Key Responsibilities
- Perform security risk assessments and technical control reviews
- Facilitate threat modelling workshops and risk identification activities
- Review solution and infrastructure designs from a security perspective
- Assess security documentation, architecture artefacts and technical implementations
- Provide practical guidance on secure design and security controls
- Support control alignment with ISO27001 and internal security standards
- Review areas including network segmentation, access control models, logging and monitoring
- Assist teams in preparation for internal and external audits
- Produce meaningful security metrics, reporting and risk visibility dashboards
- Partner with technology, engineering and risk stakeholders across multiple programmes
Essential Experience
- Strong background within Information Security, Security Assurance, Security Risk or Security Consulting
- Proven experience conducting technical security risk assessments
- Experience facilitating threat modelling and security design reviews
- Strong knowledge of ISO27001/27002 and security control frameworks
- Ability to translate security requirements into practical technical controls
- Experience working with infrastructure, platforms or enterprise technology environments
- Excellent stakeholder management and communication skills
- Previous experience within banking, financial services or a highly regulated environment
Desirable Experience
- Security architecture or design assurance experience
- Agile delivery environments
- DevOps, cloud platforms or infrastructure engineering exposure
- Audit and regulatory engagement experience
What We're Looking For
This is not a pure governance role and not a hands-on Security Architect position.
We're seeking someone who can confidently challenge technical designs, facilitate risk discussions with stakeholders and provide pragmatic security guidance that enables delivery while maintaining an appropriate risk posture.