
Security Architect - DevSecOps + Application Security
Colt Technology Services22 hours ago
London, United KingdomSenior
Responsibilities
- Provide application security and DevSecOps architecture expertise across the software development lifecycle.
- Define secure software development target architecture and support Colt’s Secure by Design principles.
- Integrate security controls, automated testing, and policy enforcement into GitLab CI/CD pipelines.
- Design and implement SAST, DAST, software composition analysis, dependency scanning, and secrets-scanning controls.
- Conduct security architecture reviews and assurance activities for internally developed applications and services.
- Identify application vulnerabilities, insecure coding practices, and exposed credentials, and guide remediation prioritization.
- Coordinate third-party penetration testing for internet-facing applications, including scope definition, execution tracking, and remediation management.
- Develop and maintain secure coding standards, architectural patterns, guidance, and architecture artefacts.
- Support risk assessments and alignment with TSA, DORA, and ISO27001 requirements.
- Promote secure coding and security awareness across engineering and development teams.
- Monitor emerging risks and technologies, including AI/LLM application risks, and translate them into practical controls.
Requirements
- At least 5 years of information security experience with a strong focus on application security and DevSecOps.
- Strong understanding of secure software development practices and common application security risks, including the OWASP Top 10.
- Hands-on experience integrating DevSecOps tooling into CI/CD environments such as GitLab pipelines.
- Experience with SAST, DAST, software composition analysis, dependency scanning, and secrets or credentials scanning.
- Experience contributing to application and API security design reviews.
- Experience supporting or participating in penetration testing and tracking remediation.
- Strong understanding of APIs, microservices, cloud-native applications, authentication, and session management.
- Experience performing or supporting risk assessments aligned with recognized frameworks.
- Ability to translate technical vulnerabilities into business-aligned risk and remediation actions.
- Strong collaboration and communication skills with technical and non-technical stakeholders.
- Preferred experience with GitLab security tooling, Azure or GCP cloud-native application security, API security controls, AI/LLM application risks, regulated environments, and Telecoms Security Act requirements.
Benefits
- Flexible working hours and the option to work from home.
- Extensive induction program with experienced mentors and buddies.
- Further development and educational opportunities.
- Global Family Leave Policy.
- Employee Assistance Program.
- Internal inclusion and diversity employee networks.
- Inclusive workplace with recruitment-process adjustments available upon request.
Tech Stack
Categories
About Colt Technology Services
Colt Technology Services provides fiber-based connectivity, internet, voice, security, and data centre/colocation services for enterprises and wholesale carriers. It sells managed network services such as Ethernet, IP access, SD-WAN, and cloud on-ramps delivered over its own metropolitan and long‑haul networks across Europe, Asia, and North America. Founded in 1992 and headquartered in London, it is privately held and operates in 40+ countries.