Haystack
← Back to Jobs
Temporary/Casual
Technology
SA

Senior Application Security Consultant (SAST/DAST/OWASP )

SaltFarringdon, Central London🇬🇧United KingdomPosted 24 Aug 2026

Quick Overview

Salary
£500 - £550/mo
Seniority
Mid Senior
Employment type
Temporary/Casual
Work mode
Hybrid
Location
Farringdon, Central London, United Kingdom
Posted
2 days ago
DockerGCPMicroservicesAWSOWASPSonarQubeAzureGitHub ActionsJenkinsKubernetesPenetration TestingPrismaRESTStakeholder Management

Job Description

Senior Application Security Consultant (SAST/DAST/OWASP )/ DevSecOps Security - Banking - London Secure SDLC | SAST | DAST | Threat Modelling | Cloud Security | CI/CD Location:

London (Hybrid - 8 days onsite per month) Contract: 12 Months + extension Rate: £500-£550 per day (Umbrella) The Opportunity We're looking for an experienced Senior Application Security Consultant / DevSecOps Security Architect to join a high-performing Cyber Security function within a large enterprise technology environment.

Working alongside software engineering, cloud, architecture and DevOps teams, you'll play a key role in embedding security throughout the Software Development Lifecycle, ensuring applications are designed, developed and deployed securely.

This is an excellent opportunity for someone passionate about Secure-by-Design, DevSecOps and modern Application Security within a large-scale cloud environment.

Key Responsibilities Lead application security reviews across business-critical applications and cloud platforms.<br />Conduct security architecture and secure design reviews.<br />Perform application security risk assessments and define security requirements.<br />Lead Threat Modelling workshops using STRIDE, MITRE ATT&amp;CK or similar methodologies.<br />Embed Secure SDLC principles into engineering teams.<br />Integrate security tooling into CI/CD pipelines and DevSecOps processes.<br />Review and analyse SAST, DAST and Software Composition Analysis (SCA) findings.<br />Work closely with development teams to prioritise vulnerability remediation.<br />Define security testing requirements and support penetration testing activities.<br />Produce security standards, technical guidance and best practice documentation.<br />Act as the Application Security SME across multiple technology programmes.Essential Skills Application Security Secure Software Development Lifecycle (SSDLC)<br />OWASP Top 10<br />Secure Coding<br />Secure Design Reviews<br />API Security<br />REST APIs<br />Microservices Security<br />Application Security Risk AssessmentsThreat Modelling STRIDE<br />MITRE ATT&amp;CK<br />Security Architecture<br />Risk AssessmentsDevSecOps CI/CD Security<br />GitHub Actions<br />GitLab<br />Jenkins<br />Azure DevOps<br />Security Automation<br />Shift Left SecuritySecurity Testing SAST<br />DAST<br />SCA<br />Vulnerability Management<br />Penetration TestingCloud Security AWS, Azure or GCP<br />Kubernetes<br />Docker<br />Container Security<br />Cloud Security Best PracticesSecurity Tooling Experience with one or more of:

Checkmarx<br />Fortify<br />SonarQube<br />Veracode<br />Semgrep<br />Burp Suite<br />OWASP ZAP<br />Snyk<br />Trivy<br />Prisma Cloud<br />Aqua<br />WizIdeal Background You'll ideally have: 8+ years in Cyber Security<br />Strong Application Security or DevSecOps experience<br />Experience working directly with software engineering teams<br />Experience embedding security into CI/CD pipelines<br />Strong knowledge of Secure SDLC<br />Experience conducting Threat Modelling sessions<br />Excellent stakeholder management and communication skills<br />Previous experience within Banking, Financial Services, Insurance or another highly regulated enterprise environmentContract Details 12-month contract<br />£500-£600 per day (Umbrella)<br />Hybrid working - 8 days onsite per month in London<br />Immediate interview availability preferred*Rates depend on experience and client requirements

Similar jobs