Senior Application Security Specialist
Key details
- Compensation
- $42,000 - $82,000
Job Description
Salary: £42,000 - 82,000 per year
Requirements
- Extensive experience in Application Security within enterprise environments, ideally as part of a centralised Centre of Excellence or security governance function
- Strong capability in developing and governing AppSec policies, standards, and secure SDLC frameworks
- Expert knowledge across threat modelling, secure design, application risk assessment, and secure code review techniques
- Hands-on understanding of DevSecOps practices, CI/CD pipeline security, and integrating security controls within modern development workflows
- Ability to influence senior engineers, architects, and product leaders, ensuring secure-by-design principles are consistently applied
- Experience producing AppSec maturity roadmaps, target-state models, and governance frameworks
- Strong understanding of industry standards and frameworks (OWASP ASVS, OWASP SAMM, NIST, ISO 27034)
- Experience implementing or advising on secure use of AI/ML applications, including secure patterns for Generative or Agentic AI (desirable)
- Background in secure architecture reviews for microservices, APIs, and cloud-native application stacks (AWS, Azure, or hybrid) (desirable)
- Experience within regulated industries such as Financial Services or Insurance (desirable)
- Strong senior stakeholder communication skills, including the ability to articulate application risks and security requirements to executives
Responsibilities
- Own and drive the governance, guidance, and architectural messaging for Application Security (AppSec) across the organisation, ensuring consistent adoption of secure development practices
- Define and maintain target-state AppSec governance frameworks, including policies, standards, and secure SDLC practices; assess current-state maturity and define transition states for teams and markets
- Provide expert advisory across development, engineering, and product teams, ensuring AppSec requirements are integrated early and effectively into design and delivery workflows
- Perform and lead application security assessments, threat modelling sessions, design reviews, and secure code review consultations
- Partner with Security Product Owners and engineering teams to ensure AppSec tooling, processes, and services meet organisational needs and regulatory expectations
- Support selection, evaluation, and procurement of AppSec technologies, contributing to tool strategy, capability uplift, and adoption across teams
- Ensure AppSec best practices are understood and leveraged across the enterprise through coaching, documentation, and stakeholder engagement
Technologies
- AI
- AWS
- Azure
- CI/CD
- Cloud
- DevSecOps
- Support
- OWASP
- Security
- microservices
More
We are looking for a Senior Application Security Specialist to join our Governance & Advisory team, based in Norwich or London with a hybrid working model. In this role, you will take ownership of application security practices across our organization, guiding teams to secure development standards and practices. We offer a dynamic work environment with opportunities for professional growth and contributions to critical security initiatives. The assignment duration is for 6 months, during which you will collaborate with various teams to enhance our application security posture.
last updated 15 week of 2026
Company & context
Evidence is labeled so you can tell internal community data from public sources.
Range from 238 indexed roles at this employer: $29,500 - $143,000(mid ~70918)
Context may refresh in the background.
Trust-check this listing
Verify scam risk and ghost-job signals before you apply.
Related roles
Browse more remote Security Engineer jobs.
PowerShell DSC Engineer - ArcGIS Automation
PowerShell DSC Engineer - ArcGIS Automation
IM Developer
Source: DevITJobs • Last updated Apr 14, 2026