About this role
Leadership & Programme Management
• Own and evolve the application security strategy, testing roadmap, and service catalogue aligned to business and regulatory requirements. • Lead, and mentor a team of AppSec engineers and penetration testers; manage workload, quality, and career development. • Act as the primary escalation point for application security risk decisions across engineering and product leadership. • Drive continuous improvement in AppSec tooling, methodologies, and coverage metrics. • Represent the AppSec function in client discussions, audits, risk committees, and vendor assessments.
Web Application Penetration Testing
• Oversee and conduct advanced web application penetration testing including complex business logic, authentication/authorisation flaws, API abuse, and chained attack scenarios. • Define and maintain testing methodology aligned to OWASP Testing Guide, PTES, and client-specific requirements. • Review and quality-assure penetration test reports produced by the team before delivery to clients or stakeholders. • Drive responsible disclosure and coordinated vulnerability management for critical findings.
Mobile Application Security
• Lead mobile security assessments for Android and iOS—static/dynamic analysis, reverse engineering, and runtime manipulation (Frida, objection, Drozer). • Establish and maintain mobile security standards aligned to OWASP MASVS and MSTG across product teams. • Guide development teams on secure mobile architecture: certificate pinning, secure storage, and inter-process communication security.
Source Code Review
• Conduct and oversee manual source code security reviews across multiple languages (Java, Python, JavaScript/TypeScript, Go, C#, and others). • Define code review standards and integrate SAST tooling (Semgrep, Checkmarx, Veracode, SonarQube) into development workflows. • Provide actionable, developer-centric findings with clear severity ratings and remediation guidance. • Track remediation SLAs and report on code security posture trends over time.
DevSecOps Integration
• Lead integration of security tooling (SAST, DAST, SCA, container scanning, API security) into CI/CD pipelines (Jenkins, GitHub Actions, and similar). • Define pipeline security gates, policy-as-code standards, and developer feedback loops to shift security left. • Oversee IaC security (Terraform, CloudFormation), secrets management, and supply-chain security controls. • Collaborate with platform and cloud engineering on secure architecture, baseline hardening, and runtime protection.
Governance, Risk & Compliance
• Own the application security risk register; track, prioritise, and report on vulnerability posture to senior leadership. • Ensure AppSec activities align with OWASP ASVS, NIST 800-53, ISO 27001, PCI-DSS, and SOC 2. • Define and track AppSec KPIs: mean time to remediation, critical findings per release, and coverage rates. • Translate regulatory and client security requirements into testable engineering controls.
AI / GenAI Security
• Assess and mitigate risks in AI/GenAI applications: LLM-based apps, RAG pipelines, agentic workflows (OWASP LLM Top 10, prompt injection, data leakage).
Incorporate AI security testing into standard AppSec assessment methodologies.
Leadership & Programme Management
• Own and evolve the application security strategy, testing roadmap, and service catalogue aligned to business and regulatory requirements. • Lead, and mentor a team of AppSec engineers and penetration testers; manage workload, quality, and career development. • Act as the primary escalation point for application security risk decisions across engineering and product leadership. • Drive continuous improvement in AppSec tooling, methodologies, and coverage metrics. • Represent the AppSec function in client discussions, audits, risk committees, and vendor assessments.
Web Application Penetration Testing
• Oversee and conduct advanced web application penetration testing including complex business logic, authentication/authorisation flaws, API abuse, and chained attack scenarios. • Define and maintain testing methodology aligned to OWASP Testing Guide, PTES, and client-specific requirements. • Review and quality-assure penetration test reports produced by the team before delivery to clients or stakeholders. • Drive responsible disclosure and coordinated vulnerability management for critical findings.
Mobile Application Security
• Lead mobile security assessments for Android and iOS—static/dynamic analysis, reverse engineering, and runtime manipulation (Frida, objection, Drozer). • Establish and maintain mobile security standards aligned to OWASP MASVS and MSTG across product teams. • Guide development teams on secure mobile architecture: certificate pinning, secure storage, and inter-process communication security.
Source Code Review
• Conduct and oversee manual source code security reviews across multiple languages (Java, Python, JavaScript/TypeScript, Go, C#, and others). • Define code review standards and integrate SAST tooling (Semgrep, Checkmarx, Veracode, SonarQube) into development workflows. • Provide actionable, developer-centric findings with clear severity ratings and remediation guidance. • Track remediation SLAs and report on code security posture trends over time.
DevSecOps Integration
• Lead integration of security tooling (SAST, DAST, SCA, container scanning, API security) into CI/CD pipelines (Jenkins, GitHub Actions, and similar). • Define pipeline security gates, policy-as-code standards, and developer feedback loops to shift security left. • Oversee IaC security (Terraform, CloudFormation), secrets management, and supply-chain security controls. • Collaborate with platform and cloud engineering on secure architecture, baseline hardening, and runtime protection.
Governance, Risk & Compliance
• Own the application security risk register; track, prioritise, and report on vulnerability posture to senior leadership. • Ensure AppSec activities align with OWASP ASVS, NIST 800-53, ISO 27001, PCI-DSS, and SOC 2. • Define and track AppSec KPIs: mean time to remediation, critical findings per release, and coverage rates. • Translate regulatory and client security requirements into testable engineering controls.
AI / GenAI Security
• Assess and mitigate risks in AI/GenAI applications: LLM-based apps, RAG pipelines, agentic workflows (OWASP LLM Top 10, prompt injection, data leakage).
Incorporate AI security testing into standard AppSec assessment methodologies.
Skills & Capabilities
Non-Negotiable – Must Have
• 6–8+ years of progressive experience in application security, penetration testing, or a closely related security engineering discipline. • Expert-level web application penetration testing: complex chained attacks, API abuse, OAuth/OIDC flaws, deserialization, advanced injection techniques. • Hands-on mobile security testing for Android and iOS (static/dynamic analysis, Frida scripting, MASVS/MSTG alignment). • Strong source code review skills across at least two major languages—able to identify security defects manually and via SAST tooling. • Proven experience embedding security into CI/CD pipelines and operating SAST/DAST/SCA tooling in a DevSecOps environment. • Experience managing or technically leading a team of security engineers or penetration testers. • Ability to communicate complex security risk credibly to technical and executive audiences.
Good to Have
• Certifications: eWPTX, OSCP, OSWE, BSCP (Burp Suite Certified Practitioner), GWAPT, GWEB, GPEN, CPENT, or equivalent offensive security credentials. • Cloud security experience across AWS, Azure, or GCP (IAM, network security, SIEM integration). • Knowledge of AI/GenAI security risks and securing ML pipelines (MLSecOps). • Threat modelling frameworks: STRIDE, PASTA, attack trees. • Experience in client-facing security consulting or managed security services.
Leadership & Soft Skills
• Proven ability to build, mentor, and retain high-performing security teams. • Strong programme management—able to manage concurrent assessments, client deliverables, and operational priorities. • Influencing skills to drive secure-by-design adoption across engineering organisations without being a pure gatekeeper. • Commercial awareness: able to balance thoroughness, risk, and delivery timelines.
Qualifications
• Bachelor’s or master’s degree in Computer Science, Information Security, Engineering, or equivalent practical experience. • 6–8+ years of relevant experience in application security, penetration testing, or DevSecOps with progressive responsibility. • 1–2+ years in a team lead or management capacity within a security function. • Offensive security certifications (eWPTX, OSCP, OSWE, or equivalent) strongly preferred.