- Company Name
- Morson Edge (Technology)
- Job Title
- Lead Application Security Consultant (AppSec)
- Job Description
-
**Job title**
Lead Application Security Consultant (AppSec)
**Role Summary**
Embed within technology delivery teams of a banking organization undergoing a major technology transformation. Drive the adoption of secure software development practices across a hybrid stack of modern web, microservices, legacy platforms, and API‑driven architectures. Lead security integration in agile delivery, shape application security assurance processes, and automate security controls within CI/CD pipelines.
**Expectations**
- Deliver secure, scalable software at pace.
- Act as the on‑site security lead for one or more delivery teams.
- Influence culture to share security ownership across engineering, product, and business stakeholders.
- Translate industry best practices and regulatory requirements into actionable, pragmatic guidance.
**Key Responsibilities**
- **Security Integration in Delivery** – Participate in stand‑ups, sprint planning, technical reviews; embed security checkpoints into the software development lifecycle.
- **Secure Coding & Architecture** – Promote secure coding standards, conduct threat modelling, and review secure architecture designs for applications and APIs.
- **Automated Security Testing** – Implement, tune, and maintain SAST, DAST, and other automated security scans in CI/CD pipelines.
- **Risk & Control Assessments** – Perform security reviews, risk assessments, and control evaluations for new technology initiatives; support supplier security due diligence and privacy impact assessments.
- **Metrics & Reporting** – Define and track security metrics, produce dashboards and reports for stakeholders.
- **Templates & Tooling** – Develop reusable templates, toolchains, and workflows that streamline secure delivery.
- **Stakeholder Engagement** – Build relationships with developers, architects, product owners, delivery managers; provide clear security guidance and facilitate knowledge transfer.
**Required Skills**
- Application security expertise in modern development environments.
- Integration of security controls into software development lifecycles and CI/CD pipelines.
- Proficiency with static (SAST) and dynamic (DAST) analysis tools.
- Threat modelling, secure architecture, and secure coding practices.
- Security risk assessment across applications, APIs, and platforms.
- Knowledge of cloud or distributed system security concepts.
- Strong written and verbal communication; ability to explain risks in business terms.
- Collaborative mindset; experience working directly with engineering teams to embed security.
- Familiarity with risk‑management practices in regulated financial environments.
**Required Education & Certifications**
- Bachelor’s degree (or equivalent) in Computer Science, Information Security, or related field.
- Relevant security certifications preferred: CISSP, CISM, OSCP, CEH, CREST‑AppSec, or equivalent application‑security credentials.
---