Security Architect - DevSecOps + Application Security
Colt Technology Services · London, GB · United Kingdom · On-site
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Colt provides network, voice and data centre services to thousands of businesses around the world, allowing them to focus on delivering their business goals instead of the underlying infrastructure.
Why we need this role
We are looking for a Security Architect specialising in Application Security and DevSecOps to join the Security and Resilience – Security Architecture team.
This role will act as a subject matter expert for secure software development and DevSecOps practices, supporting the integration of security controls into Colt’s development pipelines and ensuring applications are secure by design and by default.
The successful candidate will work closely with Engineering, DevOps, Cloud, SOC and Risk teams to embed security throughout the software development lifecycle, ensuring that Colt’s applications and services are designed, built and tested with security as a core requirement.
The role combines:
Application security architecture and design
DevSecOps pipeline integration and tooling
Security assurance and governance across internally developed applications
You will play an important role in supporting:
Secure software development practices across Colt
Security integration into CI/CD pipelines (GitLab)
Reduction of vulnerabilities through automated scanning and testing
Assurance of internet-facing applications through structured penetration testing activities
What you will do
Provide security architecture expertise for application security and DevSecOps, supporting standards and best practices across the software development lifecycle
Contribute to the target architecture for secure software development, aligned to Colt’s Secure by Design principles
Support the integration of security controls into CI/CD pipelines (GitLab), including automated testing and policy enforcement
Design and implement application security controls, including:
Static Application Security Testing (SAST)
Dynamic Application Security Testing (DAST)
Software Composition Analysis (SCA) / dependency scanning
Secrets and credentials scanning
Work with engineering teams to ensure consistent adoption of DevSecOps practices and secure coding approaches
Support security architecture reviews and assurance activities for internally developed applications and services
Identify and help reduce risks related to application vulnerabilities, insecure coding practices and exposed credentials
Support the coordination and execution of third-party penetration testing of Colt’s internet-facing applications
Assist in defining test scope, tracking execution and ensuring remediation of findings is properly managed
Provide guidance to engineering teams on remediation and prioritisation of vulnerabilities
Contribute to the development and maintenance of secure coding standards and architectural patterns
Ensure alignment with regulatory requirements such as TSA, DORA and ISO27001 in application design and…