Rodeo
Get started

Secure Source

Senior Application Security Specialist

London
£75k – £95k/yr
Posted about 21 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Application Security Specialist

The Application Security Specialist exists to embed application security expertise across Europe’s products and services, supporting the Secure Development Practice and enabling a consistent ‘shift-left’ approach. The role is accountable for advancing application security capability, leading security reviews on higher-risk systems, and ensuring secure development practices are adopted across engineering teams. The post holder will act as a technical authority on application security, helping reduce vulnerability risk and improve security outcomes across both internal IT systems and customer-facing solutions.

Key Responsibilities

  • Embed application security expertise across Europe’s products and services.
  • Support the Secure Development Practice.
  • Enable a consistent ‘shift-left’ approach.
  • Advance application security capability.
  • Lead security reviews on higher-risk systems.
  • Ensure secure development practices are adopted across engineering teams.

Required Knowledge and Experience

  • Strong knowledge of application security principles and practices
  • Experience with SAST, DAST, and software composition analysis tools
  • Knowledge of secure coding practices across languages such as Java, C, C++
  • Experience with CI/CD pipelines and DevSecOps integration
  • Threat modelling techniques and tools
  • Understanding of OWASP Top 10 and common vulnerability classes
  • Experience with API security and web application security
  • Understanding of fuzz testing and advanced testing techniques
  • Familiarity with secure AI development considerations
  • Knowledge of secure development frameworks such as SSDF
  • Understanding of vulnerability management processes

Experience Required

Minimum

  • 3 to 5 years in application security, secure development, or software engineering with a security focus
  • Hands-on experience conducting application security reviews
  • Experience implementing security in CI/CD processes
  • Experience working with development teams in an enterprise environment

Desirable

  • Experience building or contributing to a security CoE or capability model
  • Experience working in a multi-entity, multinational environment
  • Experience integrating security into large-scale development programmes
  • Experience supporting secure AI or data-centric applications

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Minimum Qualifications Required

Minimum

  • Degree or equivalent professional experience in one of the following: computer science, software engineering, cyber security, information security, or related technical discipline
  • Evidence of formal or structured learning in secure development or application security (for example, through certifications, formal training, or demonstrable experience)

Desirable

  • Recognised application security or secure development certification, such as:
    • CSSLP (Certified Secure Software Lifecycle Professional)
    • GIAC Web Application Penetration Tester (GWAPT) or GWEB
    • Offensive Security certifications (e.g., OSCP) where relevant to application testing
  • Cloud security certifications relevant to application hosting environments:
    • AWS Security Specialty
    • Microsoft Azure Security Engineer Associate
    • Google Professional Cloud Security Engineer
  • DevSecOps or CI/CD related certifications or formal training
  • ISO 27001 Lead Implementer or Lead Auditor, or demonstrable understanding of ISO control environments
  • Familiarity with NIST frameworks, particularly NIST CSF and NIST SSDF, demonstrated through training or experience
  • Relevant vendor certifications linked to SAST, DAST, SCA, or pipeline tooling where used in the organisation
  • Evidence of continuous professional development in secure coding, software assurance, or emerging technologies such as AI security

Minimum Skills Required

Minimum

  • Strong software engineering foundation:
    • Ability to read and understand code across at least one major language (Java, C, C++, C#, Python, or similar)
    • Understanding of common development frameworks and application architectures
  • Practical application security capability:
    • Hands-on experience identifying and explaining common vulnerabilities
    • Ability to guide remediation in a way developers can implement
  • Secure development lifecycle knowledge:
    • Understanding of how to embed security into design, build, test, and deployment stages
    • Familiarity with shift-left practices and developer workflows
  • Threat modelling capability:
    • Ability to identify threats, abuse cases, and attack surfaces
    • Experience applying structured approaches such as STRIDE or similar
  • CI/CD and DevOps familiarity:
    • Understanding of pipelines, build processes, and release workflows
    • Capability to integrate or advise on automated security testing within pipelines
  • Analytical and diagnostic capability:
    • Ability to interpret scan results and distinguish false positives from real risk
    • Ability to identify systemic issues rather than isolated defects
  • Communication and influence:
    • Ability to translate security issues into actionable developer guidance
    • Confidence in engaging engineers, architects, and product owners
  • Risk awareness:
    • Ability to link technical vulnerabilities to business risk and prioritisation

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Desirable

  • Advanced application security techniques:
    • Experience with fuzz testing, advanced dynamic testing, or manual code review
    • Experience testing APIs, microservices, and distributed systems
  • DevSecOps implementation:
    • Experience designing or implementing security controls within CI/CD pipelines
    • Hands-on experience integrating SAST, DAST, SCA, and secrets scanning tools
  • Secure architecture understanding:
    • Familiarity with secure design patterns and common failure modes in modern architectures (cloud-native, microservices, serverless)
  • Secure AI and data-driven systems awareness:
    • Understanding of risks associated with AI models, data pipelines, and prompt or model manipulation
  • Training and enablement capability:
    • Ability to design or deliver developer-focused training or workshops
    • Ability to simplify complex security concepts without diluting technical accuracy
  • Broader security framework awareness:
    • Working knowledge of OWASP SAMM, ASVS, or similar maturity models
    • Familiarity with threat intelligence inputs and how they influence application risk
  • Tooling depth:
    • Experience selecting, tuning, or optimising security tools for development environments
    • Understanding of strengths and limitations of common tooling categories
  • Multi-environment experience:
    • Exposure to both internal enterprise IT systems and externally facing customer solutions
  • Ability to operate in federated organisations:
    • Comfort working across multiple teams, geographies, and delivery models with varying levels of maturity
Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Application Security
SAST
DAST
Software Composition Analysis
Secure Coding
CI/CD Pipelines
DevSecOps
Threat Modelling
OWASP Top 10
API Security
Web Application Security
Fuzz Testing
Secure AI Development
Vulnerability Management
Java
C++

Location

London, England, United Kingdom

Sign up to applySee more jobs like this