FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in application security architecture, including threat modeling, secure design principles, and security testing strategies. Proficient in defining security requirements for web and mobile applications, APIs, and cloud-native architectures while ensuring compliance with industry standards.
Highest-signal resume keywords
Application Security ArchitectureThreat ModelingSecure SDLCSecurity Testing StrategiesCloud-Native Architecture
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Threat Modeling TechniquesSecurity Requirements DefinitionApplication Security TestingIdentity and Access ManagementData Protection ControlsOWASP Top 10Secure ConfigurationAPI SecurityMicroservices SecuritySecure Design Principles
Soft Skills
Strong Written CommunicationStrong Verbal Communication
Tools & Technologies
Burp SuiteOWASP ZAPSnykSonarQubeCI/CD PipelinesDevSecOps
Certifications & Qualifications
CISSPCSSLPSABSACRESTOSWE
Industry Keywords
Regulated EnvironmentNISTISO 27001CISPCI DSSMobile Application SecurityWeb Application SecurityAPI SecurityApplication ShieldingContainer Security
Tech Stack
Tools & technologiesAndroidCloudGraphQLiOSKubernetesMicroservicesSDLC
About the role
Key responsibilities & impact- Provide security architecture support to mobile and web application initiatives from discovery and design through build, testing, release and operation
- Partner with solution architects, software engineers, product teams, delivery leads and third parties to embed security early while considering pace, cost, usability and quality
- Produce and maintain high-level and detailed security designs, security requirements, architecture decisions, patterns and assurance evidence
- Lead application threat modelling using techniques such as STRIDE, documenting threats, attack paths, trust boundaries, mitigations and residual risks
- Assess web applications, native and cross-platform mobile applications, APIs, microservices, identity flows, cloud services and third-party integrations
- Define security requirements for authentication, authorisation, session management, secrets, cryptography, data protection, API security, logging, monitoring, resilience and secure configuration
- Apply OWASP Top 10, OWASP ASVS, OWASP MASVS and secure-by-design principles
- Guide teams on secure mobile and web design
- Advise on application security testing strategy, including SAST, DAST, SCA, secrets scanning, API testing, mobile application testing, IAST and penetration testing
- Support integration of security controls and automated testing into CI/CD pipelines, including quality gates and exception routes
- Review security findings, challenge false positives, prioritise remediation and support pragmatic corrective actions
- Produce penetration test scopes and security test plans, coordinate testing and assess remediation
- Identify and communicate security risks, control gaps and non-compliance, supporting accountable owners in reaching informed risk positions
- Contribute to reusable security patterns, standards, guardrails and reference architectures
- Coach engineering and architecture communities on secure design, threat modelling and secure development practices
Requirements
What you’ll need- Significant experience in application security architecture, product security or security engineering within an enterprise environment
- Security design experience across modern web applications, mobile applications and APIs
- Strong knowledge of common web, mobile and API threats and appropriate security controls
- Practical experience of threat modelling and translating findings into clear, traceable security requirements
- Good understanding of secure SDLC, DevSecOps, Agile delivery and CI/CD security
- Experience defining and interpreting application security testing, including SAST, DAST, SCA, API, mobile and penetration testing
- Knowledge of application identity and access management, including authentication, authorisation, federation, tokens and session security
- Understanding of cloud-native architecture, including containers, serverless services and microservices
- Experience assessing data flows and defining controls for sensitive data
- Strong written and verbal communication skills, with the ability to provide clear, pragmatic and risk-based advice
- Knowledge of web and API security, including HTTP/S, browser controls, CORS, CSP, REST and GraphQL
- Knowledge of iOS and Android security, including secure storage, permissions, deep links, transport security and application integrity
- Experience with application security tools such as Burp Suite, OWASP ZAP, Snyk, SonarQube or equivalent
- Working knowledge of a mainstream programming or scripting language
- Knowledge of security logging, monitoring and incident response for customer-facing applications
- Knowledge of OWASP, NIST, ISO 27001, CIS and PCI DSS frameworks and standards
- Experience securing high-volume digital services in a regulated environment is nice to have
- Knowledge of app-store releases, mobile attestation, application shielding or runtime protection is nice to have
- Familiarity with container security, Kubernetes, infrastructure as code or policy as code is nice to have
- Experience developing application security patterns, standards or developer enablement programmes is nice to have
- Relevant security certification such as CISSP, CSSLP, SABSA, CREST or OSWE is nice to have
- Experience in lottery, gaming, payments, retail, finance or another regulated sector is nice to have
Benefits
Comp & perks- Company Bonus Scheme
- Matched pension contributions up to 8.5%
- 26 days annual leave + 2 Life Days (and bank holidays)
- Single Private Health Cover
- Complimentary Private Medical
- Income Protection
- Flexible Benefits – EV Scheme, Money Coach, Will Writing, Mortgage Advice, Dental and Eye Care Schemes
- Enhanced Family Leave (Maternity, Paternity, Adoption)
- Wellness Allowance £500
- Employee Assistance Programme
- Discounted Health Assessments
- Volunteering Days
- Matched Funding
- Interview offered to disabled applicants who meet the essential requirements
- Assistance or adjustments available during the application process
