> Markdown version of [/jobs/ext/2140250-security-consultant](https://www.wearedevelopers.com/jobs/ext/2140250-security-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Consultant - **Company:** SiXworks - **Location:** Farnborough, UK - **Salary:** £50,751.0 - **Contract:** Permanent contract - **Skills:** Agile Methodology, Information Systems, Continuous Integration, Javaserver Pages, Software Engineering, Cyber Threat Analysis, Devsecops - **Published:** August 20, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5848435447 ## About the Role We value people who take ownership, think critically, and enjoy working as part of a collaborative team tackling complex challenges. You don't need to tick every box, but we're particularly interested in people with skills/experience as described below. Essential experience includes: * Experience of working on risk assessments using industry approved methodologies (such as NIST, ISO 27005). * Producing clear, actionable risk treatment plans aligned to security objectives to treat /mitigate the identified risks. * Experience supporting compliance and assurance activities, including audits, control testing, and evidence gathering * Creation of security documentation to support the development of an information system, these could include: Security Aspects of Design, Risk Assessments, Risk Management Plans, Security Policies, Security Test Plans/Results. * Ability to translate technical security risks into business language for senior stakeholders and decision-makers * High standards in written report and/or design documentation. Desirable experience includes: * Knowledge of MOD policies (JSP 440, 453/604, 892). * Knowledge and experience of Agile, DevSecOps, CI/CD principles and their application in secure environments * Relevant certifications (e.g., CISSP, ChCSP, etc) * Experience of working with MOD Cyber Assurance/Accreditors. Just as important are curiosity, strong problem solving ability, and the motivation to continuously improve how technology is designed and delivered., As an end-to-end digital innovation and delivery partner, we turn complex challenges into mission-critical digital advantages. This is a thrilling time for us, with ambitious plans for growth. We are looking for brilliant, experienced, driven and self-motivated people to join the team on our journey. ## Description We're looking for a Security Consultant who enjoys solving difficult technical challenges and wants their work to have real operational impact. What You'll Do As a Security Consultant, you'll help design, build, and deliver secure digital solutions in highly secure environments. You'll work alongside engineers, architects, and delivery specialists to develop technology that enables faster, safer decision-making for critical operations. Your key responsibilities will include the following: * Cyber Risk Management within a Defence and Security Sector. * Providing strategic security governance, risk and compliance (GRC) direction of projects. * Engagement with relevant stakeholders across the MOD, including project teams, users and policy owners to identify key security objectives and requirements. * Work closely with various teams across the business (Software Engineering, DevSecOps Engineering, Infrastructure Engineering, Agile Development, Support) to achieve security outcomes. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [ShapeShift: Reinventing Agile for a B2B SaaS Scale-Up](https://www.wearedevelopers.com/videos/1655-shapeshift-reinventing-agile-for-a-b2b-saas-scale-up) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)