Overview
The Contract Application Security Specialist will be instrumental in embedding secure development practices across a global engineering organization's software and hardware products. Collaborating closely with engineers and leadership, the specialist will drive secure software development lifecycle practices, lead threat modeling efforts, assess vulnerabilities, and ensure compliance with the EU Cyber Resilience Act. This role is a long-term commitment offered on an initial six-month contract, with the possibility of six-month renewals.
Responsibilities
- Drive the implementation of secure software development lifecycle (SDLC) practices.
- Lead threat modeling sessions to identify potential security risks.
- Assess vulnerabilities within applications and systems.
- Support alignment with regulatory compliance, particularly the EU Cyber Resilience Act.
- Engage with software teams to communicate security requirements effectively.
- Work with application security tooling, focusing on SCA and SAST methods.
- Promote secure coding principles and awareness of OWASP standards.
- Collaborate with cross-functional teams on continuous improvement of security practices.
Requirements
- Strong hands-on experience with Application Security tooling, especially SCA and SAST.
- Deep understanding of secure software development practices.
- Extensive experience with threat modeling techniques.
- Strong knowledge of secure coding principles and familiarity with OWASP.
- Ability to effectively engage and communicate with software engineering teams.
- Relevant backgrounds may include AppSec, Product Security, Ethical Hacking, DevSecOps, or Penetration Testing.
- Experience with electronics, hardware, or robotics is a plus but not essential.
- Availability for regular office visits, including 1-2 days per week in Gloucestershire.