Principal Cyber Security Test Engineer

lead
QA & TestingSecurity Test Engineer
3 views0 saves0 applied

Quick Summary

Overview

Join OneAdvanced We are looking for an experienced application security engineer who will champion a shift-left security philosophy by integrating automated security analysis into CI/CD pipelines,

Technical Tools
QA & TestingSecurity Test Engineer

We are looking for an experienced application security engineer who will champion a shift-left security philosophy by integrating automated security analysis into CI/CD pipelines, SAST scanning, GitHub Actions, and SCA. To ensure we embed security into the software development lifecycle (SDLC) across the organisation’s .NET, Java, and Node.js technology stacks.This role is also needed to run web application security assessments or penetration tests.

Responsibilities

~1 min read
  • →Threat Modelling
  • →Code reviews
  • →Supporting engineering teams with security related design and build issues
  • →Reviewing the results from various security code scanning tools
  • →Reviewing CI/CD pipeline configurations
  • →Create or amend code and generate pull requests for code fixes
  • →Reviewing and testing AI integrations and relevant guard rails etc
  • →Assisting other members of the team with application security related issues
  • →Completing web and desktop security assessments
  • →Carrying out risk assessments using the IRAM2 methodology
  • →Attending architecture board technical reviews
  • →5+ years of experience in application security, software engineering, or DevSecOps.
  • →Proven hands-on experience securing applications built with .NET, Java, and Node.js.
  • →Demonstrable expertise administering SAST scanning at enterprise scale (multi-project, multi-language).
  • →Experience implementing and managing SCA tooling, ideally Harness, across large codebases.
  • →Strong working knowledge of GitHub Actions CI/CD pipelines and GitHub Advanced Security features.
  • →Experience configuring and using IAST and RASP technologies
  • →Deep understanding of common vulnerability classes (injection, broken access control, cryptographic failures, SSRF, etc.).
  • →Ability to execute on web and desktop penetration tests.
  • →Demonstrable expertise securing the embedding and implementation of AI within applications

 

  • Number of threat models completed
  • Number of penetration tests completed
  • Number of engagements on AI and Software Engineering Projects
  • Number of risk assessments completed  

•    Relevant certifications: CSSLP, GWEB, GWAPT, CEH, OSCP or equivalent.•    Experience with additional SAST/DAST/IAST/RASP tools (Checkmarx, Snyk, Veracode, Contrast Security).•    Contributions to open-source security projects or published security research.•    Familiarity with regulatory frameworks (SOC 2, ISO 27001, GDPR) as they relate to application security.•    Experience with Kubernetes security and service-mesh architectures.

 

#LI-PB1

  • Wellbeing focused – Our people are our greatest assets, and ensuring everyone feels their best self to come to work is integral. 
  • Annual Leave – 20 days of annual leave, plus public holidays 
  • Employee Assistance Programme – Free advice, support, and confidential counselling available 24/7.
  • Personal Growth - Regardless of where you are at in your career, we’re committed to enabling your growth personally and professionally
    • Development Programmes – From Future Managers to Leadership Training, our development programmes help you get where you need to go
    • Online Learning Platform: SkillsHub! - Learning at your fingertips, anytime from anywhere. You can access our online library with relevant content for your career growth. 
  • Life Insurance - 3x annual salary 
  • Personal Accident Insurance - providing cover in the event of serious injury/illness.
  • Performance Bonus – Our Group-wide bonus scheme enables you to reap the rewards of your success

At OneAdvanced, we are at the forefront of delivering sector-focused technology solutions that simplify complexity, drive meaningful progress, and help build a fairer, more inclusive society.

 

We’re much more than a software company. We deliver SaaS workflow applications and IT services that power organisations across Education, Government, Healthcare, Legal, Manufacturing, Housing, Retail, and more.

OneAdvanced is one of the UK’s largest business software and services companies. Based in Birmingham (The Mailbox), operating across the UK, Ireland, India, and Australia.

Our secure, scalable platform, including OneAdvanced AI, our private AI service for UK organisations, powers connectivity and innovation across critical sectors. Alongside our software are our IT services, including hosting, managed services, and application modernisation.

We strive to create an inclusive workplace that drives innovation and collaboration, championing diverse perspectives and ideas. Our Environmental, Social and Governance (ESG) strategy is embedded in everything we do, guiding us to create meaningful impact for our people, our customers and the planet.

Join us and become part of a team that’s powering the world of work and making a real difference.

 

Learn more at www.oneadvanced.com

 

Location & Eligibility

Where is the job
—
Location terms not specified

Listing Details

Posted
October 8, 2026
First seen
October 8, 2026
Last seen
October 9, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
49%
Scored at
October 9, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust

4 other jobs at

View all →

Explore open roles at .

Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

Principal Cyber Security Test Engineer