<p><strong>Purpose of Position</strong></p>
<p>Your role is to establish and lead an AppSec program within the Product and Technology department, acting as an evangelist for AppSec, trusted by engineers and managers alike.</p>
<p>As a member of the core security team, you will engage in assessing application design proposals, to identify improvements to enable our engineers to create secure products.</p>
<p>You will own the existing training program, redesign it to better equip engineers with the knowledge needed to develop secure applications, and create a Security Champions program to scale and embed a DevSecOps mindset across P&T. </p>
<p> </p>
<p><strong>What you'll be responsible for</strong></p>
<ul>
<li><strong>Secure the SDLC</strong>: Integrate security tooling (e.g. SAST, DAST, dependency scanning) into CI/CD pipelines and IDEs. Automate and optimise checks so teams can identify and fix issues early and efficiently.</li>
<li><strong>Threat modelling & secure design</strong>: Collaborate with product and engineering teams during the design phase to conduct threat modelling sessions and pre-implementation security reviews.</li>
<li><strong>Code & architecture reviews</strong>: Guide developers on secure coding practices, perform targeted code reviews, and help resolve vulnerabilities with actionable remediation support.</li>
<li><strong>Vulnerability lifecycle management</strong>:
<ul>
<li>Identify, triage, track and report on vulnerabilities across internal and external apps and systems.</li>
<li>Collaborate with engineers to close gaps efficiently.</li>
<li>Support the bug bounty process with finding validation.</li>
<li>Present vulnerability management reports to our heads