Security Design Consultant

HCL Technologies
London, UK
2 months ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Agile Methodology Cloud Computing Security Cyber Security DevOps Identity and Access Management Open Web Application Security PCI Data Security Standards Restful APIs Vulnerability Analysis

Requirements

design.Work closely with engineering, architecture, product and delivery teams in Agile and DevOps environments to embed security by design.Support compliance with security and regulatory frameworks including ISO 27001, PCI DSS, OWASP and internal standards.Review security posture of vendors and outsourced services, providing due diligence and third-party risk assurance.Present security findings, risk opinions and design recommendations clearly to both technical and non-technical stakeholders, including senior leadership.Required Experience and SkillsExtensive experience in cyber security, security consulting, risk assessment or security architecture within regulated environments, ideally financial services.Strong knowledge of threat modelling methodologies, secure design principles, attack vectors and mitigating controls across network, application and cloud domains.Practical understanding of cloud security, secure application delivery, third-party risk management and access management practices.Experience applying recognised frameworks and standards such as ISO 27001, PCI DSS, OWASP, NIST and enterprise security control frameworks.Ability to translate complex technical risks into business language and provide clear, evidence-based recommendations.Exposure to contemporary architectures. E.g. RESTful APIs and containerised microservicesStrong stakeholder management, written communication and presentation skills, with confidence engaging senior managers and control functions.Qualifications and CertificationsEssential: Demonstrable experience in security design, cyber risk, security consulting or related cyber security disciplines.Desirable: Professional certifications such as CISSP, CISM, CCSP, CEH, GIAC or equivalent.Preferred background: Experience supporting cloud transformation, digital delivery, third-party assurance and regulated change programmes.Desirable AttributesCommercially aware and able to balance risk reduction with pragmatic business delivery.Capable of working independently while influencing multidisciplinary teams and senior stakeholders.Understanding or awareness about banking systemsComfortable operating in fast-paced, high-pressure environments with changing priorities.Structured, detail-oriented and focused on producing high-quality, repeatable outcom

Benefits & conditions

BenefitsA supportive, diverse, and global team with a brilliant culture.Competitive compensation and benefits that includes up to 20 days’ vacation per year, various insurances like Term life and Business Travel insurance. These are apart from the statutory benefits applicable in the country. Employee benefits are regulated by an internal policy that contains full details regarding the entitlement and conditions for the benefits as per the law of the land.Great opportunities to make the role your own, upskill yourself and get involved with exciting projects.Total Wellbeing is our focus. Alongside your professional excellence, you join the likeminded colleagues to create a larger impact within the company and society at large in your chosen area of passion - CSR Council, Diversity Council, Women Connect, Sparks - Engagement Champion to name a few.To know more about us visit - www.hcltech.comFor more information on how we process your personal data, please refer to HCLTech’s Candidate Data Privacy Not ice.

About the company

We are a $13+ billion global technology company, home to more than 224,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud, and AI, powered by a broad portfolio of technology services and products.HCLTech is a globally recognized leader in the Tech and IT industry, but we’ve never forgotten the startup mindset that got us here. We’ve always approached our work with an idea-first attitude because every one of our accomplishments -no matter how big or small -can be traced back to an idea’s single spark.It’s that spark -that inner drive -that sets our people apart from our competitors. It enables us not just to pull off game-changing feat after game-changing feat but to better our world in the process. We want you to find your spark. Because that’s what drives you to be better, be more and ultimately, be more fulfilled.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on apply4u.co.uk

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · WWC Europe 2026

2:59 min

The danger of adopting default REST APIs

Stefan Priebsch · WWC 2021

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

Videos

See all

Related articles

See all