Application Security Specialist

Application Security Specialist

Posted 3 days ago by Whitehall Resources

Negotiable
Inside
Hybrid
Cheshire East, England, United Kingdom

Summary: The Application Security Specialist role involves assessing and enhancing the security of applications throughout their lifecycle, including development, deployment, and operations. This hybrid position requires three days of on-site work in Cheshire and offers an initial 8-month contract. The specialist will conduct security reviews, support secure coding practices, and work closely with DevOps to integrate security into CI/CD pipelines. The role is classified as inside IR35.

Key Responsibilities:

  • Conduct security reviews, threat modelling, and vulnerability assessments.
  • Support secure coding practices and provide guidance to development teams.
  • Operate security scanning tools (SAST/DAST/IAST).
  • Validate remediation of vulnerabilities and track risk reductions.
  • Contribute to secure design standards and best practices.
  • Work with DevOps to embed security into CI/CD pipelines.

Key Skills:

  • Knowledge of OWASP Top 10 and secure development principles.
  • Experience with scanning tools (e.g., SonarQube, Veracode, Fortify).
  • Understanding of cloud security and API/application architecture.

Salary (Rate): undetermined

City: Cheshire East

Country: United Kingdom

Working Arrangements: hybrid

IR35 Status: inside IR35

Seniority Level: undetermined

Industry: IT

Detailed Description From Employer:

Application Security Specialist

Whitehall Resources are looking for an Application Security Specialist. This role is hybrid working with 3 days per week onsite in Cheshire, and the remainder remote working for an initial 8-month contract. ***Inside IR35***

Role Description:

We are looking for an Application Security Specialist to assess and strengthen the security of applications across development, deployment, and operations.

Key Responsibilities

  • Conduct security reviews, threat modelling, and vulnerability assessments.
  • Support secure coding practices and provide guidance to development teams.
  • Operate security scanning tools (SAST/DAST/IAST).
  • Validate remediation of vulnerabilities and track risk reductions.
  • Contribute to secure design standards and best practices.
  • Work with DevOps to embed security into CI/CD pipelines.

Required Skills:

  • Knowledge of OWASP Top 10 and secure development principles.
  • Experience with scanning tools (e.g., SonarQube, Veracode, Fortify).
  • Understanding of cloud security and API/application architecture.