
Senior Consultant or Manager, Security Engineer - Financial Services, Enterprise Security
- London
- Permanent
- Full-time
- Designing and building secure infrastructure in public, private and hybrid cloud environments, using infrastructure-as-code.
- Designing and building secure CI/CD pipelines, integrating the latest security technologies and checks.
- Designing and building a range of security tooling, across endpoint protection, vulnerability scanning, network security, cloud security posture management, and security information event management (SIEM).
- Leading security assessments and providing technical recommendations on required configurations for client platforms and tooling.
- Operating Secure by Design (SbD) procedures and producing required artefacts such as security impact assessments.
- Inputting into security architectures and solution designs.
- Designing security controls and suggesting improvements on configurations of critical control such as WAF, firewalls, compliance monitoring, and alerting.
- Conducting risk assessments and scoping vulnerability assessments to identify potential security threats and vulnerabilities.
- Helping clients create security technology roadmaps, which provide realistic efforts estimates for engineering tasks.
- Staying up to date with emerging security threats, technologies, and industry best practices, and providing recommendations for improvement.
- Conducting security reviews to identify gaps in client's technologies and suggesting improvements across people, process, and technology.
- Contributing to sales activity, through proposal documentation, eminence materials, and technical demonstrations.
- Hands-on experience configuring one or more public cloud environments (AWS, Azure, GCP).
- Hands-on experience with CI/CD tooling.
- Proficiency with infrastructure-as-code, e.g. Terraform.
- Proficiency with programming / scripting languages (e.g. Python, Bash, PowerShell).
- Experience building and deploying micro services-based applications.
- Experience with security technologies, for example Firewalls, Intrusion Detection/Prevention Systems, Vulnerability Scanning, WAFs, CASBs, SIEMs, and CSPMs.
- Experience inputting into and/or creating security architectures and designs.
- Understanding of security principles and the ability to assess alignment of controls to these principles.
- Ability to analyse and capture risk statements including references to likelihood, impact and mitigations.
- Ability to frame technology and process level risk in business and operational terms.
- Understanding of security controls and industry frameworks.
- Understanding of regulatory and compliance requirements.
- Understanding of Agile, SCRUM and Continuous Delivery.
- Bachelor's or master's degree (or equivalent) in information technology, Cybersecurity, computer science or a related field, or equivalent work experience.
- Certifications or other knowledge of cloud environments and their security controls available (AWS, Azure or Google).
- Certifications from industry-leading security vendors and/or cloud providers would be desirable.