Cyber Security Technical Consultant

DAINTTA
London, UK
about 1 month ago
Apply on uk.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Amazon Web Services Data Analysis Software System Penetration Testing Microsoft Azure Cloud Computing Cyber Security Data Governance Identity and Access Management Javaserver Pages Google Cloud Cloud Platform System
+6 more
Data Classification Software Security SC Clearance AI Platforms Devsecops Vulnerability Analysis

Job description

Daintta are a rapidly growing, values-driven team of specialists who work with government clients across Cyber, Telecommunications and Data. We are seeking a talented and motivated CyberSecurity Technical Security Manager to join our team and contribute to our mission of protecting the UK through data-driven insights and solutions. As a technical Manager, you will be expected to demonstrate versatility as you work closely with our public sector clients, governmental departments and project teams. You will lead a team to design, document and support the build of secure networks or systems, helping solve some of the UK’s most exciting cyber security challenges.

Responsibilities

  • Leading client engagements as a cyber security technical authority

  • Developing, justifying and implementing organisational and system security management strategies that address risk and control requirements, ensuring a UK Gov’t Secure by Design approach

  • Selecting, understanding and adapting/adopting appropriate security control frameworks

  • Identifying security risk business and stakeholder security requirements and proposing proportionate assessment, design and implementation of secure systems to meet the requirements

  • Performing threat modelling and risk assessments to develop a holistic picture of threat

  • Ensuring security principles are applied during solution planning, design, test, deployment and operations to reduce risk and ensure compliance, including:

  • Developing secure solution designs to mitigate the risks posed by new technologies and business practices

  • Leading third-party and supply chain security assessments, including vendor due diligence, secure procurement, software supply chain risk and ongoing assurance of externally sourced technology

  • Applying identity-led and zero-trust security principles, including strong authentication, least privilege, contextual access control and segmentation of services, users and devices

  • Defining and reviewing security assurance activities, including design assurance, verification, validation, vulnerability assessment, penetration testing inputs and interpretation of assurance evidence

  • Developing and communicating corporate and domain information security policy, standards, guidelines and design guardrails

  • Identifying and monitoring environmental and market trends and proactively assessing impact on business strategies, benefits and risks

  • Assessing our client needs, understanding how these may differ from their wants, and appropriately managing stakeholder relationships

  • Delivering high-quality work to agreed milestones and adapting quickly to unfamiliar client environments.

  • Leading the client technical engagements, including pitches and presentations

  • Helping to support & grow Daintta by actively inputting into the company strategy and helping to shape our future

Requirements

  • You have 5+ years of practical experience in cyber security engineering, architecture, design and technical assurance, with evidence of applying that knowledge credibly in client-facing consulting engagements

  • You have led technical client deliveries and teams across a range of cyber security related projects

  • You have demonstrable working-level experience across several of the following domains: Security Architecture; Security Operations; Identity & Access Management; Cloud, Infrastructure and Platform Security; Network and Connectivity Security; Application Security and DevSecOps; Data Security and Privacy; Governance, Risk & Compliance.

  • You have experience embedding security into agile, DevSecOps and iterative delivery models, including design reviews, security requirements management and pragmatic risk treatment in fast-moving projects

  • You have experience aligning business requirements with security control standards and frameworks including: ISO27001, NIST, NCSC guidance and NCSC CAF, JSP 440 or others

  • You have demonstrable continuous personal development, supported by relevant certifications and accreditations

  • You have good interpersonal skills at both the business and technical level

  • You have UK security clearance at SC or above or are eligible and willing to go through clearance

Desirable:

  • You have experience working with security controls within cloud-based infrastructure (e.g. Azure, AWS, GCP). This may include design, configuration, or protective monitoring.

  • Knowledge of digital identity and authentication systems

  • Experience applying data classification, handling requirements, data residency and sovereignty considerations to solution design, particularly where sensitive, regulated or operationally critical data is involved

  • Understanding of security risks and controls for AI-enabled systems, including data governance, access control, prompt injection, model misuse, third-party AI services and monitoring of sensitive data exposure

  • Application and governance of fine-grained access control and permissions

  • Experience in UK Gov’t public sector or defence, Due to the nature of this position and our client engagements, you must be willing and eligible to achieve a minimum of SC clearance. To qualify, you must be a British Citizen and have resided in the UK for the last 5 years. For more information about clearance eligibility, please see https://www.gov.uk/government/organisations/united-kingdom-security-vetting (https://www.gov.uk/government/organisations/united-kingdom-security-vetting)

Benefits & conditions

Pulled from the full job description

  • Referral programme
  • Annual leave
  • Employee discount
  • Employee assistance programme
  • Company pension
  • Paid volunteer time
  • Private medical insurance, We believe in supporting our people both professionally and personally. Here’s what you can expect when you join us:

Time Off

  • 25 days annual leave, plus bank holidays
  • Up to 5 days annual training leave with a dedicated training budget
  • Up to 3 days annual volunteering leave - give back to the community
  • Competitive maternity, paternity, shared parental leave & compassionate leave

Health & Wellness

  • Comprehensive Private Health Insurance
  • Employee Assistance Programme - 24/7 support services
  • £2,000 Flex Cash Allowance, paid pro-rata over the year

Financial Benefits

  • 5% pension contribution
  • Discretionary company awards and bonuses, based on performance and company targets
  • Access to Electric Vehicle (EV) Salary Sacrifice scheme

Professional Development

  • Up to £1,000 annual training budget (access to additional training and development budget via business case)
  • Up to 5 days annual training leave
  • 1 professional membership paid annually
  • Up to £200 of additional IT budget for new joiners

Perks

  • Free breakfast every Tuesday in the London office
  • Fortnightly drinks - in London
  • Regular social events, quizzes, and guest workshops
  • Huckletree perks - including gym and restaurant discounts
  • Employee referral programme
  • Monthly breakfast club in our Cheltenham office

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on uk.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:36 min

Choosing between managed AI platforms and custom governance

Péter Farkas Péter Farkas · Europe 2026 Virtual

6:10 min

Unlocking free learning credits via Google Cloud Innovators

Asrar Asrar · World Congress 2024

2:12 min

Navigating technical clarity as a global black belt

Chris Heilmann +2 · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Videos

See all

Related articles

See all