Negotiable
Undetermined
Undetermined
England, United Kingdom
Summary: The Senior Security Consultant - Cloud & Identity will lead threat modeling and secure design reviews, ensuring the application of CIS-aligned security non-functional requirements across various domains. This role involves acting as a trusted advisor to stakeholders, promoting secure-by-design practices through clear guidance and early engagement. The consultant will also embed security principles throughout the software development lifecycle (SDLC) and provide actionable security guidance aligned with delivery goals.
Key Responsibilities:
- Act as a trusted security advisor across Product, Engineering, and Architecture
- Lead secure design reviews and STRIDE threat modelling for key solutions
- Embed secure-by-design principles across the SDLC
- Provide clear, actionable security guidance aligned to delivery goals
- Apply CIS-aligned security controls across cloud, identity, and application security
Key Skills:
- Hands-on threat modelling experience (STRIDE preferred)
- Strong Azure security & IAM expertise (Entra ID, Defender, Conditional Access)
- Experience embedding security within Agile delivery teams / SDLC
- Background in enterprise-scale, regulated environments
- Comfortable working with Design Authority (DA) and CAB governance
- Relevant certifications (CISSP, CISM, SC-100 or equivalent)
Salary (Rate): undetermined
City: undetermined
Country: United Kingdom
Working Arrangements: undetermined
IR35 Status: undetermined
Seniority Level: undetermined
Industry: IT
The Role
Day-to-day, you’ll lead threat modelling and secure design reviews, applying CIS-aligned security NFRs across cloud, identity, and application security. You’ll act as a trusted advisor, influencing stakeholders through clear, pragmatic guidance - measured by early engagement and real adoption of secure-by-design practices.
Key Responsibilities
- Act as a trusted security advisor across Product, Engineering, and Architecture
- Lead secure design reviews and STRIDE threat modelling for key solutions
- Embed secure-by-design principles across the SDLC
- Provide clear, actionable security guidance aligned to delivery goals
- Apply CIS-aligned security controls across cloud, identity, and application security
Skills & Experience
- Hands-on threat modelling experience (STRIDE preferred)
- Strong Azure security & IAM expertise (Entra ID, Defender, Conditional Access)
- Experience embedding security within Agile delivery teams / SDLC
- Background in enterprise-scale, regulated environments
- Comfortable working with Design Authority (DA) and CAB governance
- Relevant certifications (CISSP, CISM, SC-100 or equivalent)