Senior Application Security Specialist
Biometric Talent
Stoke-on-Trent, United Kingdom
1 month ago
Role details
Contract type
Permanent contract Employment type
Full-time (> 32 hours) Working hours
Regular working hours Languages
English Experience level
Senior Compensation
£ 80KJob location
Stoke-on-Trent, United Kingdom
Tech stack
.NET
Artificial Intelligence
Software System Penetration Testing
Burp Suite
Code Review
Continuous Integration
Linux
Github
Python
SQL Injection
Web Applications
Software Security
Cross-Site Scripting (XSS)
Gitlab
Devsecops
Docker
Static Application Security Testing
Vulnerability Analysis
Go
Dynamic Application Security Testing
Job description
- Reviewing application code to identify and remediate security vulnerabilities across modern web applications
- Performing and supporting web application penetration testing, focused on real-world risk rather than tick-box security
- Designing, building and improving security tooling and automation for tasks such as code review and vulnerability detection
- Working closely with developers to advise on secure design, remediation approaches and best practice
- Supporting the shift from manual-heavy processes to scalable, automated and AI-assisted security workflows
- Acting as a senior technical voice within the team, contributing to decisions, mentoring others and influencing direction
- Participating in on-call activity as required, supporting high-availability systems, Should we both wish to proceed, we will submit your details to the client and be in touch regarding the outcome and any further steps.
Requirements
This role suits a senior, hands-on security professional with a strong development background who enjoys solving complex problems and engaging directly with engineers., * Strong coding experience, particularly in Golang and/or Python (experience with .NET also beneficial)
- Proven application security experience, with a focus on web application vulnerabilities rather than infrastructure-only security
- Hands-on experience with code review, penetration testing, and identifying issues such as XSS, SQL injection and logic flaws
- Experience building or improving security automation and tooling (DevSecOps mindset)
- Familiarity with tools such as Burp Suite, SAST/DAST tools, GitHub/GitLab, Linux and Docker
- The confidence and communication skills to work with large, opinionated developer groups and challenge constructively
- A pragmatic, delivery-focused mindset suited to a fast-moving, commercial environment
- Security certifications (e.g. OSCP, OSWE, DevSecOps) are desirable but not essential - practical capability matters more, * Application Security
- Python
- .Net
- Burp Suite
- CI/CD
- GoLang
Benefits & conditions
- Performance-Based Bonus
- Annual bonus paid in two instalments (April & September), based on company and personal performance.
- Pension Scheme
- Employer-matched contributions of up to 7.5%.
- Hybrid Working
- Minimum 2 days per week in the office, with flexibility on which days.
- Flexible Working Hours
- 40-hour workweek with flexibility in how hours are structured.
- Generous Annual Leave
- 25 days holiday + your birthday off, plus bank holidays. Option to buy or sell up to 5 additional days.
- Free Gym Membership
- Available to all employees.
- No Visa Sponsorship Available for this role.