- Company Name
- Talent Smart Limited
- Job Title
- Security Design Engineer (AppSec)
- Job Description
-
**Job Title:**
Security Design Engineer (AppSec)
**Role Summary:**
Design and deliver secure, architecture‑aligned solutions across complex technology environments within a large financial services transformation program. Act as an application‑security subject‑matter expert, integrating security into modern application stacks and CI/CD pipelines while providing strategic guidance and risk‑based decision making.
**Expectations:**
- Complete a 6‑month IR35 contract with up to 3 office days per week.
- Deliver high‑quality architecture artefacts, risk assessments, and design documents.
- Influence strategic architecture and secure design decisions across the enterprise.
- Communicate effectively with technical and non‑technical stakeholders, including design authorities and senior leadership.
**Key Responsibilities:**
- Own end‑to‑end secure solution design, including architecture patterns, design decisions and risk assessments.
- Partner with enterprise and solution architects to ensure alignment with strategic architecture.
- Provide technical leadership and Act as the AppSec SME for delivery teams.
- Design and embed security into modern application stacks and CI/CD pipelines.
- Present designs and recommendations to design authorities and senior stakeholders.
- Identify control gaps, develop remediation plans, and manage residual risk.
- Support governance, peer review and architectural assurance processes.
- Integrate AppSec tools and processes into development workflows.
**Required Skills:**
- Extensive experience in application security for cloud‑native, microservices, containerized and Kubernetes environments.
- Proficiency with SAST, DAST, IAST, MAST, SCA, SBOMs, and supply‑chain security.
- Demonstrated ability to integrate security testing into CI/CD platforms (GitHub Actions, GitLab, Jenkins, Azure DevOps).
- Expertise in threat modelling, secure SDLC design, and risk‑based security policy development.
- Knowledge of vulnerability and exposure management, network segmentation, logging, and scanning.
- Familiarity with industry frameworks: OWASP SAMM/ASVS, NIST SSDF, SLSA, CSA.
- Strong communication skills for translating complex security concepts to diverse audiences.
- Experience working in large, complex IT transformation programmes.
- Tool proficiency: Checkmarx, Invicti, Snyk, Black Duck, Tenable (or equivalent), BizzDesign, Archi, UML, Jira, Confluence.
**Required Education & Certifications:**
- Degree in Cybersecurity, Computer Science, Software Engineering or related field.
- Industry‑recognized security certification (e.g., CISSP, CISM, equivalent).
- Additional architecture or security framework certification (e.g., SABSA, TOGAF) preferred.
Edinburgh, United kingdom
On site
08-01-2026