Develop a strong understanding of Smart Communications’ products/ application landscape, SaaS, cloud, APIs and supporting infrastructure to identify security risks and strengthen the organisation's overall security posture.
Collaborate with Engineering, Architecture, Product, Cloud, Infrastructure, and Platform teams to embed secure-by-design and DevSecOps practices. Identify application security risks and improve controls across authentication, authorisation, secrets management, encryption, and cloud security through automation, CI/CD enhancements, developer enablement, and security guidance.
Support threat modelling, secure design reviews, application security assessments, and testing across web applications, APIs, cloud services, and supporting components.
Operate and improve application security tooling, including DAST, SCA, IaC and container scanning, vulnerability triage, false-positive analysis, and exception management.
Drive vulnerability management and continuous improvement by prioritising remediation, guiding development teams, strengthening key controls, and tracking emerging threats
5+ years’ hands-on experience in Application Security, Product Security, DevSecOps, or a similar security engineering role.
Strong application security expertise, including OWASP Top 10, API security, authentication and authorisation, session management, cryptography, secure coding, and cloud security across AWS.
Experience embedding security into the SDLC through secure design reviews, threat modelling, security testing, DevSecOps practices, CI/CD pipeline security, automation, and engineering collaboration.
Proven ability to assess and secure web applications, APIs, microservices, cloud applications, third-party integrations, architecture, configurations, dependencies, IAM, secrets management, encryption, and data protection controls.
Skilled in application security tooling, vulnerability triage, risk assessment, remediation support and stakeholder communication.
Preferred: degree in Computer Science, Cyber Security, Information Security, Software Engineering, or a related field; relevant AppSec/cloud certifications such as OSCP, OSWE, GWAPT, CSSLP, BSCP, AWS Security Specialty, or Azure Security Engineer Associate.
Preferred: experience with Python, Java, JavaScript; SaaS environments; compliance frameworks including PCI-DSS, ISO/IEC 27001, SOC 2, HIPAA, or IRAP; and threat modelling methodologies such as STRIDE or PASTA.
Apply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
S peak Openly - We are positive, creative, helpful, kind and we have fun. We listen and provide constructive feedback. Through meaningful conversations we encourage each other to be the best that we can be. We’re not complainers we’re problem solvers.
M ake a Difference - We focus on the things that matter and prioritize the things that have the greatest impact. We celebrate success and hold ourselves accountable for our choices. We don’t sit on the sidelines.
A gile & Flexible - We are focused on evolving, improving and growing. We think differently and challenge the status quo with open minds. We ask ‘why?’ so that we can help remove complexity. We don’t allow hurdles to get in our way.
R esults-Focused - We get stuff done by being efficient, working at pace and paying attention to detail. We focus on finding solutions and fixing things. We don’t believe in being busy for the sake of being busy, we focus on productivity.
T eamwork - We are stronger and better together. We collaborate, trust and support each other to deliver results for our company and our customers. We don’t want anyone to feel disengaged, we’re in this together!
About Smart Communications
Software & SaaS447 employeesFounded 2004
Cloud customer communications management software provider serving regulated enterprises with omnichannel engagement, data capture, and digital archiving.