Location: London (Hybrid - 2 days p/week onsite)
Salary: £500 - £550 per day INSIDE IR35
Contract Type: Contract - 12 months (extensions thereafter)
Our client is a leading global organisation operating within the critical financial infrastructure sector, where security is fundamental to the delivery of its services and embedded across its governance, management systems and operational processes.
The Cyber Security team is responsible for impact analysis, security risk assessments, defining security requirements, validating solution designs across IT projects, and conducting regular security assessments of applications and underlying infrastructure. The team also supports compliance activities through secure configuration baseline management, Security Exception Review Board governance, and provides expert security consultancy across the business.
Required Technical & Professional Experience
The successful candidate will have experience in one or more of the following areas:
- Proven experience conducting security risk assessments, developing functional security requirements, process design and management reporting.
- Strong understanding of industry best practices across Identity & Access Management (IAM), PKI, network security and data protection.
- Application security knowledge, including secure software development, testing methodologies, OWASP principles, code scanning tools and security/compliance automation within CI/CD pipelines.
- Experience with security technologies including Identity as a Service (IDaaS), identity management platforms, secure access management, federation services, PKI, cryptographic solutions, web application firewalls (WAF) and endpoint security.
- Broad infrastructure security knowledge covering virtualisation, Software Defined Networks (SDN), Cloud (IaaS/PaaS/SaaS), network and DMZ infrastructure, VoIP, Wi-Fi, 802.1x, anti-malware, system protection, middleware, collaboration platforms, end-user workspace solutions, storage technologies (SAN/NAS), databases and Infrastructure as Code (IaC).
- Professional certifications such as CISSP, GIAC, SABSA or ISO 27001 Lead Auditor/Lead Implementer are highly desirable. Vendor-specific security certifications are also advantageous.
Key Responsibilities
- Advise on the design, implementation and testing of security controls to protect information assets.
- Perform security risk assessments and translate security architecture, policies and controls into secure-by-design requirements for business and IT initiatives.
- Review and validate solution architectures against defined security requirements.
- Define security testing requirements, penetration testing scope, support testing activities and review test outcomes.
- Develop, implement and maintain security services in line with organisational security policies.
- Recommend improvements to existing security services and advise senior management on security enhancements.
- Produce technical security standards, documented security services and security principles.
- Act as a Subject Matter Expert within one or more specialist domains such as IAM, PKI, cryptography, network security, platform security, application security or secure coding.
- Collaborate with business stakeholders, project managers, risk teams, auditors, engineers, developers and architects to ensure security requirements are effectively implemented.
Candidate Profile
- Degree in Computer Science, Engineering or a related discipline.
- Strong background in infrastructure security and/or application security.
- Senior candidates will typically have 10+ years’ experience across multiple cyber security domains and industries, while junior candidates should possess at least three years’ experience within a cyber security discipline.
- Proficient with Microsoft Office tools including PowerPoint, Visio, Excel and Word.
- Experience translating business requirements into practical technical security solutions.
- Excellent analytical, research, organisational and problem-solving skills.
- Strong attention to detail with the ability to manage multiple priorities and meet deadlines.
- Confident presenting technical findings and recommendations to both technical and non-technical stakeholders.
- Comfortable working within international and multicultural environments.
- Fluent English communication skills, both written and verbal.
- Excellent stakeholder management skills with the ability to communicate effectively with business leaders and technical specialists.
- Able to manage multiple concurrent projects and perform effectively in fast-paced environments.
- Takes ownership, maintains high quality standards and works independently while remaining collaborative and service-oriented.