> Markdown version of [/jobs/ext/3564748-security-consultant](https://www.wearedevelopers.com/jobs/ext/3564748-security-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Consultant - **Company:** LA International - **Location:** UK (Remote available) - **Salary:** £117,000.0 - £143,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cloud Computing Security, Cyber Security, Data Security, Identity and Access Management, Network Security, Open Web Application Security, PCI Data Security Standards, Zero Trust Network Access, National Institute of Standards and Technology Cybersecurity Framework, Vulnerability Analysis - **Published:** October 3, 2026 - **Apply:** https://www.securityclearedjobs.com/job/802084752/security-consultant-/ ## About the Role * Proven experience performing security assurance or security consultancy within complex enterprise environments. * Demonstrable experience applying Secure by Design principles. * Proven understanding of security risk assessment methodologies. * Experience managing security risks, exceptions and remediation activities. * Experience and proven knowledge of working with NIST Cybersecurity Framework, ISO/IEC 27001, Zero Trust, OWASP Top 10 etc * Good understanding of Access Management, Data Security, Cloud Security, Network security guardrails * Confident enough to challenge architects, engineers and project leadership where security requirements are not adequately addressed. * Works collaboratively with delivery teams to find secure solutions instead of acting solely as an approval or governance function. Desirable skills/knowledge/experience: * Previous experience of working in UK Financial Services or similar highly regulated industry. * Have a relevant professional qualification (or be working towards certification), such as CISM / CISSP. * Knowledge / experience of PCI-DSS, NIST CSF , OWASP Top 10 , ISO 27001 * Knowledge / experience of Data privacy and GDPR; * Experience with regulatory compliance frameworks specific to financial organizations. * Excellent interpersonal and communication skills. * Able to differentiate between theoretical security concerns and material business risks, ensuring security decisions remain proportionate. ## Description * Act as the primary Security Assurance Consultant for projects and technology initiatives within the Economic Crime domain. * Conduct security assessments of new systems, material changes, integrations and technology solutions. * Provide pragmatic security advice that balances risk, regulatory expectations, customer protection and business delivery objectives. * Determine whether required preventative, detective and responsive controls are present and operating as intended. * Assess the likelihood and business impact of identified security risks & track them through to remediation, mitigation or formal acceptance. * Assess solutions against applicable security frameworks, policies and control requirements including NIST CSF 2.0 , ISO/IEC 27001, organisational security guardrails. * Define and enforce security policies, standards, and best practices ensuring Ensure compliance with financial regulations (e.g., PCI DSS, ISO 27001, GDPR). * Provide security assurance and guidance regarding IAM and PAM , Network Security , Penetration Testing Results , Vulnerability Scans etc. * Challenge solutions constructively where required security controls have not been implemented or have been implemented inadequately. * Maintain traceability between identified risks, security requirements, controls, evidence and residual risks. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Small, Secure, Interconnected: The next Internet Protocol](https://www.wearedevelopers.com/videos/100062-small-secure-interconnected-the-next-internet-protocol) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk)