Cyber Security Consultant

InfoSec People Ltd
UK
7 days ago
Apply on www.collegerecruiter.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Software as a Service Cyber Security Continuous Integration Database Security Identity and Access Management MongoDB OAuth OpenID Platform as a Service (PAAS) Role-Based Access Control Zero Trust Network Access
+5 more
Software Security Atlassian Tools Software Coding Elastic Beanstalk Terraform

Job description

We’re working with a major UK retailer that’s continuing to invest heavily in cyber security advisory capability across its digital and platform estate.

This is a consultative role focused on guiding, influencing and enabling teams to design and operate secure SaaS and PaaS platforms at scale.

Rather than hands-on operational delivery, you’ll act as a trusted security advisor, partnering with engineering, platform and product teams to reduce risk, improve configuration hygiene and embed secure-by-design practices., * Act as a Cyber Security Consultant to platform and engineering teams across SaaS/PaaS services (Microsoft, Google, Atlassian, MongoDB Atlas)

  • Lead security reviews and advisory assessments focused on configuration, access, identity and platform risk
  • Provide clear, pragmatic guidance on IAM, least privilege, Zero Trust and secure platform patterns
  • Advise on API and database security design, controls and threat mitigation
  • Support teams to embed security into CI/CD pipelines and IaC workflows, advising on guardrails rather than owning build
  • Translate security risk into practical recommendations that delivery teams can implement quickly
  • Produce guidance, standards and documentation, and run workshops and knowledge-sharing sessions
  • Act as a bridge between security, engineering, vendors and third parties

Requirements

  • Experience in a cyber security advisory, consulting or internal consulting-style role
  • Strong grounding in Identity & Access Management (SSO, JWT, OAuth/OIDC, RBAC/ABAC, least privilege)
  • Solid understanding of API security and database security fundamentals
  • Working knowledge of Terraform, CI/CD and automation concepts (hands-on coding not required)
  • Ability to assess risk, challenge designs constructively and influence without authority
  • Comfortable engaging senior engineers, architects and product stakeholders
  • A pragmatic mindset - focused on enabling delivery, not blocking it

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.collegerecruiter.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:01 min

Migrating existing applications from MongoDB to Postgres

Nikita Shamgunov Nikita Shamgunov · World Congress 2024

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all