{"id":2218002,"url":"https://alion.io/job/oneadvanced-principal-cyber-security-test-engineer","title":"Principal Cyber Security Test Engineer","company":{"id":51451,"name":"OneAdvanced","domain":"oneadvanced.com","url":"https://alion.io/company/oneadvanced","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"iCIMS","truth_index":{"grade":"A","score":100,"open_postings":3,"ghost_share":0,"stale_share":0,"repost_share":0,"time_to_fill_p50_days":16,"computed_at":"2026-10-10T05:45:15Z"}},"role":"Security","role_family":"Security","seniority":"lead","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Bengaluru, India"],"countries":["IN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":28000,"max_usd":61000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":11},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"CI/CD","optional":false},{"name":"GitHub","optional":false},{"name":"GitHub Actions","optional":false},{"name":"Java","optional":false},{"name":"Node JS","optional":false},{"name":"Shift-Left","optional":false},{"name":"Shift-Left Security","optional":false},{"name":"Checkmarx","optional":true},{"name":"GDPR","optional":true},{"name":"ISO 27001","optional":true},{"name":"JavaScript","optional":true},{"name":"Kubernetes","optional":true},{"name":"Snyk","optional":true},{"name":"SOC 2","optional":true},{"name":"Veracode","optional":true}],"status":"live","first_seen_at":"2026-10-10T09:34:19Z","employer_posted_date":"2026-10-10","last_verified_at":"2026-10-11T00:10:30Z","board_verified":true,"closed_at":null,"days_open":0,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":0},"description":"Join OneAdvanced\nWe are looking for an experienced application security engineer who will champion a shift-left security philosophy by integrating automated security analysis into CI/CD pipelines, SAST scanning, GitHub Actions, and SCA. To ensure we embed security into the software development lifecycle (SDLC) across the organisation’s .NET, Java, and Node.js technology stacks.This role is also needed to run web application security assessments or penetration tests.\nWhat You Will Do\nThreat Modelling\nCode reviews\nSupporting engineering teams with security related design and build issues\nReviewing the results from various security code scanning tools\nReviewing CI/CD pipeline configurations\nCreate or amend code and generate pull requests for code fixes\nReviewing and testing AI integrations and relevant guard rails etc\nAssisting other members of the team with application security related issues\nCompleting web and desktop security assessments\nCarrying out risk assessments using the IRAM2 methodology\nAttending architecture board technical reviews\nSuccess Measures:\nNumber of threat models completed\nNumber of penetration tests completed\nNumber of engagements on AI and Software Engineering Projects\nNumber of risk assessments completed \nWhat You Will Have\n5+ years of experience in application security, software engineering, or DevSecOps.\nProven hands-on experience securing applications built with .NET, Java, and Node.js.\nDemonstrable expertise administering SAST scanning at enterprise scale (multi-project, multi-language).\nExperience implementing and managing SCA tooling, ideally Harness, across large codebases.\nStrong working knowledge of GitHub Actions CI/CD pipelines and GitHub Advanced Security features.\nExperience configuring and using IAST and RASP technologies\nDeep understanding of common vulnerability classes (injection, broken access control, cryptographic failures, SSRF, etc.).\nAbility to execute on web and desktop penetration tests.\nDemonstrable expertise securing the embedding and implementation of AI within applications\nDesirable:\nRelevant certifications: CSSLP, GWEB, GWAPT, CEH, OSCP or equivalent.\nExperience with additional SAST/DAST/IAST/RASP tools (Checkmarx, Snyk, Veracode, Contrast Security).\nContributions to open-source security projects or published security research.\nFamiliarity with regulatory frameworks (SOC 2, ISO 27001, GDPR) as they relate to application security.\nExperience with Kubernetes security and service-mesh architectures.\nWhat We Do For You\nWellbeing focused - Our people are our greatest assets, and ensuring everyone feels their best self to come to work is integral. \nAnnual Leave - 20 days of annual leave, plus public holidays \nEmployee Assistance Programme - Free advice, support, and confidential counselling available 24/7. \nPersonal Growth - Regardless of where you are at in your career, we’re committed to enabling your growth personally and professionallyDevelopment Programmes - From Future Managers to Leadership Training, our development programmes help you get where you need to go\nOnline Learning Platform: SkillsHub! - Learning at your fingertips, anytime from anywhere. You can access our online library with relevant content for your career growth. \n\nLife Insurance - 3x annual salary \nPersonal Accident Insurance - providing cover in the event of serious injury/illness.\n Performance Bonus - Our Group-wide bonus scheme enables you to reap the rewards of your success\nWho We Are\nAt OneAdvanced, we are at the forefront of delivering sector-focused technology solutions that simplify complexity, drive meaningful progress, and help build a fairer, more inclusive society.\nWe’re much more than a software company. We deliver SaaS workflow applications and IT services that power organisations across Education, Government, Healthcare, Legal, Manufacturing, Housing, Retail, and more.\nOneAdvanced is one of the UK’s largest business software and services companies. Based in Birmingham (The Mailbox), operating across the UK, Ireland, India, and Australia.\nOur secure, scalable platform, including OneAdvanced AI, our private AI service for UK organisations, powers connectivity and innovation across critical sectors. Alongside our software are our IT services, including hosting, managed services, and application modernisation.\nWe strive to create an inclusive workplace that drives innovation and collaboration, championing diverse perspectives and ideas. Our Environmental, Social and Governance (ESG) strategy is embedded in everything we do, guiding us to create meaningful impact for our people, our customers and the planet.\nJoin us and become part of a team that’s powering the world of work and making a real difference.\nLearn more at www.oneadvanced.com","description_format":"text","description_chars":4753,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Annual leave","Life insurance"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Human Resources","EHR & Clinical Software","Legal Software"],"lifecycle":[{"event":"open","at":"2026-10-10T09:34:19Z"}],"visa":[],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":0,"expected_fill_days":16,"reasons":["conf:4","win:early"],"computed_at":"2026-10-11T04:24:43Z"},"pay":null,"html_url":"https://alion.io/job/oneadvanced-principal-cyber-security-test-engineer","json_url":"https://alion.io/job/oneadvanced-principal-cyber-security-test-engineer.json","meta":{"generated_at":"2026-10-11T04:24:43Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3032,"day_limit":5000,"remaining_today":1968,"minute_limit":60,"resets_at":"2026-10-12T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":51451},"rest":"https://alion.io/mcp/rest/get_company?id=51451"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Foneadvanced-principal-cyber-security-test-engineer"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Foneadvanced-principal-cyber-security-test-engineer"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Foneadvanced-principal-cyber-security-test-engineer"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/oneadvanced-principal-cyber-security-test-engineer\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Foneadvanced-principal-cyber-security-test-engineer"}]}