⚡ New

Application Security & Testing Analyst

Alexander Mann Solutions - Public Sector Resourcing

CardiffFull-timeMid LevelOn-site

Job Description

On behalf of Companies House, we are looking for a Application Security & Testing Analyst Inside IR35 for a 6 months contract based REMOTELY.

Companies House drives confidence in the economy and makes the UK a great place to start, and run, a business.

SC Clearance is an essential requirement for this role, as a minimum you must be willing & eligible to undergo checks. Please note, due to the exceptional requirements of this position (short-term nature of this role and speed at which we require a postholder in situ) preference may be given to candidates who meet all of the essential criteria and hold active SC clearance.

As an executive agency sponsored by The Department for Business and Trade (DBT) we have the ability to play a leading role in the right against corrupt business practices by providing the transparency and clarity necessary for the UK to continue to be regarded as a world-leading place to do business.

Companies House is undergoing an historic change - to our systems, culture, services, and ways of working. Our people are at the heart of these changes.

The Economic Crime and Corporate Transparency Act (2023) gives Companies House the power to play a more significant role in disrupting economic crime and supporting economic growth.

These changes represent the biggest opportunity for Companies House in almost 170 years. This move will help us achieve the kind of culture we want - one which drives high performance and where our brilliant people can flourish.

As a Application Security & Testing Analyst, your main responsibilities will be:

. Conduct application security assessments across web applications, APIs, mobile applications and cloud platforms. . Review, assess and triage vulnerabilities identified through penetration testing and automated security tooling. . Work closely with development teams to provide practical remediation advice and security recommendations. . Track security defects through to resolution and validate effectiveness of remediation activities. . Support the implementation and continual improvement of Secure Development Lifecycle (SDLC) processes. . Perform secure code reviews and provide guidance on secure coding best practices. . Assist with the investigation of application security incidents and root cause analysis activities. . Collaborate with engineering, testing and DevOps teams to integrate security controls into CI/CD pipelines. . Contribute to application security standards, policies, patterns and technical guidance. . Promote secure-by-design principles and help foster a security-first culture across delivery teams.

Essential Experience . Strong understanding of OWASP Top 10 vulnerabilities and common web application security risks. . Experience using security testing tools such as Burp Suite, Checkmarx, Snyk, Veracode, Fortify or similar. . Knowledge of application security testing methodologies and vulnerability management. . Experience supporting secure software development practices within Agile environments. . Understanding of web technologies, APIs, cloud services and modern development practices. . Experience working with Jira or similar work management platforms. . Ability to communicate security findings to both technical and non-technical stakeholders.

Desirable Experience . Experience integrating security into CI/CD and DevSecOps environments. . Knowledge of secure coding practices and code review processes. . Experience supporting Microsoft security and compliance technologies. . Security certifications such as Security+, CSSLP, CEH, GWAPT, OSCP or similar.

Additional Information . Primarily remote working position aligned to the Cardiff office.

Please be aware that this role can only be worked within the UK and not Overseas.

Disability Confident

As a Disability Confident employer, Companies House encourage applications from disabled and neurodivergent candidates. Applications from candidates who identify as having a disability and meet the essential criteria for the role will be prioritised for review. Where application volumes are high, additional role-specific and desirable criteria may be applied as part of the shortlisting process which may include holding active security clearance.

Armed Forces Covenant/Commitment

As a signatory of the Armed Forces Covenant, Companies House welcome applications from veterans, service leavers, reservists and military spouses or partners. Applications from eligible candidates who meet the essential criteria for the role will be prioritised for review. Where application volumes are high, additional role-specific and desirable criteria may be applied as part of the shortlisting process which may include holding active security clearance.

In applying for this role, you acknowledge the following "this role falls in scope of the Off Payroll Working in the Public Sector legislation. Any rates of payment quoted will reflect the gross rate per day for the assignment and will be subject to appropriate taxes and statutory costs. As such the payment to the intermediary and your income resulting from this contract will be different".

Posted Today

Related Jobs

Related Searches

Apply Now