Security Engineering Consultant

Sanderson Recruitment Plc
London, UK
3 days ago
Apply on www.reed.co.uk
Prepare application

Role details

Contract type
Contract
Employment type
Full-time (> 32 hours)
Compensation
£143,000.0 - £169,000.0
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Open Web Application Security Systems Development Life Cycle Secure Coding Web Application Security Software Engineering Systems Integration Software Vulnerability Management Software Security Kubernetes Devsecops

Job description

A leading Financial Services is seeking an experienced Security Engineering Consultant on a contract basis. The successful candidate will be embedded within engineering tribes, providing security consultancy and guidance to development teams throughout the software development lifecycle.

The primary focus of the role is threat modelling. The consultant will conduct threat models for new and existing products, identify risks at the design stage and work with developers to mitigate those threats during development, ensuring that products are secure by design., * Conduct and document threat models across products and services, from initial design through to delivery

  • Work with development teams to mitigate identified threats during development
  • Provide security consultancy and guidance to engineers, product owners and architects
  • Embed secure development practices across the SDLC and support the adoption of DevSecOps
  • Support application security activities, including secure design reviews and security testing
  • Manage and improve vulnerability management processes, supporting teams with prioritisation and remediation
  • Produce threat modelling diagrams and supporting documentation for use by delivery teams
  • Support the development of security knowledge within engineering teams

Requirements

  • Significant experience in threat modelling - experience using IriusRisk or comparable threat modelling tools
  • Experience in application security, with detailed knowledge of OWASP standards and web application security
  • Experience of DevSecOps practices, including integrating security controls into CI/CD pipelines
  • Knowledge of the secure SDLC within agile delivery environments
  • Experience of vulnerability management
  • Working knowledge of Kubernetes and container security
  • The ability to communicate security risks clearly to technical and non-technical stakeholders

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.reed.co.uk
Prepare application

Good distractions

Loading talks and stories from around this role…