About the Role
The Senior Application Security Specialist leads advanced application security testing, complex vulnerability analysis, and threat modeling. This role provides technical leadership, mentors analysts, acts as a security point of contact for engineering, and contributes to security strategy and standards.
Responsibilities
- Lead advanced security testing of critical applications and services, including deep-dive manual testing and targeted penetration tests across web, mobile, and API surfaces.
- Own threat modeling using structured frameworks (STRIDE, PASTA), producing threat models for new features and architecture changes.
- Support and engage in the penetration testing program.
- Design security test strategies for new products and major changes.
- Act as subject-matter expert and primary point of contact between engineering and the Application Security team.
- Provide oversight of scanning-tool usage and KPIs in the CI/CD pipeline.
- Own the overarching triage, escalation, and evidence-quality framework across all scanning tools and testing streams, resolving the most complex or contested findings and setting the standard L1/L2 analysts and specialists are mentored against.
- Track and report key security testing metrics (e.g., time-to-remediate, recurring defect patterns) to senior stakeholders.
- Build and maintain advanced test cases, automation frameworks, and custom tooling to improve coverage and efficiency.
- Own the security release process, including remediation verification and closure standards.
- Mentor and coach analysts and specialists; provide training material, playbooks, and quality review of finding reports.
- Act as an escalation point for L1/L2 security analysts.
- Provide expert-level root-cause analysis and remediation guidance for the most complex or systemic security defects and set remediation standards developers and L1/L2 analysts follow across the program.
- Develop and maintain process documentation and testing standards.
Requirements
- 5–8 years' hands-on experience in application security testing.
- Advanced knowledge of internet and network technologies.
- Expert understanding of web and API technologies and common vulnerabilities (OWASP Top 10, API/LLM Top 10, Mobile Top 10).
- Advanced mobile security testing (Android/iOS) — reverse engineering, runtime manipulation, Frida scripting, Objection.
- Advanced knowledge of container orchestration and Kubernetes security, including cluster hardening, RBAC, and workload isolation.
- Advanced AI/LLM security assessment.
- Expert understanding of security controls (access control, encryption, logging/monitoring, secure configuration) and how to assess their effectiveness at scale.
- Strong offensive security skillset — manual web and API testing, authentication/authorization bypass, session management, business-logic abuse, and data-protection testing.
- Advanced knowledge of threat remediation techniques specific to the programming languages in use at Global Relay.
- Strong awareness of advanced persistent threats (APTs), threat actor tactics (e.g., MITRE ATT&CK), and emerging vulnerability classes, and ability to apply this awareness to test strategy design.
- Ability to build and own automation: scripting test cases (Python, Bash), integrating with TestRail and Jira, building automated Burp Suite Pro scanning workflows in CI/CD, and working knowledge of supporting tools such as Postman and SonarQube.
- Excellent communication skills; ability to influence technical and non-technical stakeholders.
- Candidates must have the right to work in the UK at the time of application.
Skills
- Application security testing
- Internet and network technologies
- Web and API technologies
- OWASP Top 10
- API/LLM Top 10
- Mobile Top 10
- Mobile security testing (Android/iOS)
- Reverse engineering
- Runtime manipulation
- Frida scripting
- Objection
- Container orchestration security
- Kubernetes security
- Cluster hardening
- RBAC
- Workload isolation
- AI/LLM security assessment
- Security controls assessment
- Offensive security
- Manual web testing
- Manual API testing
- Authentication/authorization bypass
- Session management
- Business-logic abuse
- Data-protection testing
- Threat remediation
- Advanced persistent threats (APTs)
- MITRE ATT&CK
- Automation scripting (Python, Bash)
- TestRail integration
- Jira integration
- Burp Suite Pro
- CI/CD
- Postman
- SonarQube
- Communication skills
- Influencing skills
Location
- UK
Work Type
- Full-time
Experience Level
- Senior
- 5–8 years' hands-on experience
Education Level
- Recognised advanced certifications preferred (e.g. OSCP, OSWE)
Benefits
- Competitive compensation
- Competitive benefits
About the Company
- For over 25 years, Global Relay has set the standard in enterprise information archiving with industry-leading cloud archiving, surveillance, eDiscovery, and analytics solutions.
- We securely capture and preserve the communications data of the world’s most highly regulated firms, giving them greater visibility and control over their information and ensuring compliance with stringent regulations.
- Global Relay is a career-building company. A place for big ideas. New challenges. Groundbreaking innovation. It’s a place where you can genuinely make an impact – and be recognized for it.
- We believe great businesses thrive on diversity, inclusion, and the contributions of all employees.
- To learn more about our business, culture, and community involvement, visit www.globalrelay.com.
Equal Opportunity
- Global Relay is an equal-opportunity employer committed to diversity, equity, and inclusion.
- We seek to ensure reasonable adjustments, accommodations, and personal time are tailored to meet the unique needs of every individual.
