The Role
As a Security Consultant focusing on Economic Crime team, provide end-to-end cyber security assurance across the Economic Crime technology estate, ensuring that applications, platforms, infrastructure, integrations and technology changes are designed, built and operated securely.
The role will act as a trusted security advisor to engineering, architecture, infrastructure, DevOps, product, risk and business teams, embedding Secure by Design principles throughout the technology life cycle.
Your responsibilities:
Act as the primary Security Assurance Consultant for projects and technology initiatives within the Economic Crime domain.
Conduct security assessments of new systems, material changes, integrations and technology solutions.
Provide pragmatic security advice that balances risk, regulatory expectations, customer protection and business delivery objectives.
Determine whether required preventative, detective and responsive controls are present and operating as intended.
Assess the likelihood and business impact of identified security risks & track them through to remediation, mitigation or formal acceptance.
Assess solutions against applicable security frameworks, policies and control requirements including NIST CSF 2.0, ISO/IEC 27001, organisational security guardrails.
Define and enforce security policies, standards, and best practices ensuring Ensure compliance with financial regulations (eg, PCI DSS, ISO 27001, GDPR).
Provide security assurance and guidance regarding IAM and PAM, Network Security, Penetration Testing Results, Vulnerability Scans etc.
Challenge solutions constructively where required security controls have not been implemented or have been implemented inadequately.
Maintain traceability between identified risks, security requirements, controls, evidence and residual risks.
Your Profile
Essential skills/knowledge/experience:
Proven experience performing security assurance or security consultancy within complex enterprise environments.
Demonstrable experience applying Secure by Design principles.
Proven understanding of security risk assessment methodologies.
Experience managing security risks, exceptions and remediation activities.
Experience and proven knowledge of working with NIST Cybersecurity Framework, ISO/IEC 27001, Zero Trust, OWASP Top 10 etc
Good understanding of Access Management, Data Security, Cloud Security, Network security guardrails
Confident enough to challenge architects, engineers and project leadership where security requirements are not adequately addressed.
Works collaboratively with delivery teams to find secure solutions instead of acting solely as an approval or governance function.
Desirable skills/knowledge/experience:
Previous experience of working in UK Financial Services or similar highly regulated industry.
Have a relevant professional qualification (or be working towards certification), such as CISM/CISSP.
Knowledge/experience of PCI-DSS, NIST CSF, OWASP Top 10, ISO 27001
Knowledge/experience of Data privacy and GDPR;
Experience with regulatory compliance frameworks specific to financial organizations.
Excellent interpersonal and communication skills.
Able to differentiate between theoretical security concerns and material business risks, ensuring security decisions remain proportionate.