Application Security Architect

Bentley Systems
London
8 months ago
Applications closed

Related Jobs

View all jobs

Application Security Architect – London/Remote

Application Security Architect – London/Remote

Senior Software Security Architect

GSEC AI ML Security Architect

Senior Security Engineer, Corporate Services Security, Corporate Services Security

Security Architect - M365

Application Security Architect

Location:Home-Based- Europe

We are seeking a talented Application Security Architect to be part of our dedicated software security team (AppSec) at Bentley Systems. The future addition to this team will play a crucial role in safeguarding our cutting-edge products. Our product security team is committed to continuously elevating security standards and staying ahead of the curve in the ever-evolving cybersecurity landscape. This role demands exceptional expertise, a passion for learning, and a willingness to embrace challenges. You'll collaborate with a team of remotely-based experts from across the globe, working across a diverse range of technologies, including C#, Typescript, JavaScript, , single-page applications and Electron applications, Azure cloud services, K8s, and more.

We will rely on you for the following:

Define security best practices and standards. Perform security architecture and design reviews of applications. Work independently with developers to ensure secure design, development, implementation, and verification of applications. Provide remediation guidance and recommendations to developers and administrators. Lead Secure Software Development Lifecycle best practices and standards. Participate in and advance threat modeling practices. Help stakeholders make risk-based decisions. Train developers and create educational presentations. Develop tools and automation supporting responsibilities.

What You Bring to The Team:

More than 4+ years of application Security Architecture experience.Background experience in software and development.Strong experience in threat modeling software systems.Proficiency in reading, writing, and auditing code and the ability to learn new languages/technologies.Proficiency in cloud technologiesExperience with OWASP Top10 or SANS Top 25Experience breaking down complex systems and applications to identify threats.Certification in CISSP or CCSP, it’s a plus. Strong problem-solving capabilities using various technologies. Capability to research a new topic and to learn quickly. Excellent ability to communicate, verbally and in writing, complicated technical issues and the risks they pose to developers, network engineers, system administrators, and management. Requires sitting or standing at will while performing work on a computer (or any other physical requirements). The role requires communication with managers, peers, and other colleagues of the company in person, and by utilizing Microsoft Teams chat, calling, and meeting functions.

What would make you stand out:

Knowledge/Experience of containerization solutions, such as Kubernetes, Docker, and Istio. Knowledge/Experience of web technologies (JavaScript, HTML5, HTTP, REST, SOAP, etc.). Good knowledge of some of the following programming platforms/languages: .Net Core. , C#, Java, JavaScript/TypeScript, C/C++. Knowledge of OAuth Connect. Ability to make risk-based, unbiased, judgments that include both technical and business impacts.

This role is subject to multiple background checks: conduct search, criminal check, global sanctions & enforcement, and global employment checks. An offer for this role is contingent upon successful verification of these checks, which will be performed by an external vendor, HireRight, during the written offer process.

What We Offer:

A great Team and culture – please see our Recruitment Video An exciting career as an integral part of a world-leading software company providing solutions for architecture, engineering, and construction. Competitive Salary and benefits The opportunity to work within a global and diverse international team. A supportive and collaborative environment 

About Bentley Systems:

Bentley Systems (Nasdaq: BSY) is the infrastructure engineering software company. We provide innovative software to advance the world’s infrastructure – sustaining both the global economy and environment. Our industry-leading software solutions are used by professionals, and organizations of every size, for the design, construction, and operations of roads and bridges, rail and transit, water and wastewater, public works and utilities, buildings and campuses, mining, and industrial facilities. Our offerings, powered by the iTwin Platform for infrastructure digital twins, include MicroStation and Bentley Open applications for modeling and simulation, Seequent’s software for geoprofessionals, and Bentley Infrastructure Cloud encompassing ProjectWise for project delivery, SYNCHRO for construction management, and AssetWise for asset operations. Bentley Systems’ 5,200 colleagues generate annual revenues of more than $1 billion in 194 countries.

Get the latest insights and jobs direct. Sign up for our newsletter.

By subscribing you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Contract vs Permanent Cybersecurity Jobs: Which Pays Better in 2025?

Cybersecurity has become one of the fastest-growing and most crucial fields in modern business. With high-profile breaches dominating headlines and the ongoing digital transformation exposing organisations to new threats, companies across the UK are competing to attract skilled cybersecurity professionals. Roles range from penetration testers (pen testers) and SOC (Security Operations Centre) analysts to compliance officers, cloud security architects, threat intelligence analysts, and CISOs (Chief Information Security Officers). As demand continues to surge, cybersecurity salaries have climbed accordingly, and businesses have turned to more flexible hiring practices. Alongside permanent employment, many professionals explore short-term day‑rate contracting or fixed-term contracts (FTCs), searching for the ideal balance of pay, job security, and growth opportunities. Which arrangement truly pays better in 2025—and which best aligns with your ambitions? In this article, we dive into the contract vs. permanent debate with a focus on cybersecurity roles. We will examine the current market, the structure of day‑rate vs. FTC vs. permanent positions, the pros and cons of each, and some hypothetical pay comparisons. By the end, you should have a clearer sense of which career path might suit your situation and goals—whether you are a seasoned specialist aiming for top rates, or an up-and-coming analyst seeking a stable environment to develop in.

Cyber Security Jobs for Non‑Technical Professionals: Where Do You Fit In?

Defence Needs More Than Hackers in Hoodies When headlines warn of ransomware crippling hospitals or deepfakes swaying elections, we picture hoodie‑clad hackers and elite penetration testers. Yet the reality of the UK’s cyber security sector is broader—and desperately short of talent. The Department for Science, Innovation & Technology (DSIT) estimates a shortfall of 11,200 cyber security professionals in 2024, while 43 % of advertised roles require governance, risk or communication skills rather than hands‑on technical exploits. Put plainly: if you can guide policy, manage projects, interpret regulations or inspire behaviour change, cyber security wants you. This guide highlights the fastest‑growing non‑technical roles, the transferable skills you already possess, and a concrete 90‑day plan to land a cyber security job—no packet sniffers required.

BAE Systems Cybersecurity Jobs in 2025: Your Complete UK Guide to Protecting Governments, Businesses and Critical Infrastructure

From securing the Royal Navy’s new Dreadnought submarines to foiling multimillion‑pound fraud rings, BAE Systems Digital Intelligence (DI)—formerly Detica—sits at the sharp end of global cyber defence. Head‑quartered in Guildford with hubs in Gloucester, Leeds and London, the 5,500‑strong DI business delivers threat‑intelligence platforms, secure‑by‑design software and 24/7 SOC services to government and commercial clients worldwide. With escalating ransomware, AI‑driven disinformation and complex supply‑chain threats, BAE plans to expand its UK cyber workforce by 20 % in 2025. Whether you’re a graduate passionate about reverse engineering, a DevSecOps engineer who loves IaC, or an incident‑response pro comfortable in high‑side environments, this guide explains how to land a BAE Systems cybersecurity job in 2025.