Security Design Engineer; Application Security
Listed on 2026-01-12
-
IT/Tech
Cybersecurity, Systems Engineer
Location: City of Edinburgh
Security Design Engineer (Application Security)
Security Design Engineers manage end‑to‑end solution design and are responsible for delivering design documents in line with functional and non‑functional business requirements, strategies, principles, standards, and patterns. Alongside the creation of high‑level designs, Security Design Engineers publish new architecture patterns, key decisions, design deviations, and technical risks where appropriate. They collaborate with stakeholders, including the relevant enterprise architect, to ensure design decisions align with strategic direction.
Security Design Engineers present and share solutions at design authorities and senior leadership meetings, providing technical thought leadership and direction to aligned projects. They may act as subject‑matter experts and consultants related to programmes. This position sits between an Application Architect and Security consultant, with a focus on Application Architecture. It is a contract role up until November with potential extension, based in either Edinburgh or Sheffield with three days a week required in office.
Skills
- Hands‑on experience securing modern application architectures (microservices, cloud‑native, containerized environments).
- Knowledge of SCA tools and methodologies (e.g., dependency analysis, open‑source license compliance, vulnerability triage, supply‑chain risk management).
- Deep experience implementing and optimising AST capabilities, including SAST, DAST, IAST, MAST and container/K8s security scanning.
- Demonstrated success designing and integrating security testing pipelines within CI/CD environments (Git Hub Actions, Git Lab, Jenkins, Azure Dev Ops, etc.).
- Strong background in threat modelling, secure SDLC design, and establishing risk‑based security policies for code, dependencies, and build systems.
- Ability to evaluate, select, and architect App Sec technologies, including enterprise SCA/AST platforms, SBOM solutions, and vulnerability management workflows.
- Experience collaborating with engineering teams to prioritise and remediate vulnerabilities, provide secure coding guidance, and enable developer‑centric security practices.
- Familiarity with industry frameworks and standards (OWASP SAMM, ASVS, CSA, NIST SSDF, supply‑chain security frameworks such as SLSA).
- Experience across vulnerability and exposure management including detection, analysis, management and resolution activities.
Job Title
:
Security Design Engineer (Application Security)
Location
:
Edinburgh, UK
Rate/Salary
: 400.00 – 450.00 GBP Daily
Job Type
:
Contract
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: