Intact Insurance is the new name for RSA in the UK, Ireland, and across Europe. It’s a new name and a new way to do business. Backed by global expertise and a commitment to service that feels different, we’re focused on making insurance simpler, faster, and more responsive.
Shape the future:
We’re leading a transformation in insurance helping people, businesses and society prosper in good times and be resilient in bad times. When you join us, you’re not just taking a job, you’re stepping into a career where you can make a real difference.
Grow with us:
We’re customer-driven, community-focused, and committed to helping our people grow. Whether you’re early in your journey or bringing years of experience, we’ll support you with the tools, flexibility, and opportunities to thrive.
Win as a Team:
The DevSecOps and Attack Surface Specialist is responsible for embedding security across the software development lifecycle and extending that posture to artificial intelligence systems. The role sits at the intersection of secure software engineering, offensive testing, attack surface management, and emerging AI risks, acting as both a technical practitioner and a collaborative partner to engineering, product, and operations teams.
You’ll make an impact by:
- The specialist will champion a shift left philosophy, driving automated security controls earlier in the development process while maintaining rigorous validation of vulnerabilities identified through dynamic and static testing.
- You will lead application security initiatives, managing Pentest, SAST, SCA and DAST scanning and remediation activities and maintaining asset inventories.
- The specialist will be responsible for managing Intact’s external application attack surface by monitoring and assessing new and existing domains.
- You will also lead the integration of AI specific security practices across the organisation and also support the expansion of AI capabilities within the cyber defence team.
Your skills and experience:
- Strong understanding of application security principles across the full software development lifecycle
- Hands on experience with SAST and SCA tooling such as Semgrep, Checkmarx, Snyk, and OWASP Dependency Check
- Experience configuring and operating DAST tools such as OWASP ZAP, Burp Suite Enterprise, and Invicti
- Ability to triage, validate, and reproduce vulnerabilities through manual testing and proof of concept development
- Working knowledge of secure coding practices across common languages and frameworks
- Familiarity with CI and CD pipeline integration, including implementation of security gates and automated controls
- Experience with attack surface management, including asset discovery, domain enumeration, and external exposure analysis
Why You’ll Love It Here:
Being part of our team means you’ll have the support and freedom to bring your best self to work each day. As a permanent member, here’s what you can look forward to
- Annual discretionary bonus
- Up to 11% pension contributions
- Hybrid working
- 25 days annual leave + bank holidays + buy/sell options
- Health & wellbeing + virtual GP
- Career development and mentoring
- Inclusive culture + employee networks
- Share investment options
Our DEI Commitment:
We celebrate individuality and believe our differences make us stronger. We’re proud to foster a culture where everyone feels respected, valued, and empowered to thrive.
As an Equal Opportunity and Disability Confident Employer, we ensure fair consideration for all applicants and offer interviews to all disabled candidates who meet the essential criteria.
We understand that everyone’s circumstances are different and are happy to explore flexible working options such as reduced hours or job shares to support work–life balance.
If you meet the core criteria but not every requirement, we’d still love to hear from you. Let’s explore how this role could support your next career step. If you need adjustments during the recruitment process, just let us know we’re here to support you.