Security Consultant
Role details
Job location
Tech stack
Job description
Are you someone who wants to be in the heart of Cyber Security delivering change and working in an agile way, ensuring we execute our strategy and transformation agenda safely? Then we have the perfect opportunity for you.
We are actively welcoming enthusiastic Cyber Security Professionals from all industries and backgrounds to join our expanding team as we embark on an exciting journey where you will have the opportunity to ensure security by design is embedded across our change portfolio.
Cyber Security sits at the heart of our business providing the Group with a secure operating environment, safe from malicious attacks. It is a dynamic and constantly evolving world where your experience and efforts can deliver tangible results to the safety of a huge company and over 30m customers.
We're on the mission to build the bank of the future, and we need your help to do it!
What you'll do:
- Applying Agile methodologies to support engineers and deliver on multiple challenging product initiatives simultaneously, driving engineering excellence.
- Threat model by deconstructing technical solutions, identifying threats and vulnerabilities and assessing risks.
- Use experience to analyse the risks and benefits of design options to support making safe architectural decisions.
- Design secure solutions documenting the key security controls and adhering to security standards.
- Define security testing requirements and assess findings.
- Effectively communicate technical concepts to both technical and nontechnical audiences, providing security direction, governance, assurance and
guidance.
Requirements
Do you have experience in Terraform?, * Dynamic solution-oriented individual bringing energy to a rapidly evolving environment with an ability to work well under pressure.
- Broad knowledge of modern Enterprise technologies including Cloud and AI
- Exposure to contemporary architectures eg. RESTful APIs and containerised microservices.
- Up-to date on emerging threats and experienced with threat modelling frameworks eg. STRIDE / MITRE ATT&CK.
- Significant knowledge of cyber security domains and how they apply to Enterprise business environments eg. endpoint, network, cryptography and IAM.
The nice to haves:
- Awareness of industry related security standards such as ISO 27000 series, PCI DSS, COBIT, NIST, OWASP.
- Certifications in security management eg. CISSP / CISM / CCSP or equivalent.
- Certifications in technical security domains eg. CEH / OSCP or equivalent.
- Experience of Public and or Private cloud environments.