Application Security Consultant - Reading, United Kingdom - Project People

Tom O´Connor

Posted by:

Tom O´Connor

beBee Recruiter


Description

Application Security Consultant/ Lead

Permanent

Reading/Hybrid - 2 Days per week onsite

Duties and responsibilities:


  • Develop threat models and maturity assessments that can be used to integrate security requirements into projects & operations
  • Advocate for AppSec and DevSecOps from research conducted into modern threats and new technologies such containerisation and serverless computing
  • Liaise with security architects and other business units to communicate security practices and processes
  • Support identification, training, and partnership with champions for security to build a security first culture
  • Support security champions by helping them assess risk, learn to identify architectural gaps, and similar activities

Knowledge and experience

  • Experience with the full secure software or systems development life cycle, including requirements analysis, design, integration, testing, and implementation
  • Knowledge of Application Security, DevSecOps, integrating security into CI/CD
  • Experience collaborating with developers to explain testing vulnerabilities so they can be resolved
  • Experience with industry security standards and regulations (ISO 27001/02, NIST 800 series, GDPR, etc.)
  • Knowledge of security and risk management techniques as well as emerging threats and vulnerabilities
  • Knowledge of OWASP, Static and Dynamic Analysis, vulnerability management
  • Experience in software design, or knowledge of modern DevOps processes
  • Ability to develop threat models and participate in security walkthroughs
  • Strong leadership and facilitation skills with an ability to build relationships with stakeholders
  • Highly selfmotivated, selfdirected and attentive to detail
  • A University Degree in engineering, computer science or similar technical related area, with a minimum of 68 years' experience in AppSec role
  • Relevant security certification(s), preferably in AppSec, including but not limited to CISSP, CCSLP, GIAC, OCSP, GPEN, etc. will be good to have
Project People is acting as an Employment Agency in relation to this vacancy.

More jobs from Project People