We are seeking an Application Security Engineer to help strengthen the security of modern software applications throughout their... Read more
We are seeking an Application Security Engineer to help strengthen the security of modern software applications throughout their development lifecycle. You will work closely with software engineers, architects, DevOps specialists and product teams to identify security risks early, promote secure engineering practices and support the delivery of resilient, high-quality applications. This role offers the opportunity to influence security strategy while remaining hands-on with technical assessment and remediation.
Your responsibilities will include designing and maintaining application security processes, integrating security controls into CI/CD pipelines, and conducting code reviews, threat modelling, vulnerability assessments and penetration testing. You will investigate findings from automated and manual testing, assess their potential impact, and work with development teams to implement practical fixes. You will also help establish security standards, provide guidance on secure coding principles, contribute to incident investigations, and track remediation activities through to completion. Clear documentation, reporting and communication with both technical and non-technical stakeholders will be an important part of the role.
Applicants should have professional experience in application security, secure software development or a closely related discipline, together with a strong understanding of common web and API vulnerabilities, including those described by the OWASP Top 10. Experience with security testing tools, source code analysis, dependency management, cloud environments and DevSecOps practices is highly desirable. Familiarity with one or more programming languages and knowledge of authentication, authorisation, cryptography and security architecture are expected. Relevant certifications such as OSCP, CSSLP, GWEB or similar are beneficial but not essential. We are looking for a collaborative, analytical professional who can explain complex risks clearly, balance security with delivery needs, and continuously improve security practices across the software development lifecycle.
Read lessWindsor, England, United KingdomPermanent
We are seeking an Information Security Third Party Assurance Analyst to support the assessment and ongoing oversight of... Read more
We are seeking an Information Security Third Party Assurance Analyst to support the assessment and ongoing oversight of the organisation’s suppliers, partners and other external service providers. In this role, you will help ensure that third parties meet required information security, privacy, resilience and risk management standards before and throughout the relationship lifecycle. You will work closely with procurement, legal, technology, privacy, risk and business teams to provide clear, practical assurance and support informed risk-based decisions.
Your responsibilities will include reviewing supplier security questionnaires, independent assurance reports, policies, certifications and other evidence; assessing controls against recognised frameworks and internal requirements; identifying gaps, risks and areas requiring remediation; and documenting findings in a consistent and auditable manner. You will maintain accurate records of assessments, track remediation plans and follow up on outstanding actions. The role will also involve contributing to onboarding and periodic reviews, supporting risk acceptance processes, preparing management reporting and escalating material concerns where appropriate. You may assist with improving third-party risk procedures, assessment templates, guidance materials and reporting dashboards.
We are looking for experience in information security, supplier assurance, technology risk, audit, compliance or a closely related field. You should have a sound understanding of security controls and common frameworks such as ISO 27001, SOC 2, NIST or CIS, together with familiarity with data protection, business continuity, access management, vulnerability management and incident response. Strong analytical and organisational skills are essential, as is the ability to interpret technical evidence and communicate its implications clearly to both technical and non-technical stakeholders. Experience using governance, risk and compliance tools or managing multiple assessments simultaneously would be advantageous. Relevant professional qualifications or certifications are welcomed, although practical experience and a proactive, collaborative approach are equally valued.
Read lessWindsor, England, United KingdomPermanent
All your saved jobs are no longer available or you've already applied.
for the following search criteria