> Markdown version of [/jobs/ext/3602906-security-engineering-consultant](https://www.wearedevelopers.com/jobs/ext/3602906-security-engineering-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineering Consultant - **Company:** Sanderson Recruitment Plc - **Location:** London, UK (Remote available) - **Salary:** £143,000.0 - £169,000.0 - **Contract:** Contract - **Skills:** Kubernetes Security, Open Web Application Security, Systems Development Life Cycle, Secure Coding, Web Application Security, Software Engineering, Systems Integration, Software Vulnerability Management, Software Security, Kubernetes, Devsecops - **Published:** October 7, 2026 - **Apply:** https://www.reed.co.uk/jobs/security-engineering-consultant/57431345 ## About the Role * Significant experience in threat modelling - experience using IriusRisk or comparable threat modelling tools * Experience in application security, with detailed knowledge of OWASP standards and web application security * Experience of DevSecOps practices, including integrating security controls into CI/CD pipelines * Knowledge of the secure SDLC within agile delivery environments * Experience of vulnerability management * Working knowledge of Kubernetes and container security * The ability to communicate security risks clearly to technical and non-technical stakeholders ## Description A leading Financial Services is seeking an experienced Security Engineering Consultant on a contract basis. The successful candidate will be embedded within engineering tribes, providing security consultancy and guidance to development teams throughout the software development lifecycle. The primary focus of the role is threat modelling. The consultant will conduct threat models for new and existing products, identify risks at the design stage and work with developers to mitigate those threats during development, ensuring that products are secure by design., * Conduct and document threat models across products and services, from initial design through to delivery * Work with development teams to mitigate identified threats during development * Provide security consultancy and guidance to engineers, product owners and architects * Embed secure development practices across the SDLC and support the adoption of DevSecOps * Support application security activities, including secure design reviews and security testing * Manage and improve vulnerability management processes, supporting teams with prioritisation and remediation * Produce threat modelling diagrams and supporting documentation for use by delivery teams * Support the development of security knowledge within engineering teams