
Hackajob Ltd
Security Architect - DevSecOps Application Security
Job Description
Salary: £61,000 - 101,000 per year
Requirements:- At least 5 years of experience in information security, with a strong focus on application security and DevSecOps
- Strong understanding of secure software development practices and common application security risks, such as the OWASP Top 10
- Hands-on experience working with or integrating DevSecOps tooling within CI/CD environments, such as GitLab pipelines
- Experience with application security testing tools and practices, including SAST, DAST, SCA/dependency scanning, and secrets/credentials scanning
- Experience contributing to security design reviews for applications and APIs
- Experience supporting or participating in penetration testing activities, including remediation tracking
- Strong understanding of modern application architectures, such as APIs, microservices, and cloud-native applications
- Knowledge of authentication and session management concepts within applications
- Experience performing or supporting risk assessments aligned to recognised frameworks
- Ability to translate technical vulnerabilities into business-aligned risk and remediation actions
- Strong collaboration skills with engineering and development teams
- Strong technical and non-technical communication skills
- Experience with GitLab security tooling and pipeline integrations
- Familiarity with cloud-native application security in Azure or GCP environments
- Exposure to API security controls and testing approaches
- Basic understanding of AI/LLM application risks, such as prompt injection or data exposure
- Experience working within regulated environments, such as telecommunications, financial services, or critical infrastructure
- Understanding of Telecoms Security Act (TSA) requirements in application design
- Provide application security and DevSecOps architecture expertise, supporting standards and best practices across the software development lifecycle
- Contribute to the target architecture for secure software development, aligned with our Secure by Design principles
- Support the integration of security controls into CI/CD pipelines, including automated testing and policy enforcement
- Design and implement application security controls, including SAST, DAST, SCA/dependency scanning, and secrets and credentials scanning
- Work with engineering teams to encourage consistent adoption of DevSecOps practices and secure coding approaches
- Support security architecture reviews and assurance activities for internally developed applications and services
- Identify and help reduce risks related to application vulnerabilities, insecure coding practices, and exposed credentials
- Support the coordination and execution of third-party penetration testing for our internet-facing applications
- Assist in defining test scope, tracking execution, and ensuring findings are properly remediated
- Guide engineering teams on vulnerability remediation and prioritisation
- Contribute to developing and maintaining secure coding standards and architectural patterns
- Ensure application design and deployment align with regulatory requirements such as TSA, DORA, and ISO 27001
- Promote a security-first culture in development teams through awareness and best practices
- Maintain awareness of emerging risks and technologies, including basic AI/LLM-related application risks, and help translate them into practical controls where required
- Produce and maintain architecture artefacts, standards, and guidance documentation
- AI
- API
- Architect
- Azure
- CI/CD
- Cloud
- DevSecOps
- DevOps
- Exposed
- GCP
- GitLab
- Support
- LLM
- Network
- OWASP
- Security
- microservices
More:
We provide network, voice, and data centre services to thousands of businesses around the world, helping them focus on their business goals rather than underlying infrastructure. We are looking for a Security Architect specialising in Application Security and DevSecOps to join our Security and Resilience Security Architecture team. In this role, you will act as a subject matter expert in secure software development and DevSecOps, working with Engineering, DevOps, Cloud, SOC, and Risk teams to embed security throughout the software development lifecycle. The role spans application security architecture and design, DevSecOps pipeline integration and tooling, and security assurance and governance for internally developed applications. You will help strengthen secure software development, integrate security into CI/CD pipelines, reduce vulnerabilities through automated scanning and testing, and support assurance of internet-facing applications. At Colt, we empower people and bring together global teams to create intelligent solutions that put the power of the digital universe in our customers hands. Our people can inspire and lead teams and work on projects connecting people, cities, businesses, and ideas. Inclusion and diversity of thought and experience are central to our culture, and we welcome people with diverse backgrounds and experiences. Our benefits include flexible working hours and the option to work from home, an extensive induction programme with mentors and buddies, development and educational opportunities, a Global Family Leave Policy, an Employee Assistance Program, and internal inclusion and diversity employee networks.
last updated 39 week of 2026
Interested in this role?
Submit your application now
How to Apply
About Hackajob Ltd

Hackajob Ltd
Charing Cross
IT
Skills & Technologies
Inferred from job description
Salary Insight
£81,000
This role
£90,000
UK median
This salary is 10% below the UK median for Architects (£90,000/yr).
Based on 2024–2025 UK technology sector benchmarks