Senior Cyber Security Risk Assessment Consultant

Salt Search Ltd.
London, UK
21 days ago
Apply on www.totaljobs.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
£130,000.0 - £140,400.0
Working hours
Regular working hours
Languages
English

Tech stack

Software System Penetration Testing Code Review Cyber Security Information Systems Continuous Integration Open Web Application Security Systems Development Life Cycle Web Application Security Software Security Information Technology Devsecops Static Application Security Testing
+2 more
Vulnerability Analysis Dynamic Application Security Testing

Job description

You will provide security expertise across a broad portfolio of business and technology projects, working closely with architects, engineers, developers, project teams, risk management and business stakeholders.

A key part of the position is performing technical security risk assessments, translating identified risks into security requirements, reviewing and validating solution designs, and defining appropriate security testing requirements.

This is not a SOC or purely operational security role. We are looking for experienced security professionals who can understand complex technical solutions, identify security risks and vulnerabilities, and advise projects on the controls required to achieve Secure by Design., * Perform security risk assessments across business and IT projects.

  • Identify threats, vulnerabilities, security weaknesses and potential impacts within proposed solutions.
  • Translate security architecture, policies, risks and controls into clear functional and technical security requirements.
  • Define and advise on the design, implementation and testing processes required to protect information systems and assets.
  • Embed Secure by Design principles throughout the technology delivery lifecycle.
  • Contribute to architectural and solution design discussions and validate designs against security requirements.
  • Review applications, platforms and infrastructure from a security perspective.
  • Define application security testing requirements, including appropriate use of DAST, SAST, code scanning and penetration testing.
  • Define penetration-testing scope and work closely with security-testing teams throughout execution.
  • Review security-testing and penetration-testing reports and assess whether identified risks have been appropriately addressed.
  • Apply OWASP principles and guidelines when assessing application security.
  • Identify security gaps and recommend appropriate remediation and compensating controls.
  • Produce and maintain security standards, principles, baselines and documented security requirements.
  • Recommend new or improved security services and controls.
  • Act as a Security Subject Matter Expert for project and business teams.
  • Present security risks, findings and recommendations clearly to both senior stakeholders and deep technical specialists.
  • Work closely with Business Owners, Business Analysts, Project Managers, Risk Management, Architects, Developers, Engineers and internal/external auditors.

Requirements

We are particularly interested in candidates with strong knowledge of Application Security and experience across areas such as:

  • OWASP Top 10 and wider OWASP security principles
  • DAST / Dynamic Application Security Testing
  • SAST / Static Application Security Testing
  • Secure SDLC / Secure by Design
  • Application vulnerability assessment
  • Web application security
  • API security
  • Code scanning and security-analysis tooling
  • Penetration-testing methodology and scoping
  • Security testing and test-result validation
  • CI/CD security controls
  • DevSecOps
  • Security and compliance automation

You do not need to be a hands-on penetration tester, but you should have sufficient technical knowledge to define security-testing requirements, scope appropriate testing, challenge findings and determine whether security risks have been adequately addressed.

Your Experience

For the senior positions, we are looking for candidates with:

  • 10+ years’ experience within Cyber / Information Security.
  • Proven experience performing technical security risk assessments.
  • Strong understanding of application and/or infrastructure security.
  • Experience identifying security risks and translating these into practical security requirements and controls.
  • Experience contributing to and/or validating technical and architectural solution designs.
  • Strong knowledge of OWASP and application-security principles.
  • Experience with DAST, SAST, vulnerability assessment, penetration testing or related security-testing approaches.
  • Experience defining security-testing requirements and reviewing the resulting findings.
  • Ability to understand complex applications, infrastructure and technology architectures.
  • Experience producing security documentation, standards, principles, requirements or baselines.
  • Experience translating business requirements into appropriate technical security solutions.
  • Strong analytical and critical-thinking skills.
  • Ability to take ownership of security assessments and work independently across multiple projects.
  • Excellent stakeholder-management and communication skills.
  • Ability to explain and defend security recommendations with both senior business stakeholders and highly technical IT professionals.
  • Experience working within large, complex enterprise environments.
  • Fluent English.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.totaljobs.com
Prepare application

Good distractions

Loading talks and stories from around this role…