
Senior Information Security Specialist
- Stoke-on-Trent
- Permanent
- Full-time
- Excellent understanding and demonstrable experience of automated, dynamic and static application security testing tools.
- Excellent understanding and experience with manual security testing to find vulnerabilities and logical issues.
- Knowledge and understanding of OWASP and its utilisation within threat modelling.
- Experience of software development and languages.
- Working knowledge of CI and CD pipelines and associated security tooling.
- Use of planned structured methodologies for conducting and reporting on Web Application Penetration Testing.
- Strong documentation skills.
- Excellent communication skills.
- Providing support to technical leads and mentoring junior members of the team.
- Taking a lead role in the project process to ensure that information security aspects are considered up front and throughout the project lifecycle.
- Contributing to and utilising our security testing methodologies, creating and updating technical documentation as necessary.
- Conducting manual and automated source code review.
- Liaising with the software development function to ensure that security is considered throughout the lifecycle.
- Identifying and managing any security flaws within our software through appropriately liaising with external bodies where necessary.
- Performing risk assessments, threat modelling and design reviews to ensure effective security controls.
- Identifying opportunities for converting manual tasks into automated processes and identify tooling to support such automation.