk
  • Trivy
  • Prisma Cloud
  • Aqua
  • Wiz

Ideal Background

You’ll ideally have:

  • 8+ years in Cyber Security
  • Strong Application Security or DevSecOps experience
  • Experience working directly with software engineering teams
  • Experience embedding security into CI/CD pipelines
  • Strong knowledge of Secure SDLC
  • Experience conducting Threat Modelling sessions
  • Excellent stakeholder management and communication skills
  • Previous experience within Banking, Financial Services, Insurance or another highly regulated enterprise environment

Contract Details

  • 12-month contract
  • £500-£600 per day (Umbrella)
  • Hybrid working – 8 days onsite per month in London
  • Immediate interview availability preferred

*Rates depend on experience and client requirements

Apply Report issue

Cyber Security and Risk jobs

Career and Job Insights

Apply for this job

Senior Application Security Consultant (SAST/DAST/OWASP )

  • United Kingdom, London
  • Cyber Security and Risk, Technology
  • Remote
  • Contract

Save jobs

Log in to save a job

Report job

Senior Application Security Consultant (SAST/DAST/OWASP )

  • United Kingdom, London
  • Cyber Security and Risk, Technology
  • Remote
  • Contract

"*" indicates required fields

Need talent? Request a callback

This form is for companies looking to hire talent.

I am looking for a job I have a general enquiry

"*" indicates required fields

E.g. “Senior Frontend Developer” or “Offshoring team for design.”
This field is hidden when viewing the form