Negotiable
Inside
Hybrid
Cheshire East, England, United Kingdom
Summary: The Application Security Specialist role involves assessing and enhancing the security of applications throughout their lifecycle, including development, deployment, and operations. This hybrid position requires three days of on-site work in Cheshire and offers an initial 8-month contract. The specialist will conduct security reviews, support secure coding practices, and work closely with DevOps to integrate security into CI/CD pipelines. The role is classified as inside IR35.
Key Responsibilities:
- Conduct security reviews, threat modelling, and vulnerability assessments.
- Support secure coding practices and provide guidance to development teams.
- Operate security scanning tools (SAST/DAST/IAST).
- Validate remediation of vulnerabilities and track risk reductions.
- Contribute to secure design standards and best practices.
- Work with DevOps to embed security into CI/CD pipelines.
Key Skills:
- Knowledge of OWASP Top 10 and secure development principles.
- Experience with scanning tools (e.g., SonarQube, Veracode, Fortify).
- Understanding of cloud security and API/application architecture.
Salary (Rate): undetermined
City: Cheshire East
Country: United Kingdom
Working Arrangements: hybrid
IR35 Status: inside IR35
Seniority Level: undetermined
Industry: IT
Application Security Specialist
Whitehall Resources are looking for an Application Security Specialist. This role is hybrid working with 3 days per week onsite in Cheshire, and the remainder remote working for an initial 8-month contract. ***Inside IR35***
Role Description:
We are looking for an Application Security Specialist to assess and strengthen the security of applications across development, deployment, and operations.
Key Responsibilities
- Conduct security reviews, threat modelling, and vulnerability assessments.
- Support secure coding practices and provide guidance to development teams.
- Operate security scanning tools (SAST/DAST/IAST).
- Validate remediation of vulnerabilities and track risk reductions.
- Contribute to secure design standards and best practices.
- Work with DevOps to embed security into CI/CD pipelines.
Required Skills:
- Knowledge of OWASP Top 10 and secure development principles.
- Experience with scanning tools (e.g., SonarQube, Veracode, Fortify).
- Understanding of cloud security and API/application architecture.