Who we’re looking for Our clients Cyber Security team is looking for a Cybersecurity engineer with expertise in Application Security domain, who will be responsible to define consistent Secure Software Development Lifecycle practices for all technology projects throughout the planning and delivery cycles that assure application security vulnerabilities are mitigated to tolerable levels.
The successful candidate will have very strong application security, web application development experience and team leadership skillsto join a growing Information Security team and assist with the operation of the AppSec function.
About Us Our client is a global investment manager. They help institutions, intermediaries and individuals around the world invest money to meet their goals, fulfil their ambitions, and prepare for the future.
They have around 5,000 people on six continents, have been around for over 200 years but keep adapting as society and technology changes. What doesn’t change is the commitment to helping clients, and society, prosper.
What you’ll do In this position, you are a passionate and talented application security engineer with very deep understanding of OWASP, CWE 25, Data Protection, Access management, software vulnerabilities, best practices design and threat modelling skills, who can work in a dynamic environment. You must be dedicated to able to work with developers in producing secure code in short time frames and be willing to go beyond the standard routine. Your primary responsibilities includes:
Work as part of a team of software and security engineers to design/maintain and build best-in-class product security tools and services.
Technical point of contact for product teams as it relates to automation, CI/CD, and Product Application Security Operations
Using approved AI models and cyber harnesses to assess application code for business logic weaknesses, misconfiguration and vulnerabilities.
Build tools and automation scripts that enable developers to easily consume security services delivered by Security Engineering and Automation team
Responsible for security product QA and Testing
Build strong relationships with product development teams
Run software composition analysis (SCA) tools
To understand and explain penetration testing findings to the software engineering teams helping them to triage the findings and explaining how to mitigate the risks
To articulate business risk when assessing software vulnerabilities
Continuously improve the operations of SAST, DAST and IaC security tools
Continuously improve the operations of Web Application Firewalls (WAF) or IDS
Continuously improve the coverage of security tooling in Cloud environments e.g. Microsoft Azure & Amazon AWS
The knowledge, experience and qualifications you need
Computer Science / Cyber Security Degree
Application Development background
Azure DevOps experience
Prior experience in using AI models and cyber harnesses to support security evaluation of application and software code.
GitHub, Copilot, Codex, OWASP Top 10 for Agentic AI, AI skills development and security triage.
Ability to code in at least one programming language e.g. Python/JavaScript/CSharp/Powershell
Prior experience working in a large organisation or Financial Services is an advantage
Excellent analytical skills with attention to details
CISSP/CSSLP/CEH/OSCP or similar certification
Presentation skills - ability to present complex solutions to a less technical audience
Team-player interpersonal skills, with the ability to communicate and collaborate effectively with different people in a variety of roles
Passionate about developing a career in Information Security
Excellent command of the English language, both written and spoken
What you’ll be like
Passionate about mastering and innovating best practice in business analysis
Inspiring and collaborative leader, model of agile leadership approach
Friendly, approachable, enjoys working with people from a variety of backgrounds
Capable of remaining positive when under pressure
Continuous improvement mind-set, challenges the status quo and seeks self improvement
Problem solver, comfortable taking the initiative in challenging and ambiguous circumstances
For our customer a major utilities business we are seeking an Application Security Engineer for a project within the ITSM / CMDB Role is 6 months + extensionPrague based Key Skills 1. Tenable WAS / DA
At SGI, putting people first doesn't just make us a great company to work with; it makes us a great company to work for. From incredible reward schemes and opportunity-dense career paths to an empower