Security Consultant

LA International Computer Consultants Ltd
United States
1 day ago
Apply on computerjobs.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Cloud Computing Security Cyber Security Data Security Identity and Access Management Network Security Open Web Application Security PCI Data Security Standards Zero Trust Network Access Vulnerability Analysis

Job description

  • Act as the primary Security Assurance Consultant for projects and technology initiatives within the Economic Crime domain.
  • Conduct security assessments of new systems, material changes, integrations and technology solutions.
  • Provide pragmatic security advice that balances risk, regulatory expectations, customer protection and business delivery objectives.
  • Determine whether required preventative, detective and responsive controls are present and operating as intended.
  • Assess the likelihood and business impact of identified security risks & track them through to remediation, mitigation or formal acceptance.
  • Assess solutions against applicable security frameworks, policies and control requirements including NIST CSF 2.0, ISO/IEC 27001, organisational security guardrails.
  • Define and enforce security policies, standards, and best practices ensuring Ensure compliance with financial regulations (eg, PCI DSS, ISO 27001, GDPR).
  • Provide security assurance and guidance regarding IAM and PAM, Network Security, Penetration Testing Results, Vulnerability Scans etc.
  • Challenge solutions constructively where required security controls have not been implemented or have been implemented inadequately.
  • Maintain traceability between identified risks, security requirements, controls, evidence and residual risks.

Requirements

  • Proven experience performing security assurance or security consultancy within complex enterprise environments.
  • Demonstrable experience applying Secure by Design principles.
  • Proven understanding of security risk assessment methodologies.
  • Experience managing security risks, exceptions and remediation activities.
  • Experience and proven knowledge of working with NIST Cybersecurity Framework, ISO/IEC 27001, Zero Trust, OWASP Top 10 etc
  • Good understanding of Access Management, Data Security, Cloud Security, Network security guardrails
  • Confident enough to challenge architects, engineers and project leadership where security requirements are not adequately addressed.
  • Works collaboratively with delivery teams to find secure solutions instead of acting solely as an approval or governance function.

Desirable skills/knowledge/experience:

  • Previous experience of working in UK Financial Services or similar highly regulated industry.
  • Have a relevant professional qualification (or be working towards certification), such as CISM/CISSP.
  • Knowledge/experience of PCI-DSS, NIST CSF, OWASP Top 10, ISO 27001
  • Knowledge/experience of Data privacy and GDPR;
  • Experience with regulatory compliance frameworks specific to financial organizations.
  • Excellent interpersonal and communication skills.
  • Able to differentiate between theoretical security concerns and material business risks, ensuring security decisions remain proportionate.

About the company

LA International is an award-winning partner of choice for many of the world’s most influential companies and government organisations. Holding Enhanced Government Security Accreditation, we are recognised as the European market leader in the delivery of Security Cleared talent to organisations that demand the very highest levels of security, compliance and assurance.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on computerjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:04 min

Embedding data security and applied ethics into developer education

Daniel Tao +3 · World Congress 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:16 min

Securing internal pod communication with network security policies

Marc Nimmerrichter · World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

41 sec

Massive client data loss and bio-digital storage

Chris Heilmann Chris Heilmann +1 · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all