- Company Name
- Handelsbanken
- Job Title
- Application Security Consultant - 6M Contract
- Job Description
-
**Job title:** Application Security Consultant – 6‑Month Contract
**Role Summary:**
Act as the embedded security lead for a delivery team on a major technology transformation program. Own the end‑to‑end application security assurance across a hybrid stack (Java/React, J2EE, RPG/JSP on z/OS, API‑driven services). Drive secure coding practices, risk assessments, and secure change processes while collaborating closely with engineers, product managers, and stakeholders to enable rapid, secure delivery.
**Expectations:**
- Deliver measurable improvement in the team's security posture within the contract period.
- Operate independently from broader security specialists, applying depth in threat modelling, secure architecture, and regulatory compliance.
- Communicate complex security concepts clearly to both technical and non‑technical audiences.
**Key Responsibilities:**
- Lead risk & control assessments (including supplier due diligence, privacy impact assessments, and project security).
- Identify, articulate, and manage application security risks; develop treatment plans and ensure controls are implemented on schedule.
- Interpret and apply information security best practices and UK regulatory requirements to new products and processes.
- Serve as subject‑matter expert on the bank’s secure change process, guiding the workstream through approvals and gates.
- Build and maintain trusted relationships with developers, testers, product managers, delivery leads, and tech leads.
- Participate in daily stand‑ups, PI planning, and working groups to embed security within the SDLC.
**Required Skills:**
- Secure coding and threat modelling expertise for multi‑language environments (Java, JavaScript/React, J2EE, RPG/JSP).
- Hands‑on experience with SAST/DAST tools and integrating security controls into CI/CD pipelines.
- Deep knowledge of risk management frameworks (including 3‑LoD model) and information security governance.
- Proficiency in UK financial regulatory landscape (e.g., FCA, MiFID II, GDPR).
- Strong communication and stakeholder management skills.
- Ability to work autonomously, own outcomes, and seek support when knowledge gaps arise.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Technology, or related field.
- Relevant certifications such as CISSP, CISA, CISM, or ISO/IEC 27001 Lead Implementer preferred.
---