Negotiable
Inside
Hybrid
Watford, England, United Kingdom
Summary: The Technical Security Consultant (Manager) role involves providing expert technical security advice within a consultancy team, focusing on the security aspects of digital solutions throughout their lifecycle. The consultant will lead initiatives, collaborate with various teams, and ensure compliance with security requirements while managing stakeholder relationships. The position requires a blend of technical expertise and communication skills to navigate complex security challenges and promote secure practices. This is a contract role based in Watford, with a hybrid working arrangement.
Key Responsibilities:
- Lead as an internal consultant at Manager level providing technical security direction and stakeholder management.
- Collaborate with product and engineering teams to ensure digital solutions meet security requirements.
- Work with Design Authorities to review and align change initiatives with security standards.
- Provide risk and threat-based advice using threat modelling for digital solution design and implementation.
- Advise on secure-by-design adoption of AI/GenAI capabilities.
- Manage security testing requirements for new systems and products.
- Conduct Post Deployment Security Architecture reviews of existing solutions.
- Create secure development guidance documentation and eLearning in collaboration with teams.
- Provide solution architecture support for security solutions.
- Pursue professional certifications for personal development and share knowledge with others.
Key Skills:
- Experience in Infrastructure/Solution Architect, Technical Security Architect/Consultant, or Security Operations.
- Understanding of application, cloud, and SaaS security concepts and best practices.
- Hands-on experience securing digital products in AI, cloud, networks, operating systems, and security solutions.
- Experience in Agile/DevOps environments using Threat Modelling.
- Ability to adapt communication style for diverse audiences within an organization.
- Experience in prioritizing and delivering in dynamic environments.
- Problem-solving skills to navigate complex security issues.
- Desirable experience with container/serverless platforms and infrastructure/network security.
- Technical security certifications (e.g., CISSP, CCSP) or working towards them.
- Experience in customer service/regulated environments delivering high-quality information security services.
Salary (Rate): undetermined
City: Watford
Country: United Kingdom
Working Arrangements: hybrid
IR35 Status: inside IR35
Seniority Level: undetermined
Industry: IT
Role/Job title: Technical Security Consultant (Manager)
Work Location: Watford
Role type: Contract InsideIR35
Mode of working: Hybrid 2 days /week
Duration of assignment: 4 Months
Any other working conditions: travel/on call/shifts
Normal UK business Hrs 8:00 to 17:00 Hrs, Travel to London Office on ad-hoc basis. May need to travel to Birmingham and other office locations in UK for workshops etc. Expected 2 days a week.
The Role: This role is within the Security Consultancy sub-team who provide specialist technical security advice collaborating with technical and business teams throughout the entire or part of a digital solution’s life cycle. The team owns and develops Security Patterns, Security Specifications, and the Threat Modelling Framework, to support secure technology innovation in a changing threat landscape. The purpose of this role is to advise on the technical security aspects of digital solutions to be evaluated or developed and implemented by technology teams across KPMG Group for internal use, or as a service or product to KPMG clients.
The Technical Security Consultant’s responsibilities will vary based on business alignment and will include:
- Lead as an internal consultant at Manager level to an assigned Platform/Product/Capability/Practice Management area as part of our Centre of Excellence function providing technical security direction, stakeholder management, and driving improvements to our ways of working.
- Collaborate with programs and projects, product and engineering teams to help deliver digital solutions that meet the business need, by supporting and contributing to design reviews. Ensuring that the proposed design, build and run are compliant with the KPMG and client security requirements – ensuring all applicable security controls and patterns are implemented.
- Work alongside internal Design Authorities and Change Management functions to ensure all change initiatives are reviewed, supported, and aligned with KPMG security requirements.
- Using threat modelling to provide risk and threat-based advice to program stakeholders along with actionable recommendations where necessary in the design and implementation of digital solutions.
- Advise on secure-by-design adoption of AI/GenAI capabilities (e.g. Microsoft 365 Copilot/Copilot Studio and LLM integrations) including prompt and data protection, model/service selection considerations, misuse and abuse cases, and appropriate technical guardrails.
- Manage the scoping of security testing requirements for new systems and products working closely with our Security Testing function.
- Undertake Post Deployment Security Architecture reviews of existing digital solutions.
- Support the creation of secure development guidance documentation and eLearning, security patterns and specifications in collaboration with Engineering/Development teams and Enterprise Security Architecture.
- Provide solution architecture support (i.e. PoC, design creation, roadmap support) for security solutions (e.g. AI, IAM).
- Work towards and achieve or extend professional certifications as part of personal development (e.g. security or cloud vendor certifications)
- Share experiences with others to assist their learning and understanding, and promote good security hygiene and its benefits.
Prior experience Essential Skills/Experience:
- Have worked in at least one of: Infrastructure/Solution Architect , Technical Security Architect/Consultant , Security Operations, Secure application development
- A good understanding of concepts and their application across several key areas including application, cloud, and SaaS security, best practices, and industry standards (and where relevant, AI/GenAI security concepts).
- You will bring hands on experience and knowledge in securing digital products/solutions in at least one or more of the following areas:
- Artificial intelligence (e.g. AWS Bedrock, CoPilot, CoPilot Studio, Google Gemini, Azure OpenAI, Google Vertex)
- Cloud (e.g. AWS, Azure/M365, Google, ServiceNow, SAP)
- Networks (e.g. firewalls, routers, switches, WIFI, LAN/WAN, SDN)
- Operating Systems and hardware (e.g. Microsoft, Linux, Apple, Android)
- Security Solutions (e.g. Entra ID, CyberArk, SailPoint, Threat Modeler)
- Good experience of working in an Agile/DevOps software development environment using Threat Modelling.
- Be able to demonstrate the ability to adapt communication style to explain technical concepts to different people within an organization whether advising stakeholders, directing teams, or sharing experience.
- Experience prioritizing and delivering in an environment with competing demands and evolving requirements.
- Able to navigate through complex security problems to find the root cause and a balanced outcome, taking ownership of activities.
It would be desirable if you can demonstrate some, or all of the following:
- Container/serverless platforms.
- Infrastructure/network security.
- Modern application development processes and testing.
- AI/GenAI security (e.g. threat modelling for AI solutions, prompt injection and data exfiltration risks, data poisoning/model integrity risks, model/service supply chain considerations, and applying appropriate guardrails and monitoring).
- Have or working towards technical security certifications (e.g. CISSP, CCSP, Microsoft/Google/AWS technologies).
- Having worked in customer service/regulated environments, delivering high quality information security services