Rodeo
ResourcesPartnersSign in

Global Relay

Senior Application Security Analyst

London
Posted about 18 hours ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Who we are:

For over 25 years, Global Relay has set the standard in enterprise information archiving with industry-leading cloud archiving, surveillance, eDiscovery, and analytics solutions. We securely capture and preserve the communications data of the world’s most highly regulated firms, giving them greater visibility and control over their information and ensuring compliance with stringent regulations.

Though we offer competitive compensation and benefits and all the other perks one would expect from an established company, we are not your typical technology company. Global Relay is a career-building company. A place for big ideas. New challenges. Groundbreaking innovation. It’s a place where you can genuinely make an impact – and be recognized for it.

We believe great businesses thrive on diversity, inclusion, and the contributions of all employees. To that end, we recruit candidates from different backgrounds and foster a work environment that encourages employees to collaborate and learn from each other, completely free of barriers.

Job Purpose

The Senior Application Security Specialist is a senior technical role leading advanced application security testing, complex vulnerability analysis and threat modelling across the Application & Product Security function. You will provide technical leadership, mentor analysts and specialists, act as a security point of contact for engineering, and contribute to security strategy and standards.

Scope & Autonomy

Leads testing workstreams and sets the technical approach for complex assessments; acts as an escalation point for L1/L2 and a security partner to engineering.

Duties and Responsibilities

  • Lead advanced security testing of critical applications and services, including deep-dive manual testing and targeted penetration tests across web, mobile and API surfaces.
  • Own threat modelling using structured frameworks (STRIDE, PASTA), producing threat models for new features and architecture changes.
  • Support and engage in the penetration testing programme.
  • Design security test strategies for new products and major changes.
  • Act as subject-matter expert and primary point of contact between engineering and the Application Security team.
  • Provide oversight of scanning-tool usage and KPIs in the CI/CD pipeline.
  • Own the overarching triage, escalation and evidence-quality framework across all scanning tools and testing streams, resolving the most complex or contested findings and setting the standard L1/L2 analysts and specialists are mentored against.
  • Track and report key security testing metrics (e.g. time-to-remediate, recurring defect patterns) to senior stakeholders.
  • Build and maintain advanced test cases, automation frameworks and custom tooling to improve coverage and efficiency.
  • Own the security release process, including remediation verification and closure standards.
  • Mentor and coach analysts and specialists; provide training material, playbooks and quality review of finding reports.
  • Act as an escalation point for L1/L2 security analysts.
  • Provide expert-level root-cause analysis and remediation guidance for the most complex or systemic security defects and set remediation standards developers and L1/L2 analysts follow across the programme.
  • Develop and maintain process documentation and testing standards.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Qualifications

  • 5–8 years' hands-on experience in application security testing.
  • Advanced knowledge of internet and network technologies.
  • Expert understanding of web and API technologies and common vulnerabilities (OWASP Top 10, API/LLM Top 10, Mobile Top 10).
  • Advanced mobile security testing (Android/iOS) — reverse engineering, runtime manipulation, Frida scripting, Objection.
  • Advanced knowledge of container orchestration and Kubernetes security, including cluster hardening, RBAC and workload isolation.
  • Advanced AI/LLM security assessment.
  • Expert understanding of security controls (access control, encryption, logging/monitoring, secure configuration) and how to assess their effectiveness at scale.
  • Strong offensive security skillset — manual web and API testing, authentication/authorisation bypass, session management, business-logic abuse and data-protection testing.
  • Advanced knowledge of threat remediation techniques specific to the programming languages in use at Global Relay.
  • Strong awareness of advanced persistent threats (APTs), threat actor tactics (e.g. MITRE ATT&CK) and emerging vulnerability classes, and ability to apply this awareness to test strategy design.
  • Ability to build and own automation: scripting test cases (Python, Bash), integrating with TestRail and Jira, building automated Burp Suite Pro scanning workflows in CI/CD, and working knowledge of supporting tools such as Postman and SonarQube.
  • Excellent communication skills; ability to influence technical and non-technical stakeholders.
  • Recognised advanced certifications preferred (e.g. OSCP, OSWE).

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Global Relay is unable to offer visa sponsorship for this position. Candidates must have the right to work in the UK at the time of application.

What you can expect:

At Global Relay, there’s no ceiling to what you can achieve. It’s the land of opportunity for the energetic, the intelligent, the driven. You’ll receive the mentoring, coaching, and support you need to reach your career goals. You’ll be part of a culture that breeds creativity and rewards perseverance and hard work. And you’ll be working alongside smart, talented individuals from diverse backgrounds, with complementary knowledge and skills.

Global Relay is an equal-opportunity employer committed to diversity, equity, and inclusion.

We seek to ensure reasonable adjustments, accommodations, and personal time are tailored to meet the unique needs of every individual.

To learn more about our business, culture, and community involvement, visit www.globalrelay.com.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Application Security Testing
Vulnerability Analysis
Threat Modelling
Penetration Testing
Web Security
Mobile Security
API Security
OWASP Top 10
Kubernetes Security
AI/LLM Security Assessment
Python
Bash
Burp Suite Pro
CI/CD
Reverse Engineering
Offensive Security

Location

London, England, United Kingdom

Sign up to applySee more jobs like this