4 months ago
London, United KingdomSenior
Responsibilities
- Own Flagstone’s application security programme and report its effectiveness to leadership and other stakeholders.
- Formalise and operate a secure development lifecycle, including threat modelling, secure design reviews, security gates, and post-deployment safeguards.
- Run and improve secure code review practices using SAST, DAST, and SCA tooling integrated into code review and development pipelines.
- Coordinate external and execute internal penetration tests, including scoping, logistics, findings triage, and remediation tracking.
- Maintain secure coding standards and own the security champions programme.
- Track and report application vulnerabilities, prioritising them by exploitability and business impact.
- Provide application security expertise during incident response and manage application cyber risk under the Flagstone Risk Framework.
Requirements
- At least 5 years of experience in application security or security engineering with a strong AppSec focus.
- Practical experience embedding security into the SDLC, including threat modelling, secure design review, and direct collaboration with engineering teams.
- Hands-on experience with SAST, DAST, SCA, and pipeline integration.
- Strong knowledge of the OWASP Top 10 and secure coding practices in at least one major production language or framework.
- Experience coordinating penetration testing programmes and tracking remediation.
- Experience with adversarial security testing and securing agentic and AI systems through review and threat modelling.
- Ability to communicate security risk to engineering, product, and senior leadership audiences and influence stakeholders.
- Preferred qualifications include AppSec or offensive-security certifications such as OSCP or CSSLP, AppSec community involvement, financial services experience, security champions programme experience, and exposure to cloud-native application security.
Benefits
- Competitive bonus scheme.
- Flexible benefits budget and salary-sacrifice options.
- Three-month work-from-anywhere scheme, subject to exclusions.
- Mental wellbeing support through Spill.
- £1,000 personal development budget.
- Private healthcare through AXA and a medical cash plan.
- Life insurance and income protection at four times annual salary.
- Matched pension contributions up to 5%.
- 25 days of holiday plus bank holidays, wellbeing days, and volunteering days.
- Enhanced maternity, paternity, and adoption leave.
- Hybrid work arrangement indicated by the #LI-hybrid tag.
