Product Application Security Analyst

Robert Walters
Manchester, United Kingdom
Last month
£60,000 – £70,000 pa
Applications closed

Related Jobs

View all jobs

Senior Cyber Security Analyst

De Montfort University Leicester Leicester, LE1 5YA, United Kingdom
£44,746 – £56,535 pa

IT Business Solutions Analyst

ARC IT Recruitment London, United Kingdom
£60,000 – £65,000 pa Hybrid

Intrusion Analyst , GBR)

CrowdStrike United Kingdom
Remote

Threat Research Analyst

Darktrace London, UB8 1LQ, United Kingdom

Threat Research Analyst

Darktrace Cambridge, CB2 3BJ, United Kingdom

Threat Researcher II - IRE, UK or ROU)

CrowdStrike Ireland
Remote

Salary

£60,000 – £70,000 pa

Posted
24 Jul 2026 (Last month)

You'll act as a trusted security advisor to engineering communities across the entire product lifecycle. This is a non-hands-on, advisory and governance-focused role designed to embed "security-by-design" into modern monolithic and microservice application architectures. You'll lead threat modelling, conduct technical risk assessments, evaluate third-party SaaS vendors, and translate complex risk into pragmatic guidance for engineering squads and business stakeholders.

Partnering with a major UK enterprise digital platform to bring in a Senior InfoSec Analyst into their Product Assurance team.

This isn't a checkbox compliance job, nor is it an operational 2nd-line ticket handling role. You'll sit right alongside software delivery squads and product teams, acting as the technical security authority across monolithic and microservice application architectures.

What the day-to-day looks like
  • Security by Design: Threat modelling (STRIDE/OWASP) and setting security requirements early in the SDLC alongside dev squads

  • Architectural Assurance: Advising engineering teams on cloud-native security controls, containerisation, and API gateway logic

  • Risk & Advisory: Conducting technical risk assessments on internal products and third-party SaaS vendors, turning technical flaws into clear risk recommendations

  • Framework Alignment: Ensuring applications comply with PCI-DSS, NIST, and OWASP standards without creating operational friction for developers

What you'll bring
  • Experience: 6+ years in InfoSec, cybersecurity advisory, or application security

  • Tech Depth: Solid grasp of cloud environments (AWS, Azure, or GCP), microservices, containers (Docker/Kubernetes), and CI/CD pipelines (GitHub, Jenkins)

  • Stakeholder Influence: The ability to explain technical risk to product managers and challenge engineering decisions constructively

  • Certifications: Holding or actively working towards industry standards like CISSP, CCSP, CISM, CRISC, or Cloud Security Architect certs

Robert Walters Operations Limited is an employment business and employment agency and welcomes applications from all candidates

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.